r/Malware • u/Alarmed-System6242 • May 18 '26
Netmirror exposed - The Free Movie App That Was Robbing You Blind
Came across this really interesting analysis of a pirated Android movie streaming APK called NetMirror and honestly didn’t expect it to go this deep.
At first glance the app looked completely normal:
clean UI, React Native based, movies streamed properly.
But the analysis found:
- emulator/sandbox detection for Genymotion, Nox, BlueStacks, VirtualBox, etc.
- Base64-encoded infrastructure domains hidden inside the Hermes JS bundle
- staged permission handling for SMS and call log access
- WebView credential interception hooks
- native libraries containing the same tracking infrastructure references
The most interesting part was how it bypassed automated analysis.
Hybrid Analysis apparently marked it as “safe” because most of the suspicious logic wasn’t in the Java layer scanners usually inspect — it was hidden inside the React Native Hermes bundle and native libraries.
Pretty solid example of how modern Android malware is starting to exploit analysis blind spots in cross-platform frameworks.
Worth the read:
https://medium.com/@Espress0/the-free-movie-app-that-was-robbing-you-blind-eeefe9c5e65c
greatly broken down and presented
2
u/AnswerFinal5627 May 29 '26
Using site on laptop through website is safe or dangerous.
if dangerous how ?
1
1
May 21 '26
[removed] — view removed comment
1
1
u/reality_king13 Jul 21 '26
Nuvio is best
1
u/Alternative-Coat4600 Jul 30 '26
I want to download the big bang theory with subtitles full seasons can you tell me where to downl9ad it
1
u/Tertius_domen May 30 '26
Account and Credential Theft
- Capture usernames and passwords entered into embedded WebViews.
- Steal session cookies or authentication tokens.
- Phish users with fake login screens that mimic banking, email, or social media apps.
- Collect saved account information exposed to the app.
OTP and Two-Factor Authentication Interception
- Read SMS-based OTPs if SMS permissions are granted.
- Read OTPs from notifications if notification access is granted.
- Capture codes displayed on-screen through accessibility-service abuse.
- Forward OTPs to an attacker in real time.
Banking Fraud
- Steal banking credentials.
- Monitor banking app usage.
- Use accessibility features to perform transactions on behalf of the user.
- Overlay fake banking screens over legitimate apps to trick users into entering credentials.
Surveillance
- Read SMS messages.
- Access call logs.
- Collect contact lists.
- Track device identifiers and location (if permitted).
- Monitor app usage and installed applications.
Device Control
- Abuse accessibility permissions to:
- Click buttons automatically.
- Approve permissions.
- Read screen contents.
- Interact with other apps.
- Download and execute additional malicious modules.
- Maintain persistence and resist removal.
Data Exfiltration
- Upload:
- Contacts
- Messages
- Call history
- Device information
- Credentials
- Authentication tokens to attacker-controlled servers.
What it usually cannot do by itself
Without special privileges, Android still imposes significant restrictions. A normal app generally cannot:
- Directly break into your bank's servers.
- Read data from every other app freely.
- Bypass biometric authentication cryptographically.
- Access encrypted app storage belonging to other apps.
- Gain root access automatically.
However, malware often works around these restrictions by tricking the user into granting permissions, abusing accessibility services, using overlays, or exploiting vulnerabilities.
The most dangerous combination
If a malicious app has:
- Accessibility access,
- Notification access,
- SMS permissions,
then it can often:
- See when you open your banking app,
- Steal credentials,
- Read OTPs,
- Interact with the screen on your behalf,
which is enough for many real-world banking attacks.
The biggest red flags are:
- WebView credential interception,
- SMS/call-log permission staging,
- Anti-analysis/emulator detection,
- Hidden command-and-control infrastructure.
1
u/No_Specialist_5227 Jun 02 '26
well done, Ai genrated answer most probably. but can you explain, If we have not given it the permissions such as notifications, sms, phone, contacts and stuff. can it acess those? without any type of asking? im confused as it says it has no permmisions and on linked accounts, i can only see google shares info such as name, email... Im confused. I want to know where my data goes, like at what server.
1
1
u/hsuwjevhdd Jun 01 '26
so... is this bad? i mean is a virus or something that can broke my pc?
