The Sony BMG Rootkit Scandal — 20 Years Later

Updated: 23 February, 2026

The Sony BMG Rootkit Scandal — 20 Years Later

In late October 2005, a security researcher sat at his desk testing an updated version of his rootkit detection tool. What he found on his own computer would ignite one of the biggest corporate cybersecurity scandals in history — and permanently change the music industry’s relationship with digital rights management.

This is the story of how Sony BMG secretly installed rootkits on millions of computers worldwide, got caught, made it worse, and ultimately helped kill music DRM forever.

The Man Who Found It

Mark Eugene Russinovich was born on December 22, 1966, in Salamanca, Spain — the grandson of Croatian diplomat Nikola Rusinovic. His family later moved to the United States, where he was raised in Birmingham, Alabama, and then Pittsburgh, Pennsylvania.

Russinovich earned a B.S. in Computer Engineering from Carnegie Mellon University in 1989, an M.S. from Rensselaer Polytechnic Institute in 1990, and a Ph.D. from Carnegie Mellon in 1994. By 2005, at age 38, he was co-founder and Chief Software Architect of Winternals Software, and the man behind Sysinternals.com — a site that provided some of the most powerful free Windows diagnostic tools available.

On October 31, 2005 — Halloween — Russinovich published a blog post on Sysinternals titled “Sony, Rootkits and Digital Rights Management Gone Too Far.” While testing an updated version of his tool RootkitRevealer, he had discovered a rootkit hiding on his own computer. After tracing the infection, he found the source: a Sony BMG music CD he had purchased — Get Right with the Man by Van Zant.

He was not the first to discover it. Other security researchers had found the rootkit earlier but were advised by their lawyers that publishing their findings would violate Section 1201 of the DMCA — the prohibition on circumventing copyright protection measures. Russinovich was the first to defy this chilling effect and go public.

The Company That Built It

The rootkit was created by First 4 Internet Ltd, a British company based in Banbury, Oxfordshire, England (later Bridgend, Wales). The company was co-founded in 1999 by Mathew Gilliat-Smith (CEO) and Anthony Miles (CTO).

Their product was called XCP — Extended Copy Protection. Sony BMG licensed it to prevent CD copying. When the scandal broke, Gilliat-Smith dismissed the controversy as “a tempest in a teacup” and insisted the software was “not designed to be sneaky.”

After the fallout, First 4 Internet quietly renamed itself Fortium Technologies Ltd on November 20, 2006 — exactly one year after the worst of the scandal. They pivoted to enterprise content protection for the film industry. Ironically, their later clients included Sony Pictures, Disney, NBC Universal, and Warner Bros. The company still exists today.

What the Rootkit Actually Did

When a user inserted an XCP-protected CD into a Windows PC with AutoPlay enabled, it presented an End User License Agreement that made no mention of the hidden software. If accepted, XCP installed itself silently with administrative privileges.

The core was a kernel-level driver named $sys$aries that hooked into Windows system calls — specifically NtCreateFile, NtEnumerateKey, NtOpenKey, NtQueryDirectoryFile, and NtQuerySystemInformation. It filtered out any file, process, or registry key whose name began with the prefix $sys$, making them invisible to the user, to Windows Explorer, to Task Manager, and even to antivirus software.

The hidden components included:

  • aries.sys — the rootkit driver that intercepted OS messages
  • crater.sys — a filter driver that prevented other software from reading the CD-ROM directly
  • $sys$DRMServer.exe — the DRM enforcement service, deceptively named “Plug and Play Device Manager”
  • $sys$parking — a counter tracking how many times burning applications had been used

The DRM executable ran as a Windows service that polled all running processes approximately every 1.5 seconds, causing near-continuous hard drive activity. When it detected a copying attempt, it replaced audio output with random noise.

There was no uninstaller. No way for users to find it. No way to safely remove it. Manual removal attempts could cripple Windows, causing it to stop recognizing CD/DVD drives entirely.

As F-Secure concluded in their analysis: “Although the software isn’t directly malicious, the used rootkit hiding techniques are exactly the same used by malicious software to hide themselves.”

Computer Associates went further, classifying XCP as both a trojan horse and a rootkit, noting that even after Sony’s patches, the software continued to fail their security scorecard.

The Phone Home

Every time a user played a protected CD, XCP silently contacted Sony BMG’s servers via HTTP, transmitting the CD identifier, the user’s IP address, and details about the media player being used. This happened across firewalls, without user knowledge or consent.

