Godot Game Used As a Malware

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ม.ค. 2025

ความคิดเห็น • 116

  • @_JohnHammond
    @_JohnHammond  6 ชั่วโมงที่ผ่านมา +7

    With the outpouring of feedback on the original title of the video "Godot Game Engine Makes Malware", I've changed the title to "Godot Game Engine Used to Make Malware".
    If you don't like that title either, please tell me exactly what title you actually want, and we can crowdsource -- with our powers combined, we will make all TH-cam commenters happy forever.
    EDIT: After some further comments, I've changed the title further to "Godot Game Engine Can Be Used to Make Malware". Let me know if that still doesn't tickle your fancy and what exact title you would prefer instead.
    EDIT AGAIN: Thus far the TH-cam Commenter Collective seems to like "Godot Game Used As a Malware" so that is set as the new title.

    • @mate8115
      @mate8115 6 ชั่วโมงที่ผ่านมา +6

      you shouldn't need feedback to realize that title is idiotic, you have almost 2 million subscribers, how about acting accordingly with some level of responsibility? i guess a good clickbait is more important than anything else these days

    • @aventu-yt
      @aventu-yt 6 ชั่วโมงที่ผ่านมา +4

      "Used as Malware Loader" would be accurate.

    • @_JohnHammond
      @_JohnHammond  6 ชั่วโมงที่ผ่านมา +2

      ​@@aventu-yt I'm not sure, that would read "Godot Game Engine Used as Malware Loader", but the article and demo doesn't show the game engine itself being a malware loader... it is what the game engine makes as a game that is malware. 🤔"Godot Game Used As Malware"?

    • @jumphigher-runfaster
      @jumphigher-runfaster 6 ชั่วโมงที่ผ่านมา +2

      Why not windows, linux or mac os used to make malware? Or loading files used to make malware? Google chrome makes malware?
      The engine is used as a dropper, not some malware making program. Godot is not some more sophisticated metasploit.

    • @jumphigher-runfaster
      @jumphigher-runfaster 6 ชั่วโมงที่ผ่านมา +2

      It's honestly disappointing to see this sort of clickbait from someone who is knowledgeable in the topic.

  • @PlayingGilly
    @PlayingGilly 11 ชั่วโมงที่ผ่านมา +105

    That clickbait title is almost litigious.

    • @ramb0lxmb
      @ramb0lxmb 7 ชั่วโมงที่ผ่านมา

      Are there many open source projects without large corporate backing that have the legal resources available to fight mid level, niche TH-camrs? I surely would stop donating if that's what they were doing with my money. It's clickbait, but that's why the logos gave us the ability to discern. Won't be the last clickbait you ever see.

  • @huboz0r
    @huboz0r 11 ชั่วโมงที่ผ่านมา +74

    Next video: Rust and Go make malware

    • @sasjadevries
      @sasjadevries 8 ชั่วโมงที่ผ่านมา +1

      One could make Rust malware using Bevy game engine 😂. And boom: that's how you can be triggering game-devs and rust-fans in one go.

  • @KvapuJanjalia
    @KvapuJanjalia 11 ชั่วโมงที่ผ่านมา +78

    Clickbait. I thought Godot creators were distributing a malware.

  • @the1whoplayz
    @the1whoplayz 12 ชั่วโมงที่ผ่านมา +108

    I have a big issue with your title. It implies that the Godot Game Engine itself is what's responsible for creating and executing the RAT/Malware, and not the programmer who's deliberately sending an HTTP request to download a file and executing the executable.
    This is akin to saying that "Python Makes Malware", "C++ Makes Malware", "Unity Makes Malware", or "Unreal Engine Makes Malware". The title can't even be considered as clickbait, since it's just a flat out lie. Yes, I know you address this stuff near the end of the video, but that's the problem. It's near the end of the video, and the majority of viewers won't make it anywhere close to there.
    Anyways, I'm just hoping you'd change it to something more accurate (such as "Using Godot to load Malware" if you want to include Godot in the title, or "Loading Malware via Network Requests" if you want to account for the other platforms that can do this.) Thanks for taking the time to read this request.

    • @wilzzuu
      @wilzzuu 11 ชั่วโมงที่ผ่านมา +4

      Yeah, I jumped a little when I saw the title and paused another video just to watch it, because I have used Godot actively, but I'm glad your comment is the first I saw so it eased my mind

    • @shaikhmanal
      @shaikhmanal 11 ชั่วโมงที่ผ่านมา +8

      John has slowly become a typical youtuber nowadays. He's unnecessarily inflates video length to get more watchtime. It made be unsubscribe him from the first place. Now with this outright clickbait.... Nah.

  • @LGTV-wb9lv
    @LGTV-wb9lv 12 ชั่วโมงที่ผ่านมา +71

    Shocking... Next thing you will tell us one can use C++ to write a virus too 😂

  • @gamersunite9026
    @gamersunite9026 11 ชั่วโมงที่ผ่านมา +13

    this title will bring a bunch of "oh i KNEW godot was bad" comments from people that dont even watch the video and just read the title.. amazing

  • @TheReal_N-I-F-F
    @TheReal_N-I-F-F 10 ชั่วโมงที่ผ่านมา +22

    Stupid clickbait title.

  • @MrFierceVFX
    @MrFierceVFX 11 ชั่วโมงที่ผ่านมา +21

    Next Video: C# and C++ makes malware, aware!

  • @DylanEdd_1
    @DylanEdd_1 9 ชั่วโมงที่ผ่านมา +6

    I found this video to be quite interesting to watch overall. Additionally, I'm a bit concerned about the choice of title. While the content of the video was valuable, a title like that could potentially contribute to bad rep for the Godot engine. Godot is a smaller, open-source game engine, and perhaps a more neutral or balanced title would have been better as from seeing the title it would've made me think, like others have pointed out that it was the creators of the engine distributing malware themselves. Nonetheless, I appreciate you taking the time to share this information with the community.

  • @NicoTheCinderace
    @NicoTheCinderace 11 ชั่วโมงที่ผ่านมา +16

    This is clickbait. Do better.

  • @vizionthing
    @vizionthing 11 ชั่วโมงที่ผ่านมา +33

    You are going to get a shit load of downvotes for that title

    • @andrewkelley9405
      @andrewkelley9405 11 ชั่วโมงที่ผ่านมา

      who cares Godot has gone to the dogs as is.

    • @vizionthing
      @vizionthing 11 ชั่วโมงที่ผ่านมา +7

      WE FOUND A UNITY DEV

    • @ヽノ-u4t
      @ヽノ-u4t 11 ชั่วโมงที่ผ่านมา

      @@andrewkelley9405 that drama about godot just exists on twitter, not in the real world.

    • @NicoTheCinderace
      @NicoTheCinderace 11 ชั่วโมงที่ผ่านมา

      @@andrewkelley9405 Common Unity L

  • @r0nam145
    @r0nam145 7 ชั่วโมงที่ผ่านมา +2

    Not changing the title yet despite people complaining doesn't make people happy John, it's frankly a little shitty.
    Edit: A lot more clear now, thanks!

  • @pingu666
    @pingu666 11 ชั่วโมงที่ผ่านมา +17

    crappy clickbait

  • @ameliekk
    @ameliekk 7 ชั่วโมงที่ผ่านมา +2

    This is one of those video you shit out when you just need the sponsor money. No respect for your fans

  • @DayBeforeU
    @DayBeforeU 10 ชั่วโมงที่ผ่านมา +6

    Are you 12-years-old? really? reaaaally?

  • @ashwin372
    @ashwin372 11 ชั่วโมงที่ผ่านมา +9

    I mean godot is just a game engine like several other game engine. whatever you did in this video can be done even in python pygame . Seems like a click bait .

    • @mate8115
      @mate8115 6 ชั่วโมงที่ผ่านมา +1

      yeah i dont really understand what exactly is godot specific in this method, to me it just seems like a shitty video to attack an open source project without any valid reason especially with the original title

  • @Nomnomkun
    @Nomnomkun 9 ชั่วโมงที่ผ่านมา +4

    Can't you do the exact same thing with python exe or nodejs exe? The point is signed exe doing unsigned behavior and you can do that with any script runner 😅

  • @anonimenkolbas1305
    @anonimenkolbas1305 11 ชั่วโมงที่ผ่านมา +7

    DeArrow to the rescue. When I saw the original title, I was disappointed in John.

  • @ownmicelio
    @ownmicelio 9 ชั่วโมงที่ผ่านมา +2

    No, you are Malware!

