Sony rootkit refers to the anti-piracy software covertly installed on PCs during the 2005 Sony BMG copy protection rootkit scandal. The provided content identifies it as malware/rootkit associated with Sony BMG’s copy-protection scheme and notes that Dan Kaminsky used DNS cache snooping during the incident to estimate that at least 568,000 networks had computers with the Sony rootkit. High-confidence details in the content are limited: it was installed covertly on PCs as part of Sony BMG copy protection, was widely discussed as a rootkit scandal in 2005, and had significant enough prevalence to be measured at Internet scale. No additional verified details on infection vector beyond the copy-protection installation, technical capabilities, specific indicators of compromise, or associated threat actor beyond Sony BMG are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware 2005 ... Samy Sony rootkit
Covert copy-protection software installed on PCs that used rootkit techniques; the content highlights Kaminsky’s measurement of infections via DNS cache snooping.
2005 ... Sony rootkit
2005 Sony BMG copy protection rootkit scandal ... Sony rootkit
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.