Razy is a Windows malware family best characterized as an infostealer and browser-manipulation trojan focused on cryptocurrency theft and online fraud. It targets Chromium-based browsers, Mozilla Firefox, and Yandex Browser by tampering with browser components, disabling extension integrity protections, and suppressing browser auto-updates so its modifications persist. Razy can install a malicious browser extension or hijack an existing one, including legitimate or built-in extensions, then use injected scripts to alter web content viewed by the victim.
Its core behavior centers on web injection and theft of cryptocurrency transactions. Razy replaces cryptocurrency wallet addresses embedded in webpages, substitutes QR codes used for wallet payments, alters pages on cryptocurrency exchanges, injects fraudulent prompts intended to trick users into transferring funds, and modifies search-engine results to insert scam or malware-lure content. It has also been observed replacing donation prompts with attacker-controlled cryptocurrency payment requests and loading phishing content when users visit selected high-interest sites. Auxiliary scripts support page injection, advertising insertion, telemetry, and remote content loading.
Razy has been distributed through deceptive software offerings on free file-hosting services and through malicious advertising. It has also appeared as a payload in exploitation campaigns abusing WinRAR path traversal vulnerability CVE-2018-20250, where archive extraction could place malware for execution and persistence on Windows systems. In addition, Razy has been referenced in broader intrusion activity in which state-linked operators used commodity malware families alongside other tooling, including campaigns associated with suspected Chinese threat activity targeting manufacturing, retail, chemicals, sporting goods, cosmetics, product and IT firms, and critical infrastructure for sensitive data theft and intellectual property theft.
The malware is notable for combining browser compromise, defense evasion, and financially motivated fraud. By disabling browser updates and integrity checks, infecting extensions, and injecting remotely supplied scripts into browsing sessions, Razy can maintain long-lived manipulation of user web activity while evading straightforward remediation until the underlying browser components are restored.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
To disable browser updates, it creates the registry key ‘HKEY_LOCAL_MACHINE\SOFTWARE\Policies\YandexBrowser\UpdateAllowed” = 0 (REG_DWORD).
Putting into place the security measures to detect the C&C server communications of a malicious Chrome extension, or any malware for that matter, will fill this gap.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commodity trojan observed in a suspected Stone Panda/Gothic Panda-linked campaign focused on sensitive data and intellectual property theft across manufacturing, retail, cosmetics, and critical infrastructure sectors.
Razy is referenced as malware involved in a Chrome extension outbreak, illustrating how malicious browser extensions can manipulate browser behavior and contribute to broader malware activity.
Razy is a trojan that infects or installs malicious browser extensions in Chrome, Firefox, and Yandex Browser by disabling extension integrity checks and browser updates. It modifies web pages, replaces cryptocurrency wallet addresses and QR codes with attacker-controlled ones, injects ads, spoofs search results, and displays phishing or scam content on cryptocurrency, Wikipedia, Telegram, and VK-related pages.
Payload family delivered via malicious archives; described as having keylogging/password stealing and standard RAT capabilities in this campaign set.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.