The EULA explicitly stated: “No information is ever collected about you or your computer.” This was a lie.

Security researcher Dan Kaminsky used DNS cache snooping on the phone-home domains (update.xcp-aurora.com and connected.sonymusic.com) to map the global infection. His findings were staggering: at least 568,200 nameservers across 131 countries showed signs of infection, suggesting millions of compromised computers. The heaviest concentrations were in Japan (approximately 200,000 infections), the United States (approximately 130,000), and the United Kingdom (approximately 44,000).

The global spread was itself an irony. XCP-protected CDs were only sold in North America. The rootkit reached 131 countries because pirated copies of the DRM-laden CDs spread it worldwide — the ultimate failure of copy protection.

The Uninstaller Debacle

Sony’s response to the crisis made things worse at every turn.

On November 4, 2005, Sony BMG’s President of Global Digital Business, Thomas Hesse, went on NPR’s Morning Edition and delivered what became one of the most notorious corporate PR blunders in tech history: “Most people, I think, don’t even know what a rootkit is, so why should they care about it?”

Sony then announced an “uninstaller” — but only to the press, not to customers. As Russinovich documented in his November 9 blog post titled “Sony: You don’t reeeeaaaally want to uninstall, do you?”:

Visit www.sonybmg.com and search for the support site Sony has made available to the press. There’s no information on this story anywhere on the front page, no support link, and the FAQ only contains information about Sony’s merger with BMG.

For users who did discover the uninstaller, the process was deliberately hostile:

  1. Visit Sony’s support site and guess where to find the uninstall information
  2. Fill out a form with your email address and purchasing information (adding yourself to Sony’s marketing lists)
  3. Receive an email with a “Case ID”
  4. Visit another page and install an ActiveX control signed by First 4 Internet
  5. Enter your case ID and explain why you want to uninstall
  6. Wait up to one business day for an email with a cryptic, personalized uninstall link
  7. The link expires in one week and only works on the specific computer where you started the process

Russinovich’s verdict: “Without exaggeration I can say that I’ve analyzed virulent forms of spyware/adware that provide more straightforward means of uninstall.”

But the worst part was the ActiveX control itself. It was marked “Safe for Scripting,” meaning any website — not just Sony’s — could invoke its methods. Security researchers discovered it contained methods that allowed arbitrary code upload and execution. Sony’s “uninstaller” had turned every computer it touched into a wide-open backdoor. At least two malicious websites were found exploiting this vulnerability before Microsoft issued a “killbit” to disable the control.


The US-CERT (Department of Homeland Security) issued a formal advisory warning that “Sony’s uninstallation options introduce further vulnerabilities.”

The Exploitation

The $sys$ cloaking mechanism was not limited to Sony’s own files. Any malware author could hide their code simply by naming it with a $sys$ prefix. The first trojan exploiting this — known as Breplibot (also called Stinx-E or Ryknos) — appeared on November 10, 2005, just nine days after Russinovich’s disclosure. It was distributed via email to subscribers of a British business magazine and installed a backdoor connecting to IRC channels for remote control.

In June 2006, London’s Metropolitan Police Computer Crime Unit arrested three men suspected of writing the virus — a 63-year-old from England, a 28-year-old from Scotland, and a 19-year-old from Finland.

In a grimly amusing twist, World of Warcraft players discovered they could hide cheat tools from Blizzard’s anti-cheat software “Warden” by simply renaming files with the $sys$ prefix. The rootkit made the cheating tools invisible.

The infection of military and government networks was particularly alarming. Kaminsky confirmed thousands of U.S. military and defense networks were compromised. As he stated: “It is unquestionable that Sony’s code has gotten into military and government networks, and not necessarily just U.S. military and government networks.”

The Open Source Hypocrisy

Researchers Matti Nikki and Sebastian Porst discovered that the XCP software — designed to “protect” Sony’s intellectual property — was itself built on stolen code. The ECDPlayerControl.ocx component contained code from multiple open-source projects licensed under GPL and LGPL: LAME, id3lib, mpglib, mpg123, FAAC, VLC, and — in the ultimate irony — Jon Lech Johansen’s DRMS, a tool originally written to circumvent Apple’s FairPlay DRM.

Sony’s anti-piracy software was itself pirated.

