Sophos X-Ops reported that Hola Browser version 1.251.91.0 was distributed with an undeclared executable, me.exe, discovered during an AppEsteem Windows Certified Application validation test. The file was absent from the certified component list and showed multiple suspicious characteristics, including no code signing, no timestamp, obfuscated code, memory-write capability, and behavior consistent with a cryptocurrency miner. Sophos said the preserved sample appeared to be an XMRig-based miner and detects it as Troj/GoMiner-B.
Hola said its update distribution pipeline suffered a supply chain compromise that affected about 0.1% of users, adding that it found no evidence of user data access or exfiltration. Sophos assessed the issue was more likely caused by delivery-path or pipeline variance than by a malicious fixed installer payload, and escalated the case through AppEsteem. Hola and AppEsteem said the affected delivery pipeline was halted and rebuilt, while stronger code-signing verification, tighter access controls, continuous monitoring, and a forensic investigation supported by Sygnia were put in place.

Trace attribution and downstream blast radius.
6 events from the most recent confirmed update back to the earliest known activity.
Further analysis of the me.exe payload found it established persistence as the Windows service hola_monitor_svc, ran when systems were idle, and tried to evade detection by adding a Windows Defender exclusion. These details expanded the known technical behavior of the XMRig-based miner delivered through the compromised Hola Browser pipeline.
Sophos identified the preserved me.exe sample as an apparent XMRig-based miner and detects it as Troj/GoMiner-B. This provided technical characterization of the suspicious executable delivered with Hola Browser.
According to Hola and AppEsteem, the affected delivery pipeline was halted and rebuilt following the compromise. They also implemented stronger code-signing verification, tighter access controls, and continuous monitoring.
Hola stated that its update distribution pipeline had suffered a supply chain compromise affecting 0.1% of users. The company said no user data was accessed or exfiltrated and that it had engaged Sygnia to support the forensic investigation.
After analyzing the unexpected executable, Sophos concluded the issue likely resulted from delivery-path or pipeline variance rather than a fixed installer payload. Sophos then escalated the matter through AppEsteem for further handling.
During an AppEsteem Windows Certified Application validation test, Sophos X-Ops discovered an undeclared executable named me.exe being delivered alongside Hola Browser version 1.251.91.0. Sophos found the file suspicious because it was absent from the certified component list and showed traits including no code signing, no timestamp, obfuscated code, memory-write capability, and behavior consistent with a crypto-miner.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
6 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcesophos.com
Open sourcebleepingcomputer.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.