logo

After VOHO Attacks, Organizations Face Arduous Clean Up

ID: 62d90c9a-7825-5e97-b827-efd5c19c0af3

STIX ID: report--62d90c9a-7825-5e97-b827-efd5c19c0af3

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2012-10-02

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

VOHO was a widespread watering‑hole campaign (25 Jun–17 Jul 2012) that leveraged zero‑day web exploits to deliver a custom Gh0stRAT variant, resulting in thousands of compromised hosts across hundreds of organizations (notably defense, federal, financial and utilities). RSA identified large clusters of victims, is notifying affected organizations, and the intrusion displays APT-like tactics including lateral movement, credential harvesting, and evolving C2 behavior (switching from port 80 to 443).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.