Skip to content
Hola VPN Exploitation Leads to Malware and Cryptomining Activities

Hola VPN Exploitation Leads to Malware and Cryptomining Activities

First seen 16 Jun 2026, 04:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 17, 2026 at 04:44 UTC
  • Hola VPN's peer-to-peer design exposes users to significant security risks.
  • Malicious activities included downloading executables from flagged IPs linked to malware.
  • The incident involved a Monero-mining binary distributed via compromised Hola infrastructure.

In early 2026, Darktrace identified malicious activities linked to Hola VPN, a peer-to-peer VPN service. The exploitation involved devices acting as routing nodes, leading to lateral movement and command-and-control communications. Multiple customer environments showed anomalous behavior, including connections to Hola-related endpoints and downloads of suspicious executables from flagged IP addresses. The downloads were associated with user agents tied to Hola VPN, suggesting a coordinated effort to distribute malware. Notably, a binary named me.exe was identified as a Monero-mining component, introduced via a compromised delivery pipeline. Darktrace first detected this activity on January 19, 2026, with patterns persisting until March 4, 2026. The incident highlights the risks of non-compliant software in enterprise settings.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2026-01-19
New device detected on customer network
A device communicated with Hola VPN infrastructure and began downloading binaries from a hola.org subdomain.
Darktrace
2026-01-19 to 2026-03-04
Recurring malicious activity observed
The device issued multiple HTTP GET requests, indicating structured file transfers and potential malware downloads.
Darktrace
Recent
Hola VPN abuse reported widely
Darktrace documented patterns of suspicious behavior across multiple customer environments, raising alarms about Hola VPN's security implications.
Darktrace

More articles in this cluster (2)

Following this threat?

Track Rhadamanthys in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed