Hola Browser for Windows Update Mechanism Used to Deliver Cryptominer
Key Takeaways Hola Browser for Windows’ update mechanism was compromised to deliver an undeclared cryptominer (me.exe). The malicious executable, identified as Troj/GoMiner-B by Sophos, is...
Key Takeaways
- Hola Browser for Windows’ update mechanism was compromised to deliver an undeclared cryptominer (me.exe).
- The malicious executable, identified as Troj/GoMiner-B by Sophos, is based on XMRig and runs covertly in the background, primarily when the system is idle.
- The compromise affected approximately 0.1% of Hola Browser users, but no user data was reportedly accessed or exfiltrated.
- The issue was discovered during a routine certification review by AppEsteem and has since been fully remediated by Hola.
A significant supply chain security incident has emerged, involving Hola Browser for Windows, a widely used application. Cybersecurity researchers recently uncovered that the browser’s official distribution channel was exploited to deliver an unauthorized cryptominer to a segment of its user base.
Table Of Content
The malicious file, named “me.exe,” was found being distributed alongside the legitimate Hola Browser installer. This executable was not part of the browser’s approved software package and was surreptitiously installed on users’ systems without their knowledge or consent, as detailed in a report.
The discovery was made during a routine certification audit conducted by AppEsteem, an AMTSO-certified organization established in 2016. AppEsteem regularly performs validation tests to ensure that certified software adheres to its declared and approved installation footprint. During one such test involving Hola Browser version 1.251.91.0, the “me.exe” file was unexpectedly found within the browser’s installation directory at C:Program FilesHolame.exe.
Sophos Identifies Cryptominer Characteristics
Analysts at Sophos X-Ops identified the suspicious file during the certification test, classifying it as a Potentially Unwanted Application (PUA). A Sophos report shared with Cyber Security News (CSN) highlighted several red flags: the binary lacked a code signature, had no timestamp, contained obfuscated code, and exhibited memory-write capabilities. While each of these traits might not be immediately alarming in isolation, their combination strongly indicated a malicious payload bundled with a certified application.
Further investigation revealed that “me.exe” did not appear in every test run, ruling out the possibility of it being a static component of the installer. This inconsistency pointed to a dynamic delivery-path issue, suggesting the binary was being pushed through the update distribution pipeline under specific, yet to be fully understood, conditions. Essentially, AppEsteem had certified a clean version of Hola Browser, but some users were receiving additional, unauthorized software.
Upon escalation of the issue by AppEsteem, Hola’s CEO, Avi Raz Cohen, confirmed that “me.exe” was never intended to be part of their installer. Hola’s internal monitoring had also detected the anomaly, prompting them to engage independent cybersecurity firm Sygnia for a comprehensive forensic review. Sygnia’s findings corroborated a supply chain compromise, impacting approximately 0.1% of Hola Browser users. Crucially, the review confirmed that no user data was accessed or exfiltrated during the incident.
Hola Browser for Windows Delivery Pipeline Compromised
The “me.exe” binary has been identified as a variant of XMRig, a well-known open-source cryptocurrency mining tool. When executed with administrative privileges, the file copies itself to a new location within the Hola directory and establishes persistence by registering itself as a Windows service named “hola_monitor_svc.” This service is configured to auto-start and activate specifically when the host machine is idle, a tactic designed to minimize detection by avoiding noticeable performance degradation during active use.
To further evade detection, the binary also implemented a Windows Defender exclusion, instructing the operating system to ignore its presence. The internal strings found within the file, including explicit references to pausing the miner when user activity is detected, underscore its sophisticated design for stealthy, background operation. Sophos has assigned the detection name Troj/GoMiner-B to this specific threat.
Supply Chain Risk and Pipeline Integrity
This incident serves as a stark reminder that even reputable and certified software can be leveraged as a vector for malicious payloads if the underlying delivery pipeline is compromised. The intermittent appearance of the malicious file across different test environments highlights the difficulty in detecting such threats through conventional certification processes alone. It required the collaborative efforts of third-party testing organizations and security vendor telemetry to fully uncover the scope of the issue.
In response to the discovery, Hola has undertaken a comprehensive remediation effort. The company has rebuilt its distribution pipeline, implemented advanced code-signing verification protocols, and significantly tightened access controls across its entire infrastructure. Hola has also committed to continuous monitoring to ensure that only legitimate and properly signed components reach end-users moving forward. This resolution demonstrates the effectiveness of the certification ecosystem in identifying, escalating, and resolving integrity issues before they can escalate into more severe security breaches.
Indicators of Compromise (IoCs):-



No Comment! Be the first one.