HomeSecurityWarning: New malware is looking to steal your encryption!

Warning: New malware is looking to steal your encryption!

According to a new study by cybersecurity firm Kaspersky, a malware program called "Razy" has been found to infect browser and spoof search results, with the sole purpose of stealing your encryption.

malware

Many times users have wondered how it is possible for ads to appear in browsers, which lead to pop-up pornography. The reason behind this is because browser extensions have been infected with malware that seeks to steal encryption. According to a recent study at Kaspersky, the malware program “Razy” attempts to steal the user’s encryption

How Razy steal your crypto?

Let's first see how cryptocurrency is stolen. In particular, the method of theft depends on how and where the user has stored the cryptocurrency. Cryptocurrency consists of values ​​stored on the blockchain under different addresses. Someone can exchange these values ​​between different addresses, using the private key of each address. If an address and the private key are stored somewhere, then the location is called a wallet. Just as in the material world we have a wallet with money and cards, we ourselves are responsible for its contents. If someone steals it, then the money will be lost forever. In the same way on the computer, when a malware program searches for cryptocurrency wallets on websites, it tries to replace them with the addresses of the person it threatens. It should be noted that so far, the malicious program "Trojan.Win32.Razy.gen" can work in Google Chrome, Mozilla Firefox and Yandex browser.

In Firefox, Razy installs an extension called “Firefox Protection”. In Yandex, Razy edits a file to disable the security check in the browser and creates a registry key to disable security updates. It then installs a malicious extension called Yandex Protect and in the same way in Google Chrome, it edits files, disables the security check and infects the existing extension. In addition, “Main.js” scans and processes Google and Yandex results and displays fake results on pages if the search query is related to crypto exchanges or simply to music downloads or torrents. So this is how users are lured to visit infected websites with fake messages.

According to the Kaspersky report, Razy’s codes show fake messages to the user that appear as new features on crypto exchanges and then offer to sell crypto at specific numbers. In simple terms, users are convinced to transfer their money to the criminal’s wallet under the guise of a good deal.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS