Godot Game Used As Malware

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ม.ค. 2025

ความคิดเห็น • 129

  • @_JohnHammond
    @_JohnHammond  16 ชั่วโมงที่ผ่านมา +10

    With the outpouring of feedback on the original title of the video "Godot Game Engine Makes Malware", I've changed the title to "Godot Game Engine Used to Make Malware".
    If you don't like that title either, please tell me exactly what title you actually want, and we can crowdsource -- with our powers combined, we will make all TH-cam commenters happy forever.
    EDIT: After some further comments, I've changed the title further to "Godot Game Engine Can Be Used to Make Malware". Let me know if that still doesn't tickle your fancy and what exact title you would prefer instead.
    EDIT AGAIN: Thus far the TH-cam Commenter Collective seems to like "Godot Game Used As a Malware" so that is set as the new title.

    • @mate8115
      @mate8115 16 ชั่วโมงที่ผ่านมา +9

      you shouldn't need feedback to realize that title is idiotic, you have almost 2 million subscribers, how about acting accordingly with some level of responsibility? i guess a good clickbait is more important than anything else these days

    • @aventu-yt
      @aventu-yt 16 ชั่วโมงที่ผ่านมา +5

      "Used as Malware Loader" would be accurate.

    • @_JohnHammond
      @_JohnHammond  15 ชั่วโมงที่ผ่านมา +2

      ​@@aventu-yt I'm not sure, that would read "Godot Game Engine Used as Malware Loader", but the article and demo doesn't show the game engine itself being a malware loader... it is what the game engine makes as a game that is malware. 🤔"Godot Game Used As Malware"?

    • @jumphigher-runfaster
      @jumphigher-runfaster 15 ชั่วโมงที่ผ่านมา +3

      Why not windows, linux or mac os used to make malware? Or loading files used to make malware? Google chrome makes malware?
      The engine is used as a dropper, not some malware making program. Godot is not some more sophisticated metasploit.

    • @jumphigher-runfaster
      @jumphigher-runfaster 15 ชั่วโมงที่ผ่านมา +2

      It's honestly disappointing to see this sort of clickbait from someone who is knowledgeable in the topic.

  • @PlayingGilly
    @PlayingGilly 21 ชั่วโมงที่ผ่านมา +109

    That clickbait title is almost litigious.

    • @ramb0lxmb
      @ramb0lxmb 17 ชั่วโมงที่ผ่านมา

      Are there many open source projects without large corporate backing that have the legal resources available to fight mid level, niche TH-camrs? I surely would stop donating if that's what they were doing with my money. It's clickbait, but that's why the logos gave us the ability to discern. Won't be the last clickbait you ever see.

  • @huboz0r
    @huboz0r 21 ชั่วโมงที่ผ่านมา +76

    Next video: Rust and Go make malware

    • @sasjadevries
      @sasjadevries 17 ชั่วโมงที่ผ่านมา +1

      One could make Rust malware using Bevy game engine 😂. And boom: that's how you can be triggering game-devs and rust-fans in one go.

  • @KvapuJanjalia
    @KvapuJanjalia 21 ชั่วโมงที่ผ่านมา +82

    Clickbait. I thought Godot creators were distributing a malware.

    • @jamnagang7462
      @jamnagang7462 28 นาทีที่ผ่านมา

      What was the title?

    • @KvapuJanjalia
      @KvapuJanjalia 18 นาทีที่ผ่านมา

      @@jamnagang7462 "Godot Game Engine Makes Malware"

  • @the1whoplayz
    @the1whoplayz 21 ชั่วโมงที่ผ่านมา +108

    I have a big issue with your title. It implies that the Godot Game Engine itself is what's responsible for creating and executing the RAT/Malware, and not the programmer who's deliberately sending an HTTP request to download a file and executing the executable.
    This is akin to saying that "Python Makes Malware", "C++ Makes Malware", "Unity Makes Malware", or "Unreal Engine Makes Malware". The title can't even be considered as clickbait, since it's just a flat out lie. Yes, I know you address this stuff near the end of the video, but that's the problem. It's near the end of the video, and the majority of viewers won't make it anywhere close to there.
    Anyways, I'm just hoping you'd change it to something more accurate (such as "Using Godot to load Malware" if you want to include Godot in the title, or "Loading Malware via Network Requests" if you want to account for the other platforms that can do this.) Thanks for taking the time to read this request.

