Razy is a Windows malware family centered on malicious browser-extension abuse for cryptocurrency theft, fraud, and web-content manipulation. It targets Chromium-based browsers and Mozilla Firefox, including Google Chrome and Yandex Browser, by disabling extension integrity protections and browser auto-updates, then installing a rogue extension or modifying an existing one. Documented infections include replacement or compromise of legitimate extensions and abuse of built-in browser components to gain persistent access to web sessions and page content.
Its primary objective is crypto-focused theft and monetization. Razy modifies visited webpages to replace cryptocurrency wallet addresses with attacker-controlled ones, substitutes wallet QR codes, alters pages on cryptocurrency exchanges, injects fraudulent prompts intended to trick victims into transferring funds, and replaces donation requests with attacker-controlled payment details. It also manipulates Google and Yandex search results, inserts advertising content, and injects phishing or scam material into selected sites. Auxiliary scripts have been used to inject remote content into pages and send telemetry.
Razy has been distributed while masquerading as legitimate software through advertising blocks on websites and free file-hosting services. It has also appeared as a payload in broader malware-delivery campaigns. The malware is notable for browser-specific tampering methods, including direct modification of browser files and extension metadata to preserve malicious extensions and resist remediation. High-confidence reporting associates Razy with theft and fraud operations rather than a publicly established named threat actor. Targeting is opportunistic and focused on users of supported browsers, especially those interacting with cryptocurrency services or search engines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
To disable browser updates, it creates the registry key ‘HKEY_LOCAL_MACHINE\SOFTWARE\Policies\YandexBrowser\UpdateAllowed” = 0 (REG_DWORD).
Putting into place the security measures to detect the C&C server communications of a malicious Chrome extension, or any malware for that matter, will fill this gap.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Razy is referenced as malware involved in a Chrome extension outbreak, illustrating how malicious browser extensions can manipulate browser behavior and contribute to broader malware activity.
Razy is a trojan that infects or installs malicious browser extensions in Chrome, Firefox, and Yandex Browser by disabling extension integrity checks and browser updates. It modifies web pages, replaces cryptocurrency wallet addresses and QR codes with attacker-controlled ones, injects ads, spoofs search results, and displays phishing or scam content on cryptocurrency, Wikipedia, Telegram, and VK-related pages.
Payload family delivered via malicious archives; described as having keylogging/password stealing and standard RAT capabilities in this campaign set.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.