There is a website impersonating krita that might distribute malware

Sorry i didnt know where to post this.

There is a page called krita.io that i thing is distributing malwere the installer has untrusted certificate and it makes processes that have similar names to system processes

Hello @shantia2022 and welcome to the forum :slight_smile:

Thank you for providing information about this.
(I’ve edited your topic title and changed the category.)

That particular domain/website has been known about for some time:

Beware of imposters sending mails to artists about offers on behalf of Krita foundation.

Fake promo request from spammer/scammers

I don’t know if there has been any further attempt to report the domain to its registrar or website hosting provider.
Someone else may know more details about this.

I take it that krita . io does not have any connection to the real Krita site?

(How come there is no warning of this site on the official krita site? I noticed it was mentioned in one of the links)

Absolutely not. It’s an opportunistic ā€˜name squatting’ exercise by someone up to no good.
Nowadays, there are so many first level domain codes that you can easily and cheaply register/claim krita.{whatever} then use it to deliver a website.

A quick check finds that nine krita.{something} domains are available for registration.
I could get krita[dot]uk for US$8.00 a year.

That would be a useful thing to do but I’ve no idea why it hasn’t happened.
Maybe @halla could comment on this.

2 Likes

i have sent an abuse report to their host it should get taken down soon. if the host cares enough

3 Likes

This might be slightly offtopic, but some sites ( like specific libraries. ) do have those kinds of warning very visible on their main pages; although, to be fair, I am now slightly tempted to purchase some of the cheaper .pl domains as redirects… ; P

Still, I do think putting a warning would be a good idea; plus maybe a warning for iOS users. I’ve seen a few ā€œā€ā€œofficial Kritaā€ā€œā€ releases on the iOS store, and some do have very short lives, but not all. I haven’t installed them obviously, but it still feels nasty for them to do something like that.

1 Like

this thing’s so vibecoded it can’t even handle switching languages :broken_heart:
as someone who was using pirated software for the long time in my life i’m fine with soft-portals, but this thing is clearly malicious.

..and why pirate a free software anyway?
If they wanted to make a special version they could just use the source code and change what they want + change name, right? I could - if I knew anything about code - use Kritas code, change whatever I thought I could do better, and ship it as Zabspaint?

(What is a soft-portal?)

2 Likes

If a free software application is well known and popular then making a fake imitation of it, complete with same naming and logos etc is a good way to trick people into downloading and installing it.
If you do that then you have your software running on people’s computers and it can do whatever you’ve designed it to do in addition to pretending to be the genuine software.

Also, the real krita has internet access for the purpose of downloading news articles. So people expect krita to access the internet (if they’ve enabled that) and will not be worried by any system warning messages (from firewalls etc) that tell them the so-called ā€˜krita’ is accessing the internet.

It’s the software version of a Trojan Horse.

basically any download-this-software-for-free-no-virus type sites that has it’s own library of software (:pirate_flag:) often packed with activators like keygens, patches, and other ways to bypass license checks. and viruses. so yeah download anything from there at your own risk.

i dunno, maybe to stuff it full of malware and hope someone downloads it from a non-official source or for other shady things.

i have krita in my steam library anyway, thought it was worth to pay for software i actually use on daily basis, even if it’s free.

1 Like

I’ve purchased Krita on android, and I think in windows store (I use linux now though) and once in a while I donate. I don’t mind spending some on a program.. but since nobody has to pay for it, it seems super useless to soft-portal it. Unless there’s evil intent.

Thanks for the explanation :slight_smile:

1 Like

My personal general rule of thumb is; I can pay as much as I would for a monthly CSP subscription, or semi-yearly OTP’s like when Rebelle was for 170~ PLN. These days a bit too broke to contribute, but I can’t wait to be able to donate to my favorite projects/ sites again ;_;

1 Like

Why pirate a free software? Because it provides an opportunistic chance of sending out malware that can be literally anything. The domain by itself is an example of ā€œtypo-squattingā€ and the website does have the legitimate chance of giving out malware (infostealers, viruses, trojan horses, worms, spyware, etc.) that can range from just slow down you computer & steal information or at worse case end up being ransomware that locks down your computer & data that if there isn’t an unecrypter then the only real thing you can do is install a completely new thing of whatever OS your computer uses while trying to get your information back before it was all hijacked.

Other such software gets targeted all the time not just Krita, it’s just a bunch of opportunistic groups using every trick in the book to make money. Even though Krita is open source, not all users are gonna sit down and individually look through each line of code to verify anything, even then any malicious code can be intermixed with genuine code to make detection difficult, a trick called obfuscation.

3 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.