    • @wilzzuu
      @wilzzuu 21 ชั่วโมงที่ผ่านมา +4

      Yeah, I jumped a little when I saw the title and paused another video just to watch it, because I have used Godot actively, but I'm glad your comment is the first I saw so it eased my mind

    • @shaikhmanal
      @shaikhmanal 20 ชั่วโมงที่ผ่านมา +8

      John has slowly become a typical youtuber nowadays. He's unnecessarily inflates video length to get more watchtime. It made be unsubscribe him from the first place. Now with this outright clickbait.... Nah.

  • @LGTV-wb9lv
    @LGTV-wb9lv 21 ชั่วโมงที่ผ่านมา +74

    Shocking... Next thing you will tell us one can use C++ to write a virus too 😂

  • @gamersunite9026
    @gamersunite9026 20 ชั่วโมงที่ผ่านมา +12

    this title will bring a bunch of "oh i KNEW godot was bad" comments from people that dont even watch the video and just read the title.. amazing

  • @MrFierceVFX
    @MrFierceVFX 20 ชั่วโมงที่ผ่านมา +22

    Next Video: C# and C++ makes malware, aware!

  • @TheReal_N-I-F-F
    @TheReal_N-I-F-F 20 ชั่วโมงที่ผ่านมา +22

    Stupid clickbait title.

  • @DylanEdd_1
    @DylanEdd_1 19 ชั่วโมงที่ผ่านมา +6

    I found this video to be quite interesting to watch overall. Additionally, I'm a bit concerned about the choice of title. While the content of the video was valuable, a title like that could potentially contribute to bad rep for the Godot engine. Godot is a smaller, open-source game engine, and perhaps a more neutral or balanced title would have been better as from seeing the title it would've made me think, like others have pointed out that it was the creators of the engine distributing malware themselves. Nonetheless, I appreciate you taking the time to share this information with the community.

  • @vizionthing
    @vizionthing 21 ชั่วโมงที่ผ่านมา +33

    You are going to get a shit load of downvotes for that title

    • @andrewkelley9405
      @andrewkelley9405 20 ชั่วโมงที่ผ่านมา

      who cares Godot has gone to the dogs as is.

    • @vizionthing
      @vizionthing 20 ชั่วโมงที่ผ่านมา +7

      WE FOUND A UNITY DEV

    • @ヽノ-u4t
      @ヽノ-u4t 20 ชั่วโมงที่ผ่านมา

      @@andrewkelley9405 that drama about godot just exists on twitter, not in the real world.

    • @NicoTheCinderace
      @NicoTheCinderace 20 ชั่วโมงที่ผ่านมา

      @@andrewkelley9405 Common Unity L

  • @NicoTheCinderace
    @NicoTheCinderace 20 ชั่วโมงที่ผ่านมา +16

    This is clickbait. Do better.

  • @pingu666
    @pingu666 20 ชั่วโมงที่ผ่านมา +18

    crappy clickbait

  • @ameliekk
    @ameliekk 16 ชั่วโมงที่ผ่านมา +3

    This is one of those video you shit out when you just need the sponsor money. No respect for your fans

  • @r0nam145
    @r0nam145 16 ชั่วโมงที่ผ่านมา +2

    Not changing the title yet despite people complaining doesn't make people happy John, it's frankly a little shitty.
    Edit: A lot more clear now, thanks!

  • @DayBeforeU
    @DayBeforeU 20 ชั่วโมงที่ผ่านมา +6

    Are you 12-years-old? really? reaaaally?