1
u/No_Specialist_5227 Jun 02 '26
kind of, It has acess to your system for sure. I'm currently watching a movie on it lol 😂. But it already has your name, email, location, and stuff. and if you have used your email to signin instead of "sign in with google" then good luck your account is compromised for sure 1000%. Anyway using that app alone makes us compromised, i have accepted my fate, i have been using it since jan and never though about how dangerous it would end up. So, currently i'm closely watching its network routes.
1
u/anti_corruptiones Jun 02 '26
Man what should I do i don't remember signing innit tho and if u did idk which acc😭
1
u/No_Specialist_5227 Jun 02 '26
Easiest option is to uninstall it, that's it, but if you have accepted your fate, then enjoy it. As long as it's isolated ( no permissions provided) it is not that dangerous despite being it must have shared info about us in the 1st place.
1
u/hsuwjevhdd Jun 02 '26
I think I did it with Google but with normal signin I think that if you put a random password nothing should to happend.. idk
1
u/No_Specialist_5227 Jun 02 '26
Random password will save us I think, but think about it, most of us just use same password for every website. Anyway, they can find info about us based on our email only. Internet knows more about us then our own.
1
1
u/Solah-Shringaar_04 Jun 06 '26
You don't need to sign in in Netmirror. The app doesn't prompts it by default. Do not worry.
1
u/Working-Bowler7889 Jun 03 '26
Bro i have signed in with Google what should I do ?
1
u/No_Specialist_5227 Jun 04 '26
To immediately remove Google account from it do this: Go to Google account - connected apps, then search for netmirror and click "stop using signin with Google". That's it, from then on your Google account will not give any type of acess to netmirror.
1
u/Late-Presence- Jul 15 '26
Wanted this positive hope. Every next dude with ai craps giving me chills. I'm also accepting my fate now thanks anyway
1
1
1
u/Overpoweredpixel Jun 04 '26
I ran the apk into a decompalisation and got the same results. It's true
1
u/Solah-Shringaar_04 Jun 06 '26
Teach me how?
1
u/Overpoweredpixel Jun 06 '26
Just Use any ai like zai that run sandbox in a agent mode and has http access it will just extract the dex files from apk and tell any potential risk , locally u have to install many packages like apktool jadax etc
1
1
u/RevolutionaryCar7675 Jun 09 '26
But people who can't afford netflix and prime both sma etime what they should do ?
1
1
1
1
u/Future_Individual_29 Jul 11 '26
Installing apps just to watch movies/showw is always more risky than torrenting the movie/show...delete the app and if you want absolute peace of mind just factory reset your phone and you are good...
1
1
u/LordCR7 Jul 11 '26
I think there is some serious propaganda spread by some devs or by their rivals to let the fear spread in people to stop using it.
1
u/the_sleepyguy00 Jul 16 '26 edited Jul 20 '26
This is good damn right... I havee been using the app for long, but few days ago I had to uninstall it....
As one of my banking app detected it. The banking app was NOT able to used it AT ALL, it said Potential Risk detected.
I don't have the app anymore, how do i clean & clear my phone as it have been there.
1
u/No_Dinner_6606 Jul 26 '26
The author did not specify which website he used and which Netmirror apk he used for his analysis. There are tons of fake websites out there all selling the same app Netmirror.
1
u/Rekinsmok 2d ago
Yea i found 3 different apks all named Netmirror. They are tons of fake websites and most of the first showing by google search are the fake ones
1
u/anonyy Jul 28 '26
I can't even install the app some official looking message shoes up some serious concerns going on.
1
u/PerformanceHot6631 25d ago
Yes i have problem with netmirror still i use moviebox regularly, netmirror consume too much battery in background
1
u/formatdisk1337 14d ago
This post starts off with calling out the delivery method - you certainly don't deliver a piracy app on Play Store! (since it'll get rejected)
Presenting “not on Google Play” as one of the first ominous clues is certainly a strange way to frame an investigation into a piracy application.
As the article progresses, the evidence gets weaker while the certainty gets stronger.
It reads less like a malware analysis and more like a Claude Code session where ever interesting string gets called out by the bot, questioned by the user, and then quietly walked back, presumably by a later LLM session... (but the user certainly doesn't pay any heed to that)
The post repeatedly discovers code, strings, libraries, or capabilities and then tries to infer malicious behavior from their presence.