  • @gonderage
    @gonderage 9 ชั่วโมงที่ผ่านมา +1

    DeArrow de-clickbaits TH-cam titles and it only costs $1 wow

    • @obfuscated3474
      @obfuscated3474 8 ชั่วโมงที่ผ่านมา

      DeArrow costs nothing btw

  • @fusillator
    @fusillator 12 ชั่วโมงที่ผ่านมา +3

    if people execute not signed code by unknown author what's the point? Godot it's only a mit opensource framework to create gAme without developing all the boilerplate of the physics rulez

  • @VirtualReality-zv5oh
    @VirtualReality-zv5oh 8 ชั่วโมงที่ผ่านมา +3

    Shitty and an unnecessary clickbait.

  • @UserName-pv9qz
    @UserName-pv9qz 9 ชั่วโมงที่ผ่านมา

    It seems that few people really understand what this is about

  • @wilzzuu
    @wilzzuu 4 ชั่วโมงที่ผ่านมา

    Anyone with the extension that tells you the estimated dislikes, could you share us some numbers on this one?

  • @HeIsHarsh
    @HeIsHarsh 7 ชั่วโมงที่ผ่านมา +1

    Nearly 2M subs & yet your average video views is 70k, no wonder why you desperately needed clickbait.

    • @wilzzuu
      @wilzzuu 4 ชั่วโมงที่ผ่านมา

      Yeah, then face the fact that desperate clickbait leads to more falling off. It's a vicious cycle

  • @logiciananimal
    @logiciananimal 5 ชั่วโมงที่ผ่านมา

    How does the game engine use the source code? Is it compiled? Can it be detected?

  • @lerenstuderenopschool
    @lerenstuderenopschool 8 ชั่วโมงที่ผ่านมา +1

    🔥TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!

  • @randykitchleburger2780
    @randykitchleburger2780 10 ชั่วโมงที่ผ่านมา +1

    Uhh, you guys thought the engine itself was making malware? Like by itself? 😂

  • @saadzahem
    @saadzahem 10 ชั่วโมงที่ผ่านมา

    Hey! A genuine question is here.
    Whatsapp shows me a warning message asking me if I trust the sender whenever I open a pdf document sent by him. Can pdf files be malicious? What about .docx and .ppt? Is there any chance I could get hacked opening some of these files carelessly?

    • @catcatcatcatcatcatcatcatcatca
      @catcatcatcatcatcatcatcatcatca 9 ชั่วโมงที่ผ่านมา

      pdf files can run javascript code, which means they can pose a threat, but can not for example deliver a payload without other exploits.
      However, they can make webrequests, meaning they can leak your IP address, and information how you are reading the pdf at the very least. This functionality is intentional part of the format but can compromise privacy.
      Plenty of PDF exploits have been found previously, so it is safe to say more will be found in the future as well. An example I found by quick search leaked the victims hashed password on windows, by trying to fetch content from an SMB (network share) server controlled by the attacker. To authenticate, the victims machine automatically submitted their credentials, but with hashed password. This is a real risk because a weak password could be broken with a dictionary attack.
      And in vulnerable environments (where older authentication method for smb is still used/allowed) this attempt to connect is enough to stage a man-in-the-middle attack to gain access to the wider system.
      So altogether, PDF files do pose a risk:
      - they can leak private information
      - they might be able to exploit a new or still unknown vulnerability of the reader you use
      - they might be able to exploit other vulnerable aspects of your network
      Mitigations against this are pretty easy, however:
      - always use an up-to-date reader
      - disable use of javascript in files in your readers preferences
      - scan any suspicious pdf you reseave with antivirus or malware detection tools, to see if it matches a known fingerprint (however not matching one does not mean the file is necessarily safe)

    • @ownmicelio
      @ownmicelio 9 ชั่วโมงที่ผ่านมา

      Yes those files can be malicious

    • @ameliekk
      @ameliekk 7 ชั่วโมงที่ผ่านมา

      Any file you download can be a virus. If hackers find a way to exploit the program you use to view document files they can leverage that to send you a malicious file that when read with your pdf viewer or etc then executes some malicious code

  • @Ewie7
    @Ewie7 8 ชั่วโมงที่ผ่านมา +3

    I was expecting better from you. Dislike.

  • @Rishabh_Joshi_
    @Rishabh_Joshi_ 11 ชั่วโมงที่ผ่านมา +2

    Only 20% dislikes

    • @christaylorakaskunk
      @christaylorakaskunk 9 ชั่วโมงที่ผ่านมา +2

      30% now

    • @wilzzuu
      @wilzzuu 4 ชั่วโมงที่ผ่านมา

      ​@@christaylorakaskunk what's it now?

