logo

You do surprise me.exe: An unexpected executable in Hola Browser

ID: 8ff2c94b-f6e4-5b07-a5ac-8c499b315e9a

STIX ID: report--8ff2c94b-f6e4-5b07-a5ac-8c499b315e9a

Feed Name: Sophos Blogs

Threat Score
60/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

...
...

Sophos X-Ops discovered an unexpected unsigned executable (me.exe) bundled with Hola Browser installers that functions as a crypto-miner (Troj/GoMiner-B). The binary performs Windows Defender exclusion, contains XMRig-related strings, copies itself to Program Files and installs an autostart service; Hola engaged a forensic firm, confirmed a supply-chain delivery issue affecting ~0.1% of users, and rebuilt their distribution pipeline to remove the undeclared component.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.