  • @ashwin372
    @ashwin372 20 ชั่วโมงที่ผ่านมา +8

    I mean godot is just a game engine like several other game engine. whatever you did in this video can be done even in python pygame . Seems like a click bait .

    • @mate8115
      @mate8115 16 ชั่วโมงที่ผ่านมา +1

      yeah i dont really understand what exactly is godot specific in this method, to me it just seems like a shitty video to attack an open source project without any valid reason especially with the original title

  • @Nomnomkun
    @Nomnomkun 19 ชั่วโมงที่ผ่านมา +4

    Can't you do the exact same thing with python exe or nodejs exe? The point is signed exe doing unsigned behavior and you can do that with any script runner 😅

  • @epyonm99
    @epyonm99 7 ชั่วโมงที่ผ่านมา +1

    So, programming language may build an instalable program with malicious intent?😅

  • @anonimenkolbas1305
    @anonimenkolbas1305 20 ชั่วโมงที่ผ่านมา +6

    DeArrow to the rescue. When I saw the original title, I was disappointed in John.

  • @felo7343
    @felo7343 4 ชั่วโมงที่ผ่านมา

    5:12 When TH-cam inserts a short commercial In the middle of your commercial for your sponsor...
    Not the first time...

  • @gonderage
    @gonderage 18 ชั่วโมงที่ผ่านมา +1

    DeArrow de-clickbaits TH-cam titles and it only costs $1 wow

    • @obfuscated3474
      @obfuscated3474 17 ชั่วโมงที่ผ่านมา

      DeArrow costs nothing btw

  • @HeIsHarsh
    @HeIsHarsh 17 ชั่วโมงที่ผ่านมา +2

    Nearly 2M subs & yet your average video views is 70k, no wonder why you desperately needed clickbait.

    • @wilzzuu
      @wilzzuu 14 ชั่วโมงที่ผ่านมา +1

      Yeah, then face the fact that desperate clickbait leads to more falling off. It's a vicious cycle

  • @fusillator
    @fusillator 21 ชั่วโมงที่ผ่านมา +3

    if people execute not signed code by unknown author what's the point? Godot it's only a mit opensource framework to create gAme without developing all the boilerplate of the physics rulez

  • @wbusine
    @wbusine 9 ชั่วโมงที่ผ่านมา

    Please I am new to Cyber Security, the play list is not so clear on where I can start from . Any direction ?

    • @VA3KAMA3
      @VA3KAMA3 43 นาทีที่ผ่านมา

      read articles, books, etc related to the topic, start working with code snippets, watch videos also related to the topic.

  • @VirtualReality-zv5oh
    @VirtualReality-zv5oh 17 ชั่วโมงที่ผ่านมา +3

    Shitty and an unnecessary clickbait.

  • @wilzzuu
    @wilzzuu 14 ชั่วโมงที่ผ่านมา

    Anyone with the extension that tells you the estimated dislikes, could you share us some numbers on this one?

  • @UserName-pv9qz
    @UserName-pv9qz 19 ชั่วโมงที่ผ่านมา

    It seems that few people really understand what this is about

  • @logiciananimal
    @logiciananimal 15 ชั่วโมงที่ผ่านมา

    How does the game engine use the source code? Is it compiled? Can it be detected?

  • @lerenstuderenopschool
    @lerenstuderenopschool 17 ชั่วโมงที่ผ่านมา +1

    🔥TH-cam ALGORITHM ➡ Like, Comment, & Subscribe!

  • @randykitchleburger2780
    @randykitchleburger2780 19 ชั่วโมงที่ผ่านมา +1

    Uhh, you guys thought the engine itself was making malware? Like by itself? 😂

  • @saadzahem
    @saadzahem 19 ชั่วโมงที่ผ่านมา

    Hey! A genuine question is here.
    Whatsapp shows me a warning message asking me if I trust the sender whenever I open a pdf document sent by him. Can pdf files be malicious? What about .docx and .ppt? Is there any chance I could get hacked opening some of these files carelessly?

