Razy in search of cryptocurrency
#1
Information 
[Image: 190124-cryptobrowser-1.png]

Quote:Spoofing search results and infecting browser extensions

Last year, we discovered malware that installs a malicious browser extension on its victim’s computer or infects an already installed extension. To do so, it disables the integrity check for installed extensions and automatic updates for the targeted browser. Kaspersky Lab products detect the malicious program as Trojan.Win32.Razy.gen – an executable file that spreads via advertising blocks on websites and is distributed from free file-hosting services under the guise of legitimate software.
Razy serves several purposes, mostly related to the theft of cryptocurrency. Its main tool is the script main.js that is capable of:
  • Searching for addresses of cryptocurrency wallets on websites and replacing them with the threat actor’s wallet addresses

  • Spoofing images of QR codes pointing to wallets

  • Modifying the web pages of cryptocurrency exchanges

  • Spoofing Google and Yandex search results
Infection

The Trojan Razy ‘works’ with Google Chrome, Mozilla Firefox and Yandex Browser, though it has different infection scenarios for each browser type.

Mozilla Firefox

For Firefox, the Trojan installs an extension called ‘Firefox Protection’ with the ID {ab10d63e-3096-4492-ab0e-5edcf4baf988} (folder path: “%APPDATA%\Mozilla\Firefox\Profiles\.default\Extensions\{ab10d63e-3096-4492-ab0e-5edcf4baf988}”).

For the malicious extension to start working, Razy edits the following files:
  • “%APPDATA%\Mozilla\Firefox\Profiles\.default\prefs.js”,

  • “%APPDATA%\Mozilla\Firefox\Profiles\.default\extensions.json”,

  • “%PROGRAMFILES%\Mozilla Firefox\omni.js”.
Full reading: https://securelist.com/razy-in-search-of...ncy/89485/
[-] The following 2 users say Thank You to harlan4096 for this post:
  • Deep900, silversurfer
Reply


Messages In This Thread
Razy in search of cryptocurrency - by harlan4096 - 25 January 19, 09:20

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Recover Corrupted EDB to PST
If you want to recov...AlbertTaylor — 10:40
Recover Corrupted EDB to PST
Safely recover your ...Jyoti_baghel — 05:25
GFYI [Official] AirVPN 2025 Christmas / ...
  We at Geeks For Y...jasonX — 20:47
GFYI [Official] Macrium Reflect X Home E...
  We at Geeks For ...jasonX — 20:39
GFYI [Official] Hasleo Backup Suite Vers...
  We at Geeks For ...jasonX — 20:32

[-]
Birthdays
Today's Birthdays
avatar (41)Enlargedterrestrial20
Upcoming Birthdays
avatar (43)ivyhuv

[-]
Online Staff
zevish's profile zevish

>