World of Warcraft hackers using Sony BMG rootkit
Want to cheat in your online game and not get caught? Just buy a Sony BMG copy protected CD. — World of Warcraft hackers have confirmed that the hiding capabilities of Sony BMG's content protection software can make tools made for cheating …
Context & Ripple Effects
Sony BMG's copy-protection software had already drawn scrutiny for installing itself covertly on listeners' PCs, prompting a promised patch and a hastily issued mysterious software update from Sony BMG and First4Internet. This report sharpens the story's stakes: the same cloaking behavior that made the rootkit controversial is now confirmed useful to World of Warcraft cheaters as a ready-made hiding place for detection-evasion tools.
First-order effects
- World of Warcraft players and Blizzard face a new class of cheat that exploits the Sony BMG rootkit's stealth to evade anti-cheat detection, meaning the DRM software is actively harming users beyond its original purpose.
- Sony BMG's containment problem deepens overnight: the patch it committed to now has to address not just privacy and security exposure but active abuse by cheating communities.
Second-order effects
- Game publishers are pushed toward treating consumer machines as hostile territory — hardening anti-cheat to detect hidden processes rather than trusting the OS — while security researchers gain a vivid case that DRM can function as malware delivery infrastructure.
- The episode pressures labels and DRM vendors to weigh legal and reputational liability for software shipped on commercial CDs, since a copy-protection product is now demonstrably aiding rule-breaking in an adjacent market (online gaming).
Third-order effects
- If the pattern holds, DRM and other vendor-installed low-level software become a structural attack surface: any code designed to hide itself from users becomes reusable cover for malicious or abusive tooling, foreshadowing later episodes where cheats themselves turn out to be malware, as when Activision warned Warzone players that a popular 'cheat' was actually malware taking over machines.
- The incident points toward a lasting norm that stealthy client-side software — whether for rights enforcement or anti-cheat — invites adversarial reuse, shaping how the industry regulates what may be installed invisibly on end-user PCs.
The trend: Security tools built on secrecy keep backfiring as dual-use code: anything designed to hide from its user eventually gets repurposed by adversaries, from 2005's DRM rootkits to today's cheat-as-malware ecosystem.