    • @catcatcatcatcatcatcatcatcatca
      @catcatcatcatcatcatcatcatcatca 18 ชั่วโมงที่ผ่านมา

      pdf files can run javascript code, which means they can pose a threat, but can not for example deliver a payload without other exploits.
      However, they can make webrequests, meaning they can leak your IP address, and information how you are reading the pdf at the very least. This functionality is intentional part of the format but can compromise privacy.
      Plenty of PDF exploits have been found previously, so it is safe to say more will be found in the future as well. An example I found by quick search leaked the victims hashed password on windows, by trying to fetch content from an SMB (network share) server controlled by the attacker. To authenticate, the victims machine automatically submitted their credentials, but with hashed password. This is a real risk because a weak password could be broken with a dictionary attack.
      And in vulnerable environments (where older authentication method for smb is still used/allowed) this attempt to connect is enough to stage a man-in-the-middle attack to gain access to the wider system.
      So altogether, PDF files do pose a risk:
      - they can leak private information
      - they might be able to exploit a new or still unknown vulnerability of the reader you use
      - they might be able to exploit other vulnerable aspects of your network
      Mitigations against this are pretty easy, however:
      - always use an up-to-date reader
      - disable use of javascript in files in your readers preferences
      - scan any suspicious pdf you reseave with antivirus or malware detection tools, to see if it matches a known fingerprint (however not matching one does not mean the file is necessarily safe)

    • @ownmicelio
      @ownmicelio 18 ชั่วโมงที่ผ่านมา

      Yes those files can be malicious

    • @ameliekk
      @ameliekk 16 ชั่วโมงที่ผ่านมา

      Any file you download can be a virus. If hackers find a way to exploit the program you use to view document files they can leverage that to send you a malicious file that when read with your pdf viewer or etc then executes some malicious code

  • @Rishabh_Joshi_
    @Rishabh_Joshi_ 20 ชั่วโมงที่ผ่านมา +2

    Only 20% dislikes

    • @christaylorakaskunk
      @christaylorakaskunk 18 ชั่วโมงที่ผ่านมา +2

      30% now

    • @wilzzuu
      @wilzzuu 13 ชั่วโมงที่ผ่านมา

      ​@@christaylorakaskunk what's it now?

  • @Ewie7
    @Ewie7 17 ชั่วโมงที่ผ่านมา +3

    I was expecting better from you. Dislike.

  • @MAdhvaryu
    @MAdhvaryu 16 ชั่วโมงที่ผ่านมา +2

    This is this type of clickbait I really dislike. Unsubscribing.

  • @michaelavrie
    @michaelavrie 18 ชั่วโมงที่ผ่านมา

    TD for the title

  • @iamwitchergeraltofrivia9670
    @iamwitchergeraltofrivia9670 18 ชั่วโมงที่ผ่านมา

    More Zombie malware games

  • @hackwithprogramming7849
    @hackwithprogramming7849 21 ชั่วโมงที่ผ่านมา

  • @circuitgamer7759
    @circuitgamer7759 7 ชั่วโมงที่ผ่านมา +1

    Currently every single comment in the comment section (I scrolled through all of it) is about the old title being bad, so I want to add my comment just so it isn't all negative :)
    I'm 3:28 into the video so far, so I haven't seen most of it, but it's already interesting to realize how this could work. I've been very slowly trying to learn Godot (it should be very easy for me honestly, I'm great at programming in a lot of languages, but I can't keep focus long enough to really learn Godot for some reason), but I don't know much about it yet at all, so I'll probably learn quite a bit from this video. In general I've learned it's very frequently easier to learn from using something as it wasn't intended to be used than using it as intended, and this is definitely the former, so it should be fun :)

  • @PokemonBattleQuestGodot
    @PokemonBattleQuestGodot 21 ชั่วโมงที่ผ่านมา +1

    not godot 😂

  • @NVsquare
    @NVsquare 18 ชั่วโมงที่ผ่านมา

    Is it the Russians again?