The Legal Storm

The lawsuits came fast and from everywhere.

November 21, 2005: Texas Attorney General Greg Abbott filed the first state lawsuit — also the first case ever brought under Texas’s 2005 spyware law.

New York Attorney General Eliot Spitzer’s investigators found Sony XCP CDs still on sale in New York City stores after the recall had been announced.

The Electronic Frontier Foundation (EFF) filed suit. Class actions were launched in New York (covering all U.S. citizens) and California. Italy’s ALCEI reported it to the Financial Police. Canada saw a class action seeking up to C$1 billion in damages.

Stewart Baker, Assistant Secretary for Policy at the U.S. Department of Homeland Security, publicly rebuked Sony at a trade conference: “It’s very important to remember that it’s your intellectual property; it’s not your computer.”

The settlements unfolded over the following years:

  • Class-action settlement (2006): Consumers could exchange CDs for clean replacements and choose between $7.50 cash plus one free album download, or three free album downloads
  • Multi-state AG settlement (December 2006): $4.25 million to 39 states plus D.C., with consumers able to claim up to $175 for documented computer damage
  • California: $750,000 in fines
  • Texas: $750,000 in legal fees plus consumer remedies
  • FTC settlement (January 2007): Barred Sony from installing software without informed consent, required reimbursement of up to $150 per consumer for computer damage

In July 2007, Sony itself sued First 4 Internet (by then renamed Fortium Technologies) for the damage caused.

The DMCA Problem

The scandal exposed a fundamental flaw in the Digital Millennium Copyright Act. As Avery Morrow argued in his November 2005 proposal for a DMCA exemption:

Forcing the consumer to use dangerous software in order to make fair use of a product should not be within the rights of any property holder.

The fact that researchers who discovered the rootkit before Russinovich were silenced by DMCA fears showed that the law was protecting the attacker — Sony — while preventing defenders from warning the public. Microsoft’s Andrew Moss put it plainly: “A personal computer is called a personal computer because it’s yours. Anything that runs on that computer, you should have control over.”

The Legacy

The Sony BMG rootkit scandal killed music DRM. Sony suspended all CD copy-protection efforts in the U.S. by early 2007. EMI became the first major label to go DRM-free on iTunes in April 2007. By 2008, the entire iTunes music store was DRM-free, and the rest of the industry followed.

Bruce Schneier described the rootkit as creating “one of the most serious internet epidemics of all time — on a par with worms like Blaster, Slammer, Code Red and Nimda.”

The Sony-BMG joint venture itself dissolved in October 2008.

Mark Russinovich’s career soared. Microsoft acquired Winternals in July 2006. Russinovich became a Microsoft Technical Fellow and eventually CTO of Microsoft Azure — one of the most senior technical positions in the company. He also wrote three cyberthriller novels and continues to maintain the Sysinternals tools to this day.

The scandal is widely credited with accelerating the shift from CD sales to streaming. Spotify launched in 2008. The industry learned, painfully, that treating your customers as criminals tends to backfire — especially when you infect their computers in the process.

Twenty years later, the Sony rootkit remains the definitive case study in what happens when corporate intellectual property enforcement crosses the line from protection into attack. As the Department of Homeland Security reminded Sony: it’s your music, but it’s not your computer.

Sources and Further Reading

  • Mark Russinovich, “Sony, Rootkits and Digital Rights Management Gone Too Far” — Sysinternals Blog, October 31, 2005
  • Mark Russinovich, “Sony: You don’t reeeeaaaally want to uninstall, do you?” — Sysinternals Blog, November 9, 2005
  • F-Secure, “XCP DRM Software” — Technical Analysis by Samuli Larvala, November 2005
  • Computer Associates, “XCP.Sony.Rootkit” — Spyware Encyclopedia
  • Dan Kaminsky, “Welcome to Planet Sony” — DNS research on global infection
  • Electronic Frontier Foundation, “Sony BMG Litigation Info” — eff.org
  • Avery Morrow, “Outline for a Computer Security Exemption to the DMCA” — November 23, 2005
  • Mark Lyon, sonysuit.com — Class action tracking and settlement documentation
  • J. Alex Halderman and Edward W. Felten, “Lessons from the Sony CD DRM Episode” — Princeton CITP
  • FTC, “Sony BMG Settles FTC Charges” — Press Release, January 30, 2007

#20yrsago — Originally documented at sonysuit.com