Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The activity described is a recon-first cryptomining operation that profiles Linux hosts for CPU, GPU, RAM, uptime, and privilege level before deciding whether to deploy a miner, with Monero mining cited as the likely end goal.
Hidden executable delivered via a supply-chain compromise of the Hola browser for Windows. The malware behaved as a cryptominer, added itself to Microsoft Defender exclusions, copied itself as HolaMonitorService.exe, created the Windows service hola_monitor_svc for persistence, and mined only during system idle periods.
Cryptocurrency (XMR) referenced in the context of a mining campaign (cryptomining activity).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.