Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/Threats/Hola Browser for Windows Update Mechanism Used to Deliver Cryptominer
Threats

Hola Browser for Windows Update Mechanism Used to Deliver Cryptominer

Key Takeaways Hola Browser for Windows’ update mechanism was compromised to deliver an undeclared cryptominer (me.exe). The malicious executable, identified as Troj/GoMiner-B by Sophos, is...

David kimber
David kimber
June 5, 2026 4 Min Read
52 0

Key Takeaways

  • Hola Browser for Windows’ update mechanism was compromised to deliver an undeclared cryptominer (me.exe).
  • The malicious executable, identified as Troj/GoMiner-B by Sophos, is based on XMRig and runs covertly in the background, primarily when the system is idle.
  • The compromise affected approximately 0.1% of Hola Browser users, but no user data was reportedly accessed or exfiltrated.
  • The issue was discovered during a routine certification review by AppEsteem and has since been fully remediated by Hola.

A significant supply chain security incident has emerged, involving Hola Browser for Windows, a widely used application. Cybersecurity researchers recently uncovered that the browser’s official distribution channel was exploited to deliver an unauthorized cryptominer to a segment of its user base.

Table Of Content

  • Key Takeaways
  • Sophos Identifies Cryptominer Characteristics
  • Hola Browser for Windows Delivery Pipeline Compromised
  • Supply Chain Risk and Pipeline Integrity

The malicious file, named “me.exe,” was found being distributed alongside the legitimate Hola Browser installer. This executable was not part of the browser’s approved software package and was surreptitiously installed on users’ systems without their knowledge or consent, as detailed in a report.

The discovery was made during a routine certification audit conducted by AppEsteem, an AMTSO-certified organization established in 2016. AppEsteem regularly performs validation tests to ensure that certified software adheres to its declared and approved installation footprint. During one such test involving Hola Browser version 1.251.91.0, the “me.exe” file was unexpectedly found within the browser’s installation directory at C:Program FilesHolame.exe.

Sophos Identifies Cryptominer Characteristics

Analysts at Sophos X-Ops identified the suspicious file during the certification test, classifying it as a Potentially Unwanted Application (PUA). A Sophos report shared with Cyber Security News (CSN) highlighted several red flags: the binary lacked a code signature, had no timestamp, contained obfuscated code, and exhibited memory-write capabilities. While each of these traits might not be immediately alarming in isolation, their combination strongly indicated a malicious payload bundled with a certified application.

Further investigation revealed that “me.exe” did not appear in every test run, ruling out the possibility of it being a static component of the installer. This inconsistency pointed to a dynamic delivery-path issue, suggesting the binary was being pushed through the update distribution pipeline under specific, yet to be fully understood, conditions. Essentially, AppEsteem had certified a clean version of Hola Browser, but some users were receiving additional, unauthorized software.

Upon escalation of the issue by AppEsteem, Hola’s CEO, Avi Raz Cohen, confirmed that “me.exe” was never intended to be part of their installer. Hola’s internal monitoring had also detected the anomaly, prompting them to engage independent cybersecurity firm Sygnia for a comprehensive forensic review. Sygnia’s findings corroborated a supply chain compromise, impacting approximately 0.1% of Hola Browser users. Crucially, the review confirmed that no user data was accessed or exfiltrated during the incident.

Hola Browser for Windows Delivery Pipeline Compromised

The “me.exe” binary has been identified as a variant of XMRig, a well-known open-source cryptocurrency mining tool. When executed with administrative privileges, the file copies itself to a new location within the Hola directory and establishes persistence by registering itself as a Windows service named “hola_monitor_svc.” This service is configured to auto-start and activate specifically when the host machine is idle, a tactic designed to minimize detection by avoiding noticeable performance degradation during active use.

To further evade detection, the binary also implemented a Windows Defender exclusion, instructing the operating system to ignore its presence. The internal strings found within the file, including explicit references to pausing the miner when user activity is detected, underscore its sophisticated design for stealthy, background operation. Sophos has assigned the detection name Troj/GoMiner-B to this specific threat.

Supply Chain Risk and Pipeline Integrity

This incident serves as a stark reminder that even reputable and certified software can be leveraged as a vector for malicious payloads if the underlying delivery pipeline is compromised. The intermittent appearance of the malicious file across different test environments highlights the difficulty in detecting such threats through conventional certification processes alone. It required the collaborative efforts of third-party testing organizations and security vendor telemetry to fully uncover the scope of the issue.

In response to the discovery, Hola has undertaken a comprehensive remediation effort. The company has rebuilt its distribution pipeline, implemented advanced code-signing verification protocols, and significantly tightened access controls across its entire infrastructure. Hola has also committed to continuous monitoring to ensure that only legitimate and properly signed components reach end-users moving forward. This resolution demonstrates the effectiveness of the certification ecosystem in identifying, escalating, and resolving integrity issues before they can escalate into more severe security breaches.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA256 174086534a2de730058465a4a4e231ce3778ab17ebebfd7f62b3bf9750bc7bdb Hola Browser installer certified hash
SHA1 8046735d354814bf9ef9a053cb9cad8cfec261f2 Hola Browser installer certified hash <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/a85208a1-ec6a-4246-8d69-0ea6ede7d872/Hola-Browser-for-Windows-Delivery-Pipeline-Comprom

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

CybersecuritySecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Microsoft 365 outage bypassed Windows driver auto-update controls

Next Post

Gafgyt Variant Targets Linux Architectures, IoT Devices

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us