After VOHO Attacks, Organizations Face Arduous Clean Up
ID: 62d90c9a-7825-5e97-b827-efd5c19c0af3
STIX ID: report--62d90c9a-7825-5e97-b827-efd5c19c0af3
Feed Name: Security Ledger
VOHO was a widespread watering‑hole campaign (25 Jun–17 Jul 2012) that leveraged zero‑day web exploits to deliver a custom Gh0stRAT variant, resulting in thousands of compromised hosts across hundreds of organizations (notably defense, federal, financial and utilities). RSA identified large clusters of victims, is notifying affected organizations, and the intrusion displays APT-like tactics including lateral movement, credential harvesting, and evolving C2 behavior (switching from port 80 to 443).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
