{
  "family": "razy",
  "sample_count": 3391,
  "category": "infostealer",
  "description": "Razy is a malware family that targets cryptocurrency. According to analysis published by Kaspersky, Razy installs or abuses a malicious browser extension in order to steal cryptocurrency from its victims. By operating inside the browser, it can interfere with how cryptocurrency-related web pages are displayed and how transactions are handled, allowing it to redirect funds or harvest wallet information.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Razy"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is the Razy malware family?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Razy is malware focused on cryptocurrency theft. As described by Kaspersky, it uses a malicious browser extension to steal cryptocurrency from infected users."
      }
    },
    {
      "@type": "Question",
      "name": "How does Razy steal cryptocurrency?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Razy operates through a malicious browser extension, which lets it tamper with cryptocurrency-related web content and the browser environment in order to capture or redirect funds."
      }
    },
    {
      "@type": "Question",
      "name": "Why does Razy target browsers?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Cryptocurrency transactions are frequently performed through web interfaces, so by embedding itself as a browser extension Razy gains a position to observe and manipulate those activities."
      }
    }
  ],
  "faq_count": 3,
  "mitre_attack": [
    "T1176",
    "T1539",
    "T1555.003",
    "T1clipboard",
    "T1041"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-06-11",
  "sources": [
    {
      "name": "Kaspersky: \"Razy in search of cryptocurrency\" (Vlasova, Bogdanov)",
      "url": "https://malpedia.caad.fkie.fraunhofer.de/details/win.razy"
    }
  ],
  "target_industries": [
    "Financial Services",
    "Retail",
    "Consumers"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}