A watering hole attack gets its name from the idea of poisoning a central water source, and everyone who takes from that source is affected. Similarly, watering hole attacks infect a genuine website, and everyone who uses that website will be exploited. In this, watering hole attacks have two victims
The legitimate website that was impregnated with the malicious software.
The common/targeted users who use the infected website.
Watering hole attacks have been used by authoritarian governments to track political activists and other targeted groups. Simply, they exploit activist websites and thus infect the devices of anyone who visits those sites.
Attackers usually use the victim website as a conduit between the victims and their malicious architecture — conveniently masking their trace.
To establish a watering hole attack, you must exploit software flaws on particular devices (most often in the from of a browser bug). This would give you access to then set up your malware to be distributed to victim users.
