logo

The Shang-Chi Malware Campaign: Is your pirated copy of the summer blockbuster laced with a RAT?

ID: e5ae60be-cf6b-563f-8e93-2c085b66e072

STIX ID: report--e5ae60be-cf6b-563f-8e93-2c085b66e072

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2021-10-12

Date Updated: 2026-04-27

...
...

This report describes an active campaign that lures victims via pirated movie files and compromised high-SEO hosting domains; the malicious package includes a hex-encoded payload hidden in an .srt subtitle file and a batch "Ultra XVid Codec Setup.bat" loader that auto-elevates UAC, disables monitoring for .exe and .srt, uses certutil to decode the payload, executes the resulting RAT (route.exe / zroute.exe) which persists via a Run registry key, and reports to listed C2 IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.