  • @joaoprogrammer5306
    @joaoprogrammer5306 20 ชั่วโมงที่ผ่านมา +1

    Lol

  • @vizionthing
    @vizionthing 20 ชั่วโมงที่ผ่านมา +5

    This was a pile of shit, come on John wtf are you doing? how is this any diffeferent from ANY OTHER PROGRAMMING LANGUAGE ?

  • @ioxmedia
    @ioxmedia 21 ชั่วโมงที่ผ่านมา +2

    First

  • @Mauretto-j7u
    @Mauretto-j7u 21 ชั่วโมงที่ผ่านมา

    MHA!

  • @ヽノ-u4t
    @ヽノ-u4t 7 นาทีที่ผ่านมา

    unsubscribed because of clickbait title and cheap content

  • @h471x
    @h471x 15 ชั่วโมงที่ผ่านมา

    Creepy

  • @jacoumata
    @jacoumata 11 ชั่วโมงที่ผ่านมา

    No comment

  • @craxxysum1264
    @craxxysum1264 21 ชั่วโมงที่ผ่านมา +2

    I read the article about a month ago as I am a Godot fan and I was amazed...it was a great read...and a somehow obvious vector that everybody missed...it's pure evil genius

  • @EmiliaHoarfrost
    @EmiliaHoarfrost 15 ชั่วโมงที่ผ่านมา

    Grrrrrrrrrrrrrrrrrrrrrrrr me not smort me see Godot dissed me angerrrrrrr

  • @MujurID
    @MujurID 21 ชั่วโมงที่ผ่านมา

    😶😶

  • @hydrogennetwork
    @hydrogennetwork 17 ชั่วโมงที่ผ่านมา

    how is this clickbait eople

  • @ThisIsJustADrillBit
    @ThisIsJustADrillBit 21 ชั่วโมงที่ผ่านมา +1

    Kernel level anticheat they said .. what could go wrong 😂😂😂

  • @gercekbko
    @gercekbko 21 ชั่วโมงที่ผ่านมา +2

    Godot's twitter account manager was a bad person tbh.

    • @gamersunite9026
      @gamersunite9026 20 ชั่วโมงที่ผ่านมา +1

      has n0othing to do with what the video is about?? 💔

    • @gercekbko
      @gercekbko 20 ชั่วโมงที่ผ่านมา

      @@gamersunite9026 Yeah it doesn't, I just wanted to point that out.

  • @HellCat-g7x
    @HellCat-g7x 21 ชั่วโมงที่ผ่านมา

    3d

  • @antigogle
    @antigogle 21 ชั่วโมงที่ผ่านมา +1

    Fourth

  • @d4nix5
    @d4nix5 21 ชั่วโมงที่ผ่านมา

    first!

  • @SLZeroArrow
    @SLZeroArrow 21 ชั่วโมงที่ผ่านมา +3

    it just never ends, huh Godot?

    • @gamersunite9026
      @gamersunite9026 20 ชั่วโมงที่ผ่านมา +4

      applies to unity/unreal as well

  • @kalinathalie
    @kalinathalie 21 ชั่วโมงที่ผ่านมา +1

    Awesome content, I'm starting with godot engine and it's pretty cool ^^

  • @sakib87-ih
    @sakib87-ih 21 ชั่วโมงที่ผ่านมา +1

    john lots of respect from BANGLADESH

  • @pelaajahacks8358
    @pelaajahacks8358 21 ชั่วโมงที่ผ่านมา

    i just recommended godot to a friend

    • @ParasocialCatgirl
      @ParasocialCatgirl 21 ชั่วโมงที่ผ่านมา +7

      Rest assured that this is *not* a problem with Godot itself.
      This is like saying 'The C++ programming language can be used to make malware'.

    • @pelaajahacks8358
      @pelaajahacks8358 15 ชั่วโมงที่ผ่านมา

      @ yeah, just kind of bad timing which i found funny

  • @45678213914284289421
    @45678213914284289421 20 ชั่วโมงที่ผ่านมา +9

    Clickbait. Now try the same with Unity or Unreal and see what happens.

