Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

Water Holing

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: Threats, Abuse & Incident Response

Water holing is a social engineering and malware delivery technique that targets sites people already trust and visit regularly. An attacker compromises or imitates a legitimate website so visitors may be redirected, infected, or persuaded to disclose information without realizing the site has been altered.

What Water Holing Means in Practice

Water holing is effective because it borrows trust from a site the target already expects to be safe. That trust can lower suspicion, increase click-through, and make malicious content or credential prompts appear routine rather than hostile.

Unlike broad spray-and-pray phishing, water holing is often selective. Attackers may tailor the compromise or redirect path to a defined audience, such as a profession, company, or community that regularly visits the same web property.

How Water Holing Works

A water holing campaign usually starts with compromise of a legitimate site, though impersonation and poisoned third-party content can produce similar outcomes. Once the destination is altered, visitors may receive malware, a credential theft page, or a redirect chain that quietly profiles the browser and sends only some users onward.

The technique can succeed without the victim noticing a change in the site itself. That makes it especially useful for initial access, because the user often believes they are interacting with a normal business or industry resource.

For defenders, this is a web integrity problem as much as a phishing problem. The weak point is not only the lure, but the trust relationship between the victim and the site being used as the delivery point. Controls such as content integrity checks, hardened administration, and rapid compromise detection matter because they reduce the time a trusted property can be abused.

Why Water Holing Is Hard to Spot

Water holing blends into normal browsing behavior. Visitors are not always sent to a brand-new domain, so reputation filters, user training, and simple URL scrutiny may not help if the original site has already been compromised.

Detection often depends on noticing changes in the trusted site itself, such as unexpected script injection, unusual redirects, or a page that behaves differently for selected visitors. Security teams should also watch for evidence that a benign site is being used as a staging point for malware delivery or credential harvesting.

Because the attacker is abusing a real trust anchor, investigation usually has to move beyond the endpoint. Web logs, DNS patterns, server-side changes, and content integrity telemetry can be more revealing than a blocked download or a single suspicious click.

Common Security Consequences

Water holing can lead to malware infection, account compromise, or targeted reconnaissance of a high-value population. When the site serves a specific professional group, the attacker can use that audience to reach further inside a network or to harvest credentials with unusually high credibility.

The technique also creates reputational and operational damage for the compromised site owner. Even if the original compromise is brief, users may lose trust in the site, and incident response may need to address both the external abuse and the underlying web weakness.

For that reason, water holing should be treated as both an intrusion method and a trust-chain problem. The immediate harm is the malicious payload, but the broader issue is that a legitimate web property has been converted into an attack distribution mechanism.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1189 — Drive-by CompromiseWater holing uses trusted sites to deliver payloads or redirects to victims.
Recommendation — Map compromised-site delivery to drive-by compromise and hunt for injected scripts or malicious redirects.
NIST SP 800-53 Rev 5SI-10 — Information Input ValidationValidates web content and inputs that can be abused for malicious redirects or injection.
CM-5 — Access Restrictions for ChangeWater holing often starts with unauthorized changes to a legitimate web property.
AU-6 — Audit Record Review, Analysis, and ReportingDetects abnormal web changes, redirects, and delivery activity associated with compromise.
Recommendation — Apply SI-10 to validate and constrain web-delivered content before it reaches users. Use CM-5 to restrict who can modify web content, scripts, and redirects. Use AU-6 to review logs for unexpected web edits, redirect chains, and delivery anomalies.
CIS Controls v8CIS-8 — Audit Log ManagementWater holing often leaves detectable web and server-side logging evidence.
Recommendation — Centralize and review logs to spot compromised pages, redirects, and suspicious user journeys.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org