Darktrace Hola VPN Exploitation Leads to Malware and Cryptomining Activities
Article Content
- •Hola VPN's peer-to-peer design exposes users to significant security risks.
- •Malicious activities included downloading executables from flagged IPs linked to malware.
- •The incident involved a Monero-mining binary distributed via compromised Hola infrastructure.
In early 2026, Darktrace identified malicious activities linked to Hola VPN, a peer-to-peer VPN service. The exploitation involved devices acting as routing nodes, leading to lateral movement and command-and-control communications. Multiple customer environments showed anomalous behavior, including connections to Hola-related endpoints and downloads of suspicious executables from flagged IP addresses. The downloads were associated with user agents tied to Hola VPN, suggesting a coordinated effort to distribute malware. Notably, a binary named me.exe was identified as a Monero-mining component, introduced via a compromised delivery pipeline. Darktrace first detected this activity on January 19, 2026, with patterns persisting until March 4, 2026. The incident highlights the risks of non-compliant software in enterprise settings.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Rhadamanthys in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mass Credential Exposures Across Major Corporations Lunar Cyber reported 747,485 credential exposure events linked to ten large organizations, primarily in technology, finance, and retail. The analysis revealed that infostealer malware and breach databases were responsible for these exposures, with Apple showing over 46 million total events, but only 209,767 tied to…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…