  • @MAdhvaryu
    @MAdhvaryu 7 ชั่วโมงที่ผ่านมา +2

    This is this type of clickbait I really dislike. Unsubscribing.

  • @michaelavrie
    @michaelavrie 9 ชั่วโมงที่ผ่านมา

    TD for the title

  • @vizionthing
    @vizionthing 11 ชั่วโมงที่ผ่านมา +6

    This was a pile of shit, come on John wtf are you doing? how is this any diffeferent from ANY OTHER PROGRAMMING LANGUAGE ?

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 9 ชั่วโมงที่ผ่านมา

    More Zombie malware games

  • @hackwithprogramming7849
    @hackwithprogramming7849 12 ชั่วโมงที่ผ่านมา

  • @PokemonBattleQuestGodot
    @PokemonBattleQuestGodot 12 ชั่วโมงที่ผ่านมา +1

    not godot 😂

  • @NVsquare
    @NVsquare 9 ชั่วโมงที่ผ่านมา

    Is it the Russians again?

  • @joaoprogrammer5306
    @joaoprogrammer5306 10 ชั่วโมงที่ผ่านมา +1

    Lol

  • @ioxmedia
    @ioxmedia 12 ชั่วโมงที่ผ่านมา +2

    First

  • @Mauretto-j7u
    @Mauretto-j7u 11 ชั่วโมงที่ผ่านมา

    MHA!

  • @h471x
    @h471x 5 ชั่วโมงที่ผ่านมา

    Creepy

  • @jacoumata
    @jacoumata 2 ชั่วโมงที่ผ่านมา

    No comment

  • @craxxysum1264
    @craxxysum1264 12 ชั่วโมงที่ผ่านมา +2

    I read the article about a month ago as I am a Godot fan and I was amazed...it was a great read...and a somehow obvious vector that everybody missed...it's pure evil genius

  • @EmiliaHoarfrost
    @EmiliaHoarfrost 6 ชั่วโมงที่ผ่านมา

    Grrrrrrrrrrrrrrrrrrrrrrrr me not smort me see Godot dissed me angerrrrrrr

  • @MujurID
    @MujurID 12 ชั่วโมงที่ผ่านมา

    😶😶

  • @hydrogennetwork
    @hydrogennetwork 7 ชั่วโมงที่ผ่านมา

    how is this clickbait eople

  • @ThisIsJustADrillBit
    @ThisIsJustADrillBit 12 ชั่วโมงที่ผ่านมา +1

    Kernel level anticheat they said .. what could go wrong 😂😂😂

  • @gercekbko
    @gercekbko 12 ชั่วโมงที่ผ่านมา +2

    Godot's twitter account manager was a bad person tbh.

    • @gamersunite9026
      @gamersunite9026 11 ชั่วโมงที่ผ่านมา +1

      has n0othing to do with what the video is about?? 💔

    • @gercekbko
      @gercekbko 11 ชั่วโมงที่ผ่านมา

      @@gamersunite9026 Yeah it doesn't, I just wanted to point that out.

  • @HellCat-g7x
    @HellCat-g7x 12 ชั่วโมงที่ผ่านมา

    3d

  • @antigogle
    @antigogle 12 ชั่วโมงที่ผ่านมา +1

    Fourth

  • @d4nix5
    @d4nix5 12 ชั่วโมงที่ผ่านมา

    first!

  • @SLZeroArrow
    @SLZeroArrow 12 ชั่วโมงที่ผ่านมา +3

    it just never ends, huh Godot?

    • @gamersunite9026
      @gamersunite9026 11 ชั่วโมงที่ผ่านมา +4

      applies to unity/unreal as well

  • @kalinathalie
    @kalinathalie 12 ชั่วโมงที่ผ่านมา +1

    Awesome content, I'm starting with godot engine and it's pretty cool ^^

  • @sakib87-ih
    @sakib87-ih 12 ชั่วโมงที่ผ่านมา +1

    john lots of respect from BANGLADESH

  • @pelaajahacks8358
    @pelaajahacks8358 12 ชั่วโมงที่ผ่านมา

    i just recommended godot to a friend

    • @ParasocialCatgirl
      @ParasocialCatgirl 11 ชั่วโมงที่ผ่านมา +7

      Rest assured that this is *not* a problem with Godot itself.
      This is like saying 'The C++ programming language can be used to make malware'.

