Netskope Threat Labs

Razy

ATP Sandbox Adv. HeuristicsAV

Razy is a trojan typically distributed via malicious advertisements disguised as legitimate software, and operators often use it to steal cryptocurrency data from infected systems. Its lures imitate popular applications on fake download sites, and its payload harvests wallet data and credentials while downloading additional payloads. The family illustrates how malvertising remains a productive channel for reaching users who download software outside official stores.

First seen
January 2022
Last seen
October 2026
razy
Alert Name
Archive-RAR.Trojan.Razy
Binary.Trojan.Razy
ByteCode-MSIL.Trojan.Razy
Document-HTML.Trojan.Razy
Document-Multimedia.Trojan.Razy
Gen:Variant.Adware.ICloader.Razy.22
Gen:Variant.Adware.ICloader.Razy.8
Gen:Variant.Adware.Razy.252182
Gen:Variant.Adware.Razy.63832
Gen:Variant.Adware.Razy.657283