Malware
Watering hole
Watering hole is compromising a site that your real target group already visits, and waiting for them to arrive. The attacker never contacts the victims directly.
How it is measured
Evidence shows on the chosen site: an injected script or iframe that serves only certain IP ranges, languages, or user agents, and a landing page that checks the visitor before delivering anything. Server logs on the victim end show visits followed by odd downloads.
Spotting it means looking at the site as the target sees it, with matching IP geography, browser, and referrer. A clean look from a generic scanner proves little because the code is gated to the audience.
Worked example
A trade association's news page is edited to add a 3 KB script. It checks the visitor's IP against four ranges belonging to defence suppliers and only then loads a hidden iframe. A visitor from a hosting provider's IP sees nothing at all.
The webmaster finds it only because a member's security team reports a browser exploit attempt traced to the page. The association then hands the member companies the page's modified date and the admin login that wrote the change.
How it differs
A drive-by download is the delivery: a page quietly pushes a file or exploit at whoever loads it. A watering hole is the targeting strategy: pick the site, then often use a drive-by download on it. Drive-bys can hit anyone on any site; watering holes hit a chosen group.
Common errors
Testing from an office IP that is not in the target ranges. Assuming a niche site is too small to be useful to an attacker. Removing the iframe and not the admin access that placed it. Not warning visitors who loaded the page during the window. Relying on a scanner that does not mimic the audience.
In practice
If you run a site that serves a specific industry, treat it as a target: enforce MFA on admin, review all script sources, and monitor for changes. Keep the dates of any modification so you can tell visitors exactly when the page was risky.