Extended Copy Protection (XCP) is a DRM software package developed by First 4 Internet and used by Sony BMG on some music CDs, becoming central to the 2005 Sony BMG copy protection scandal. On affected Microsoft Windows systems, XCP installed after a user accepted an EULA when attempting to play an affected CD, but the EULA did not disclose that hidden software would be installed. Once present, it remained resident, intercepted CD drive access, and blocked media players and ripping software other than the included player. Researchers, including Mark Russinovich in October 2005, described it as functionally identical to a rootkit because it hid files, processes, and registry keys beginning with "$sys$". This cloaking behavior increased exposure to follow-on malware, and other malware was reported to abuse the hiding mechanism. XCP did not provide an obvious uninstall method, and manual deletion could render the CD drive inoperable due to altered registry settings. Sony’s web-based uninstaller introduced an additional severe security risk: its ActiveX component allowed any website to run software on the user’s computer without restriction, enabling arbitrary code execution. Computer Associates classified XCP as both a trojan horse and a rootkit, reporting that it installed a misleadingly named Windows service, "Plug and Play Device Manager," and a CD-ROM filter driver that inserted noise into audio data returned to unauthorized software. Reported indicators and artifacts include hidden objects prefixed with "$sys$" and the file aries.sys, which users associated with crashes. The issue primarily affected Windows systems; Linux, BSD, OS/2, Solaris, and Mac OS X were not affected in the same way. Sony BMG temporarily suspended manufacturing CDs containing XCP in November 2005 and recalled affected discs after broad security scrutiny, legal action, and remediation efforts by security vendors and Microsoft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2005 Brontok Emcodec Extended Copy Protection PGPCoder PoisonIvy Samy SpySheriff
A Sony BMG CD copy-protection/DRM package developed by First 4 Internet that installs hidden software on Windows systems, intercepts CD drive access, cloaks files/processes/registry keys beginning with $sys$, phones home, and exposed users to significant security risks including abuse by other malware and unsafe ActiveX-based uninstallation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.