Drive-by Compromise

T1189

Technique.View on attack.mitre.org

About this technique

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

* A legitimate website is compromised, allowing adversaries to inject malicious code
* Script files served to a legitimate website from a publicly writeable cloud storage bucket are modified by an adversary
* Malicious ads are paid for and served through legitimate ad providers (i.e., Malvertising)
* Built-in web application interfaces that allow user-controllable content are leveraged for the insertion of malicious scripts or iFrames (e.g., cross-site scripting)

Browser push notifications may also be abused by adversaries and leveraged for malicious code injection via User Execution. By clicking "allow" on browser push notifications, users may be granting a website permission to run JavaScript code on their browser.

Often the website used by an adversary is one visited by a specific community, such as government, a particular industry, or a particular region, where the goal is to compromise a specific user or set of users based on a shared interest. This kind of targeted campaign is often referred to a strategic web compromise or watering hole attack. There are several known examples of this occurring.

Typical drive-by compromise process:

1. A user visits a website that is used to host the adversary controlled content.
2. Scripts automatically execute, typically searching versions of the browser and plugins for a potentially vulnerable version. The user may be required to assist in this process by enabling scripting, notifications, or active website components and ignoring warning dialog boxes.
3. Upon finding a vulnerable version, exploit code is delivered to the browser.
4. If exploitation is successful, the adversary will gain code execution on the user's system unless other protections are in place. In some cases, a second visit to the website after the initial scan is required before exploit code is delivered.

Unlike Exploit Public-Facing Application, the focus of this technique is to exploit software on a client endpoint upon visiting a website. This will commonly give an adversary access to systems on the internal network instead of external systems that may be in a DMZ.

Detection rules5

Rules on DetectionCode tagged with T1189.

Sigma3

RuleLevelLog source
Cross Site Scripting StringshighNULL / webserver
Flash Player Update from Suspicious LocationhighNULL / proxy
Suspicious Browser Child Process - MacOSmediummacos / process_creation

Splunk2

Groups31

Show 7 more

Software10

Campaigns3

Procedure examples44

Groups31

Used byProcedure example
GroupAndariel

Andariel has used watering hole attacks, often with zero-day exploits, to gain initial access to victims within a specific IP range.

GroupAPT19

APT19 performed a watering hole attack on forbes.com in 2014 to compromise targets.

GroupAPT28

APT28 has compromised targets via strategic web compromise utilizing custom exploit kits. APT28 used reflected cross-site scripting (XSS) against government websites to redirect users to phishing webpages.

GroupAPT32

APT32 has infected victims by tricking them into visiting compromised watering hole websites.

GroupAPT37

APT37 has used strategic web compromises, particularly of South Korean websites, to distribute malware. The group has also used torrent file-sharing sites to more indiscriminately disseminate malware to victims. As part of their compromises, the group has used a Javascript based profiler called RICECURRY to profile a victim's web browser and deliver malicious code accordingly.

GroupAPT38

APT38 has conducted watering holes schemes to gain initial access to victims.

GroupAxiom

Axiom has used watering hole attacks to gain access.

GroupBRONZE BUTLER

BRONZE BUTLER compromised three Japanese websites using a Flash exploit to perform watering hole attacks.

View all 31 groups examples

Software10

Used byProcedure example
MalwareBad Rabbit

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

MalwareBundlore

Bundlore has been spread through malicious advertisements on websites.

MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

MalwareIcedID

IcedID has cloned legitimate websites/applications to distribute the malware.

MalwareKARAE

KARAE was distributed through torrent file-sharing websites to South Korean victims, using a YouTube video downloader application as a lure.

MalwareLoudMiner

LoudMiner is typically bundled with pirated copies of Virtual Studio Technology (VST) for Windows and macOS.

MalwarePOORAIM

POORAIM has been delivered through compromised sites acting as watering holes.

MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

View all 10 software examples

Campaigns3

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus compromised the `www.tradingtechnologies[.]com` website hosting a hidden IFRAME to exploit visitors, two months before the site was known to deliver a compromised version of the X_TRADER software package.

CampaignC0010

During C0010, UNC3890 actors likely established a watering hole that was hosted on a login page of a legitimate Israeli shipping company that was active until at least November 2021.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors used a watering hole attack on a popular software reseller to exploit the then-zero-day Internet Explorer vulnerability CVE-2014-0322.

References4

  1. Push notifications - viruspositive Open source
    Gaurav Sethi. (2021, December 14). The Dark Side of Web Push Notifications. Retrieved March 14, 2025.
  2. Shadowserver Strategic Web Compromise Open source
    Adair, S., Moran, N. (2012, May 15). Cyber Espionage & Strategic Web Compromises – Trusted Websites Serving Dangerous Results. Retrieved March 13, 2018.
  3. push notification -mcafee Open source
    Craig Schmugar. (2021, May 17). Scammers Impersonating Windows Defender to Push Malicious Windows Apps. Retrieved March 14, 2025.
  4. push notifications - malwarebytes Open source
    Pieter Arntz. (2019, January 22). Browser push notifications: a feature asking to be abused. Retrieved March 14, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.