    • @pelaajahacks8358
      @pelaajahacks8358 5 ชั่วโมงที่ผ่านมา

      @ yeah, just kind of bad timing which i found funny

  • @andrewkelley9405
    @andrewkelley9405 11 ชั่วโมงที่ผ่านมา

    as if things couldn't get worse for Godot.

    • @ninstars
      @ninstars 11 ชั่วโมงที่ผ่านมา +7

      Did you watch the video or bother reading the article? This isn't exclusive to Godot, you can achieve the exact same thing with almost any other game engine.

    • @gamersunite9026
      @gamersunite9026 11 ชั่วโมงที่ผ่านมา +1

      gonna do this with unity just to make you mad :3

  • @stewartmaxey8369
    @stewartmaxey8369 12 ชั่วโมงที่ผ่านมา

    Thanks for the great information.

  • @SolitaryElite
    @SolitaryElite 11 ชั่วโมงที่ผ่านมา

    communists trying to make a good game engine(impossible)

    • @ParasocialCatgirl
      @ParasocialCatgirl 11 ชั่วโมงที่ผ่านมา

      "Everything I don't like is communism!"

    • @gamersunite9026
      @gamersunite9026 11 ชั่วโมงที่ผ่านมา +7

      SOMEONE opened up the video to comment this without knowing this applies to every single engine...

    • @SolitaryElite
      @SolitaryElite 10 ชั่วโมงที่ผ่านมา

      @@gamersunite9026 nah i was just joking, i actually use godot, and i know in this case, the bad guys "abused" the engine and that you can do this with any engine. when it comes to the engine... it's kind of bad, important features are "hidden away", it's messy ui etc... but i accept it anyways because it's one of the few good open source game engines, it don't really like using stuff like unreal or unity.

  • @SkyFly19853
    @SkyFly19853 12 ชั่วโมงที่ผ่านมา +1

    I never ever liked Godot engine in the first place....
    such an unnecessary game engine...

    • @ヽノ-u4t
      @ヽノ-u4t 11 ชั่วโมงที่ผ่านมา +4

      It is very calming to know, that only the Godot engine can be used to stage malware because it is impossible with other engines :shrug:

    • @Bempus
      @Bempus 11 ชั่วโมงที่ผ่านมา +3

      You can make malware with anything that can make code, this is probably just a heads up to be aware when downloading games/software in general. This is just an example using Godot, you could make malware with GameMaker, Unity, Unreal, Java, Rust, etc. and Godot is a very good engine for it's purposes.

    • @ParasocialCatgirl
      @ParasocialCatgirl 11 ชั่วโมงที่ผ่านมา +6

      How so?
      I personally think that Godot's existence, as a free-and-open-source alternative to the duopoly of Unity and Unreal is ultimately a very good thing for the game development ecosystem as a whole. After all, if Godot didn't exist as a viable alternative, the duopoly would be able to get away with much scummier business practices.
      Just off the top of my head, do you also remember the Unity Runtime Fee debacle (and other enshittification tactics recently employed by Unity Technologies)? And are you aware of Tencent's notable investments in Epic Games (and the fact that Unreal Engine's current 'free-to-start using' pricing model is thanks to this investment)?
      Now, with these rather worrying blemishes on the record of Unity and Unreal, would you agree with me that it's better to have a fully usable alternative engine out there which one can start using right now (Godot) than it is to be obliged to put up with the continued enshittification of the Unity/Unreal duopoly?

    • @SkyFly19853
      @SkyFly19853 6 ชั่วโมงที่ผ่านมา

      @@ヽノ-u4t
      Because it uses its own programming language which is unnecessary in the first place.

    • @Yezper
      @Yezper 6 ชั่วโมงที่ผ่านมา

      @@SkyFly19853 But why is it unnecessary? Is unreal engine also unnecessary because they made their own blueprint system?
      If you don't like it because they made their own language then you can use C# in Godot instead of GDScript.

  • @45678213914284289421
    @45678213914284289421 11 ชั่วโมงที่ผ่านมา +8

    Clickbait. Now try the same with Unity or Unreal and see what happens.

  • @diffdimgamerseven9986
    @diffdimgamerseven9986 12 ชั่วโมงที่ผ่านมา +1

    resetti. my favorite (probably not) animal crossing character