  • @andrewkelley9405
    @andrewkelley9405 20 ชั่วโมงที่ผ่านมา

    as if things couldn't get worse for Godot.

    • @ninstars
      @ninstars 20 ชั่วโมงที่ผ่านมา +7

      Did you watch the video or bother reading the article? This isn't exclusive to Godot, you can achieve the exact same thing with almost any other game engine.

    • @gamersunite9026
      @gamersunite9026 20 ชั่วโมงที่ผ่านมา +1

      gonna do this with unity just to make you mad :3

  • @stewartmaxey8369
    @stewartmaxey8369 21 ชั่วโมงที่ผ่านมา

    Thanks for the great information.

  • @SolitaryElite
    @SolitaryElite 21 ชั่วโมงที่ผ่านมา

    communists trying to make a good game engine(impossible)

    • @ParasocialCatgirl
      @ParasocialCatgirl 20 ชั่วโมงที่ผ่านมา

      "Everything I don't like is communism!"

    • @gamersunite9026
      @gamersunite9026 20 ชั่วโมงที่ผ่านมา +7

      SOMEONE opened up the video to comment this without knowing this applies to every single engine...

    • @SolitaryElite
      @SolitaryElite 20 ชั่วโมงที่ผ่านมา

      @@gamersunite9026 nah i was just joking, i actually use godot, and i know in this case, the bad guys "abused" the engine and that you can do this with any engine. when it comes to the engine... it's kind of bad, important features are "hidden away", it's messy ui etc... but i accept it anyways because it's one of the few good open source game engines, it don't really like using stuff like unreal or unity.

  • @SkyFly19853
    @SkyFly19853 21 ชั่วโมงที่ผ่านมา +1

    I never ever liked Godot engine in the first place....
    such an unnecessary game engine...

    • @ヽノ-u4t
      @ヽノ-u4t 20 ชั่วโมงที่ผ่านมา +4

      It is very calming to know, that only the Godot engine can be used to stage malware because it is impossible with other engines :shrug:

    • @Bempus
      @Bempus 20 ชั่วโมงที่ผ่านมา +3

      You can make malware with anything that can make code, this is probably just a heads up to be aware when downloading games/software in general. This is just an example using Godot, you could make malware with GameMaker, Unity, Unreal, Java, Rust, etc. and Godot is a very good engine for it's purposes.

    • @ParasocialCatgirl
      @ParasocialCatgirl 20 ชั่วโมงที่ผ่านมา +6

      How so?
      I personally think that Godot's existence, as a free-and-open-source alternative to the duopoly of Unity and Unreal is ultimately a very good thing for the game development ecosystem as a whole. After all, if Godot didn't exist as a viable alternative, the duopoly would be able to get away with much scummier business practices.
      Just off the top of my head, do you also remember the Unity Runtime Fee debacle (and other enshittification tactics recently employed by Unity Technologies)? And are you aware of Tencent's notable investments in Epic Games (and the fact that Unreal Engine's current 'free-to-start using' pricing model is thanks to this investment)?
      Now, with these rather worrying blemishes on the record of Unity and Unreal, would you agree with me that it's better to have a fully usable alternative engine out there which one can start using right now (Godot) than it is to be obliged to put up with the continued enshittification of the Unity/Unreal duopoly?

    • @SkyFly19853
      @SkyFly19853 16 ชั่วโมงที่ผ่านมา

      @@ヽノ-u4t
      Because it uses its own programming language which is unnecessary in the first place.

    • @Yezper
      @Yezper 15 ชั่วโมงที่ผ่านมา

      @@SkyFly19853 But why is it unnecessary? Is unreal engine also unnecessary because they made their own blueprint system?
      If you don't like it because they made their own language then you can use C# in Godot instead of GDScript.

  • @diffdimgamerseven9986
    @diffdimgamerseven9986 21 ชั่วโมงที่ผ่านมา +1

    resetti. my favorite (probably not) animal crossing character