Sorry i didnt know where to post this.
There is a page called krita.io that i thing is distributing malwere the installer has untrusted certificate and it makes processes that have similar names to system processes
Sorry i didnt know where to post this.
There is a page called krita.io that i thing is distributing malwere the installer has untrusted certificate and it makes processes that have similar names to system processes
Hello @shantia2022 and welcome to the forum ![]()
Thank you for providing information about this.
(Iāve edited your topic title and changed the category.)
That particular domain/website has been known about for some time:
Beware of imposters sending mails to artists about offers on behalf of Krita foundation.
Fake promo request from spammer/scammers
I donāt know if there has been any further attempt to report the domain to its registrar or website hosting provider.
Someone else may know more details about this.
I take it that krita . io does not have any connection to the real Krita site?
(How come there is no warning of this site on the official krita site? I noticed it was mentioned in one of the links)
Absolutely not. Itās an opportunistic āname squattingā exercise by someone up to no good.
Nowadays, there are so many first level domain codes that you can easily and cheaply register/claim krita.{whatever} then use it to deliver a website.
A quick check finds that nine krita.{something} domains are available for registration.
I could get krita[dot]uk for US$8.00 a year.
That would be a useful thing to do but Iāve no idea why it hasnāt happened.
Maybe @halla could comment on this.
i have sent an abuse report to their host it should get taken down soon. if the host cares enough
This might be slightly offtopic, but some sites ( like specific libraries. ) do have those kinds of warning very visible on their main pages; although, to be fair, I am now slightly tempted to purchase some of the cheaper .pl domains as redirects⦠; P
Still, I do think putting a warning would be a good idea; plus maybe a warning for iOS users. Iāve seen a few āāāofficial Kritaāāā releases on the iOS store, and some do have very short lives, but not all. I havenāt installed them obviously, but it still feels nasty for them to do something like that.
this thingās so vibecoded it canāt even handle switching languages ![]()
as someone who was using pirated software for the long time in my life iām fine with soft-portals, but this thing is clearly malicious.
..and why pirate a free software anyway?
If they wanted to make a special version they could just use the source code and change what they want + change name, right? I could - if I knew anything about code - use Kritas code, change whatever I thought I could do better, and ship it as Zabspaint?
(What is a soft-portal?)
If a free software application is well known and popular then making a fake imitation of it, complete with same naming and logos etc is a good way to trick people into downloading and installing it.
If you do that then you have your software running on peopleās computers and it can do whatever youāve designed it to do in addition to pretending to be the genuine software.
Also, the real krita has internet access for the purpose of downloading news articles. So people expect krita to access the internet (if theyāve enabled that) and will not be worried by any system warning messages (from firewalls etc) that tell them the so-called ākritaā is accessing the internet.
Itās the software version of a Trojan Horse.
basically any download-this-software-for-free-no-virus type sites that has itās own library of software (
) often packed with activators like keygens, patches, and other ways to bypass license checks. and viruses. so yeah download anything from there at your own risk.
i dunno, maybe to stuff it full of malware and hope someone downloads it from a non-official source or for other shady things.
i have krita in my steam library anyway, thought it was worth to pay for software i actually use on daily basis, even if itās free.
Iāve purchased Krita on android, and I think in windows store (I use linux now though) and once in a while I donate. I donāt mind spending some on a program.. but since nobody has to pay for it, it seems super useless to soft-portal it. Unless thereās evil intent.
Thanks for the explanation ![]()
My personal general rule of thumb is; I can pay as much as I would for a monthly CSP subscription, or semi-yearly OTPās like when Rebelle was for 170~ PLN. These days a bit too broke to contribute, but I canāt wait to be able to donate to my favorite projects/ sites again ;_;
Why pirate a free software? Because it provides an opportunistic chance of sending out malware that can be literally anything. The domain by itself is an example of ātypo-squattingā and the website does have the legitimate chance of giving out malware (infostealers, viruses, trojan horses, worms, spyware, etc.) that can range from just slow down you computer & steal information or at worse case end up being ransomware that locks down your computer & data that if there isnāt an unecrypter then the only real thing you can do is install a completely new thing of whatever OS your computer uses while trying to get your information back before it was all hijacked.
Other such software gets targeted all the time not just Krita, itās just a bunch of opportunistic groups using every trick in the book to make money. Even though Krita is open source, not all users are gonna sit down and individually look through each line of code to verify anything, even then any malicious code can be intermixed with genuine code to make detection difficult, a trick called obfuscation.
This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.