PılPılı ← All posts

Naming a game in 2026: the malware check nobody does

One live trademark matter is with our lawyer and is deliberately absent from this post; everything below is a settled case.

PilPili is a browser-game arcade of small games, built by one person directing AI for about two hours a day. A month of naming games at volume produced a log — every candidate, what was searched, what was found, the verdict — and it has become one of the most quietly useful documents in the whole project. Three findings from it generalise to anyone shipping games, and the first one we have never seen written down anywhere.

A clean trademark search is not a clean name

We had a game called Brick Storm. The name cleared every conventional test: no distinctive game title collision, no registered trademark in the classes that matter for games (9, 28, 41 and 42 — software, toys and games, entertainment services, software services). By the book, shippable.

It was retired anyway, because BRICKSTORM is an active malware family. Security advisories about it own that search term — pages from incident responders and government CERTs, updated continuously, with an authority signal a browser game will never outrank. And it gets worse than search: brand-safety scanners at ad networks and game portals match names against threat intelligence feeds. A game sharing a name with active malware isn't a legal problem. It's a commercial one — flagged by machines that will never explain themselves, in reviews you will never see.

It happened again, harder, with a tower-defence game we wanted to call Gate Keepers. Gatekeeper is Apple's built-in security layer on every Mac; "Gatekeeper bypass" is a permanent stream of vulnerability advisories, and it appears by name in a widely used threat-detection catalogue — plus, for good measure, a live tower-defence title on Steam already uses the word. Rejected before a line was written. The game is called No Way Through, which also happens to say the win condition out loud.

The naming checklist needs a third tier after trademarks and title collisions: the security namespace. Malware families, vulnerability identifiers, threat-actor naming schemes. One detail makes it actionable: Microsoft names entire threat-actor groups after weather — Storm, Blizzard, Typhoon, Tempest — so any name ending in a dramatic weather word is presumed contaminated until searched. Weather words are exactly what game names reach for. Check yours.

Name the action, never the object

Two of our candidates died in two days, the same way. A slingshot game wanted the Hindi word for slingshot; a marbles game wanted the Hindi word for marble. Both searches came back crowded — one developer ships three slingshot games under that first word, every one of them on the store today; five marble games own the second.

The third repeat was a carrom game, and it is the purest case in the log: every carrom title already made is Carrom-something — and the word itself is a registered mark, filed on 19 June 1905 for game boards, still owned, and defended down to the spelling. The game got named after its most argued-about rule instead — Cover the Queen — which no one owns, because no one else thought one step past the object.

Everyone shipping the obvious game reaches for the obvious noun first, so the name of the object in the game is the most contested string in its niche, in any language. What clears is the action, the rule, the win condition — one step less obvious than the object, and one step is all it takes. Any title built from the thing you fire, hit or fly is assumed taken until proven otherwise.

Where descriptive names are fine, and where they aren't

The two-tier structure of the checklist is itself worth stealing, because the common failure is applying one standard to both cases.

Your studio or site brand must be genuinely ownable — unique enough to dominate its own search results, because it is the thing you will spend years pointing people at.

Individual game titles need much less. They must avoid distinctive existing game titles and registered marks in the four classes — and that is all. Descriptive names coexist by the hundred; nobody owns "Bubble Shooter," and a descriptive title sitting alongside look-alikes is normal commerce, not a lawsuit. We shipped a snake game whose name is shared, descriptively, with several others, and recorded exactly why that's fine. Treating every game title to the brand-name standard would have cost weeks and produced worse names.

Two corollaries from the log. First, search app stores, not just the web — one of our names cleared everything except a live phone game one letter away, found only by searching the store directly; the game got a new name. Second, write the finding down even when it's "taken": the record of why a rejected name failed has stopped us re-proposing the same name twice, which absolutely happens once you're naming at volume.

The checklist, in order

For each candidate, cheapest useful failure first: registered marks in classes 9, 28, 41, 42 → distinctive title collisions, web and app stores → the security namespace (malware families, vulnerability IDs, threat-actor schemes — and presume weather words contaminated). Log every name, what was searched, what was found, and quote the specific collision when rejecting — "too crowded" is not a finding, and a log that says "nothing found" when three look-alikes exist is worse than no log.

The whole routine costs maybe twenty minutes per name. The one time it matters, it saves a launched game from a rename — and a rename after launch costs every link, every share, and every player who typed the old name into a search box and found a security advisory instead.