News.Sophos
Hola Browser Compromised to Deliver Cryptominer via Supply Chain Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Hola Browser for Windows (version 1.251.91.0) was compromised in a supply chain attack, delivering an undeclared executable identified as a cryptocurrency miner. This issue was discovered during AppEsteem certification checks, which revealed the presence of the executable 'me.exe' in some installations. The binary lacked code signing, a timestamp, and contained obfuscated code, indicating malicious intent. Hola confirmed the compromise, stating that only 0.1% of users were affected and that no user data was accessed or stolen. The company has since rebuilt its distribution pipeline and implemented advanced security measures. The incident highlights significant vulnerabilities in software supply chains and the importance of rigorous application integrity checks.
Key Points: • Hola Browser was compromised to deliver a crypto-miner via supply chain attack. • The malicious executable 'me.exe' was not part of the certified application footprint. • Hola has implemented new security measures to prevent future incidents.