logo

Are Security Firms Ducking Attribution for VOHO? (Rhymes with ‘Carolina’)

ID: 003d6bd4-d8fd-59d2-a6eb-2a4f2bee7493

STIX ID: report--003d6bd4-d8fd-59d2-a6eb-2a4f2bee7493

Feed Name: Security Ledger

Threat Score
78/100

Date Published: 2012-10-15

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

This report summarizes RSA and related analyses of the VOHO watering‑hole campaign: attackers used xKungFoo scripts and Gh0st‑family trojans in targeted watering‑hole drive‑by compromises that affected tens of thousands of systems across more than 700 organizations (pro‑democracy groups, defense contractors and high‑finance). Researchers observed APT‑style TTPs (targeted user‑profile infections, selected lure sites, C2 infrastructure in the Hong Kong area) and debated possible links to China, but conclusive attribution was not established; the article also highlights expert disagreement over the evidentiary standard for nation‑state attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.