The Shang-Chi Malware Campaign: Is your pirated copy of the summer blockbuster laced with a RAT?
ID: e5ae60be-cf6b-563f-8e93-2c085b66e072
STIX ID: report--e5ae60be-cf6b-563f-8e93-2c085b66e072
Feed Name: CloudSEK Blog
Threat Score
This report describes an active campaign that lures victims via pirated movie files and compromised high-SEO hosting domains; the malicious package includes a hex-encoded payload hidden in an .srt subtitle file and a batch "Ultra XVid Codec Setup.bat" loader that auto-elevates UAC, disables monitoring for .exe and .srt, uses certutil to decode the payload, executes the resulting RAT (route.exe / zroute.exe) which persists via a Run registry key, and reports to listed C2 IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
