New Razy Trojan Spoofs Search Results, Infects Browser Extensions to Steal Cryptocurrency: Kaspersky

Advertisement
By Tasneem Akolawala | Updated: 25 January 2019 19:19 IST
Highlights
  • Razy Trojan was discovered by Kaspersky Labs
  • It is able to spoof Google and Yandex search results
  • It's main aim is to steal cryptocurrency

The new Trojan Razy can infect Google Chrome, Mozilla Firefox and Yandex Browser

Kaspersky Lab has discovered a new 'Razy' Trojan that it says spoofs search results and targets browser extensions in a bid to attack cryptocurrency wallets. It found a malicious program called Trojan.Win32.Razy.gen in an executable file that spreads via advertising blocks on websites and is distributed from free file-hosting services under the guise of legitimate software. It mainly indulges in theft of cryptocurrency.

Razy Trojan is said to search for addresses of cryptocurrency wallets on websites and replace them with the threat actor's wallet addresses; spoof images of QR codes pointing to wallets; modify the webpages of cryptocurrency exchanges, and also spoof Google and Yandex search results as well.

Kaspersky claims that Razy can infect extensions of Google Chrome, Mozilla Firefox, and Yandex Browser, though it has different infection scenarios for each browser type. For Firefox, the Trojan installs an extension called 'Firefox Protection', on the Yandex browser it installs the extension called Yandex Protect, and in Chrome Razy modifies the contents of the folder where the Chrome Media Router extension is located.

Advertisement

The Razy Trojan is said to spoof search results by showing fake links that are added to pages if the search request is connected with cryptocurrencies and cryptocurrency exchanges, or just music downloading or torrents. After the user's system is infected, the Trojan adds a banner containing a request for donations to support Wikipedia, whenever the user visits the site. The cybercriminals' wallet addresses are used in place of bank details. The original Wikipedia banner asking for donations (if present) is deleted. Kaspersky notes that when the user visits the webpage telegram.org, they will see an offer to buy Telegram tokens at an incredibly low price.

Advertisement

Similarly, when users visit the pages of Russian social network Vkontakte (VK), the Trojan adds an advertising banner to it. If a user clicks on the banner, they are redirected to phishing resources (located on the domain ooo-ooo[.]info), where they are prompted to pay a small sum of money now to make a load of money later on.

Kaspersky also listed the wallet addresses detected in the analysed scripts, for users to be more aware:

Advertisement
  • Bitcoin: '1BcJZis6Hu2a7mkcrKxRYxXmz6fMpsAN3L', '1CZVki6tqgu2t4ACk84voVpnGpQZMAVzWq', '3KgyGrCiMRpXTihZWY1yZiXnL46KUBzMEY', '1DgjRqs9SwhyuKe8KSMkE1Jjrs59VZhNyj', '35muZpFLAQcxjDFDsMrSVPc8WbTxw3TTMC', '34pzTteax2EGvrjw3wNMxaPi6misyaWLeJ'.
  • Ethereum: '33a7305aE6B77f3810364e89821E9B22e6a22d43′, '2571B96E2d75b7EC617Fdd83b9e85370E833b3b1′, '78f7cb5D4750557656f5220A86Bc4FD2C85Ed9a3'.

The report says that the total incoming transactions on all these wallets amounted to approximately 0.14 BTC plus 25 ETH, at the time of writing.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Kaspersky Labs, Trojan, Razy Trojan
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Teases OnePlus Turbo 6 Series China Launch Date, Key Specs
  2. Vijay Sales Announces Apple Days Sale With Offers on These Apple Products
  3. Here's How Much the Oppo Reno 15 Pro Mini Might Cost in India
  4. Realme 16 Pro+ 5G Confirmed to Launch With This Snapdragon Chipset
  5. Vivo X300 Ultra Surfaces on Certification Website Ahead of 2026 Launch
  6. Why the Samsung Galaxy S26 Series Might Launch at a Higher Price in 2026
  7. Gadgets 360 Picks Best Camera Smartphones of 2025
  8. OnePlus Turbo 6, Turbo 6V Price Range Leaked, Might Cost More in India
  9. Vivo V70 Elite 5G, Vivo Y51 5G Listed on BIS Database, Could Launch Soon
  10. Honor Power 2 Will Launch Next Month With This Massive Battery Upgrade
  1. Foxconn’s Manufacturing Expansion in India Is Straight Out of Its China Playbook
  2. Oppo Pad 5 Will Launch in India Alongside Oppo Reno 15 Series; Flipkart Availability Confirmed
  3. Biggest Space Discoveries in 2025: From New Comets and Black Holes to Sign of Life on Mars
  4. Samsung AI TVs to Bring Google Photos’ Memories Features Next Year
  5. Athibheekara Kaamukan Streaming Now on Prime Video: Everything You Need to Know About Cast, Crew, Plot, and More
  6. Phoenix OTT Release Date: Know When and Where to Watch This Tamil Action-Drama Online
  7. Poco M8 5G Design Teased Ahead of India Launch; Confirmed to Sport Slim 7.35mm Profile
  8. Vivo Y31d Confirmed to Launch Soon With 7,200mAh Battery; Might Not Debut in India, Tipster Claims
  9. Realme 16 Pro+ 5G Chipset, Display and Other Features Confirmed Ahead of January 6 India Launch
  10. OnePlus Turbo 6, Turbo 6V Price Range Leaked; RAM and Storage Configurations Officially Revealed
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.