Hola VPN Exploitation Leads to Malware and Cryptomining Activities

Hola VPN Exploitation Leads to Malware and Cryptomining Activities

First seen 16 Jun 2026, 04:52 UTC Darktrace 100% similarity 64.5

Article Content

Browse articles
ThreatCluster

In early 2026, Darktrace identified malicious activities linked to Hola VPN, a peer-to-peer VPN service. The exploitation involved devices acting as routing nodes, leading to lateral movement and command-and-control communications. Multiple customer environments showed anomalous behavior, including connections to Hola-related endpoints and downloads of suspicious executables from flagged IP addresses. The downloads were associated with user agents tied to Hola VPN, suggesting a coordinated effort to distribute malware. Notably, a binary named me.exe was identified as a Monero-mining component, introduced via a compromised delivery pipeline. Darktrace first detected this activity on January 19, 2026, with patterns persisting until March 4, 2026. The incident highlights the risks of non-compliant software in enterprise settings.

Key Points: • Hola VPN's peer-to-peer design exposes users to significant security risks. • Malicious activities included downloading executables from flagged IPs linked to malware. • The incident involved a Monero-mining binary distributed via compromised Hola infrastructure.

ThreatCluster AI How this analysis works

Timeline

2026-01-19
New device detected on customer network
A device communicated with Hola VPN infrastructure and began downloading binaries from a hola.org subdomain.
Darktrace
2026-01-19 to 2026-03-04
Recurring malicious activity observed
The device issued multiple HTTP GET requests, indicating structured file transfers and potential malware downloads.
Darktrace
Recent
Hola VPN abuse reported widely
Darktrace documented patterns of suspicious behavior across multiple customer environments, raising alarms about Hola VPN's security implications.
Darktrace

Community

Browse all →

Tracked Entities in This Story