Emcodec is a Windows trojan horse that masquerades as an audio or video codec. It was widely used beginning in spring 2005 and was commonly distributed through deceptive websites, particularly pornographic sites, where users were told they needed to download a codec to view media content. Reported variant and lure names include Media Codec, Ecodec, Imediacodec, IntCodec, Pcodec, SVideocodec, Video iCodec, QualityCodec, Vcodec, Zip Codec, zCodec, and ZCODEC. After execution, Emcodec copied files into the Program Files directory, modified Windows registry keys, and displayed a fake end-user license agreement. The zCodec variant reportedly changed DNS settings, monitored browsing activity, and acted as adware. Some Emcodec variants installed Zlob, which in turn could lead to fake security software such as SpywareQuake, SpyFalcon, and WinFixer, and some variants also installed a backdoor on infected systems. Vendor detections mentioned in the content include Symantec Trojan.Emcodec / Trojan.Emcodec.[Letter] and Trend Micro TROJ_CODEC.[Letter], MAL_CODEC, and MAL_CODEC-[Number].
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Some versions of the trojan install malware called Zlob, which in turn may lead to the installation of malicious and fake "security programs" such as SpywareQuake, SpyFalcon, WinFixer or other malware; some variants also install a backdoor into the infected computer.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
2005 Brontok Emcodec Extended Copy Protection PGPCoder PoisonIvy Samy SpySheriff
A Windows trojan disguised as an audio/video codec installer. It is distributed via websites that prompt users to install a supposed codec to view media, then copies files into Program Files, modifies registry keys, displays a fake EULA, and some variants alter DNS settings, monitor browsing, and act as adware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.