Darktrace
Hola VPN Exploitation Leads to Malware and Cryptomining Activities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In early 2026, Darktrace identified malicious activities linked to Hola VPN, a peer-to-peer VPN service. The exploitation involved devices acting as routing nodes, leading to lateral movement and command-and-control communications. Multiple customer environments showed anomalous behavior, including connections to Hola-related endpoints and downloads of suspicious executables from flagged IP addresses. The downloads were associated with user agents tied to Hola VPN, suggesting a coordinated effort to distribute malware. Notably, a binary named me.exe was identified as a Monero-mining component, introduced via a compromised delivery pipeline. Darktrace first detected this activity on January 19, 2026, with patterns persisting until March 4, 2026. The incident highlights the risks of non-compliant software in enterprise settings.
Key Points: • Hola VPN's peer-to-peer design exposes users to significant security risks. • Malicious activities included downloading executables from flagged IPs linked to malware. • The incident involved a Monero-mining binary distributed via compromised Hola infrastructure.