logo

You do surprise me.exe: An unexpected executable in Hola Browser

ID: fd6ecfcd-4e0c-5f08-9e66-6fc02bf29408

STIX ID: report--fd6ecfcd-4e0c-5f08-9e66-6fc02bf29408

Feed Name: Sophos Blogs

Threat Score
55/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

...
...

Sophos X-Ops identified an undeclared, unsigned executable (me.exe) bundled intermittently with Hola Browser that functions as a crypto-miner (Troj/GoMiner-B). The binary copies itself to Program Files, installs an autostart service, attempts Windows Defender exclusions and contains XMRig-related artifacts; Hola confirmed a supply-chain compromise affecting ~0.1% of users and rebuilt its distribution pipeline after investigation and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.