logo

Hola Browser Windows Delivery Pipeline Hijacked to Deploy Cryptominer

ID: 7a33c5e3-ce66-5444-82ff-fee2c94b7846

STIX ID: report--7a33c5e3-ce66-5444-82ff-fee2c94b7846

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Mayura Kathir

...
...

Hola Browser's Windows delivery pipeline intermittently installed an unsigned, obfuscated executable (me.exe) that analysis linked to crypto‑mining (XMRig indicators). The binary showed persistence behaviors (copying itself to C:\Program Files\Hola\HolaMonitorService.exe, creating an autostart service, and attempting to create Windows Defender exclusions), was classified by Sophos as Troj/GoMiner‑B and matched SHA256 e3541caf708c075f0bb22fc68b03acd8457fea7cf0732ea935b1eb016d1c7721; Hola halted the affected distribution path, engaged Sygnia, rebuilt the pipeline with stricter signing and controls, and reported ~0.1% user impact with no data exfiltration reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.