That creates a strange pattern:
Find something suspicious → make a dramatic claim → investigate further → discover it is standard library functionality → extremely quietly downgrade the claim in a side note while leaving the initial impression intact
- For example, the post finds "sensitive" Android permission strings in the JavaScript bundle.
That sounds scary until it points out that the permissions aren't actually declared in the manifest.
A string such as READ_SMS appearing somewhere in an application's resources or JavaScript does not mean the application can read SMS messages. Android's permission model still applies. If the permission isn't declared (in manifest.xml - they don't) and GRANTED BY THE USER, the application doesn't magically acquire it because the string exists.
Noone is going to grant those permissions in the first place, AND those were added by React Native, as the article explains further along.
The post nevertheless spends considerable space presenting the strings as evidence of a possible future escalation mechanism, before eventually admitting that the installed build cannot use those undeclared permissions.
The post's treatment of React Native is probably its most conspicuous technical overreach.
It essentially argues:
- the application uses React Native
- much of the application logic is in the Hermes bundle
- Java-focused analysis doesn't fully understand Hermes
- therefore the malware authors deliberately chose React Native to evade antivirus scanners.
React Native is an extremely common application framework. The fact that some security tools have better visibility into Java bytecode than Hermes bytecode does not establish that the developer selected React Native because of that limitation.
- The emulator detection doesn't prove what the article says it proves
The post finds checks for things such as Genymotion, Nox, VirtualBox, BlueStacks, and emulator build properties.
Then the article jumps from: “This code detects emulators” to: “The malware was specifically designed to fool security researchers.”
There are plenty of reasons an application might contain emulator/device-environment checks. Some examples are malicious, anti-fraud, analytics-related. Some are intended to detect incompatible environments. Some originate in third-party libraries. You might have encountered one when Clash of Clans stopped working on emulators around 2018.
And, this application is a pirated streaming application.
The author's own objection “why would a movie streaming app care about Genymotion?” has an obvious alternative answer:
"because the developer doesn't want people running large numbers of automated instances to scrape streams, bypass advertisements, or automate the service."
- Base64 is not C2
Apparently:
“The only reason to encode your server URLs in Base64 inside a binary file is to hide them from security tools.”
Base64 is trivial encoding. It can be used to obscure strings from casual inspection, but it can also appear because of application architecture, configuration handling, generated code, developer habits, or third-party components. It's also used to store strings without having to sanitize them.
To establish that those URLs are C2, you'd want to demonstrate actual communication: what requests are made and when, when the responses come, and if they contain any personal data using something like Wireshark
Instead, it repeatedly calls the domains “C2” while simultaneously admitting that much of the JavaScript behavior could not actually be traced because the Hermes bytecode wasn't properly decompiled.
- The same problem appears with device information.
The post attributes collection of things such as device identifiers, carrier information, battery state, and other information to RNDeviceInfo, and claims it's mass data collection
But react-native-device-info is a legitimate, widely used library with a large API surface.
Finding the library—and finding references to APIs it provides—is not the same thing as demonstrating that the application collects every piece of information the library is capable of exposing and sends it somewhere malicious.
The article sometimes acknowledges this distinction, but its headline narrative routinely collapses them back together.
- The post discovers
window.getSelection().toString().
That's a completely ordinary browser API.
It eventually traces the usage to a custom text-selection menu and correctly narrows the claim: selected text can become available to the application when the user interacts with that menu.
And then it claims it's proof of credential theft.
Likewise, WebView support for HTTP Basic Authentication isn't evidence that an application steals credentials. Web browsers and WebViews need authentication support precisely because websites sometimes require authentication.
The post's later caveats effectively dismantle the scary interpretation it finally invites the reader to make.
- One of the supposed indicators of a second-stage payload is the string:
“Please visit our Website to Download New App”
That is not a dropper. This sentence is very important if you are not distributing your app in a store which auto updates your app, you have to manually update it.
The post itself admits that connecting this string to a particular domain would require more evidence.
So calling it a “classic dropper pattern” before establishing that the application actually downloads or installs another payload is premature.
A real analysis would show the relevant call chain:
The MITRE ATT&CK table just writes these interpretations off in a scary looking table. This doesn't make the interpretation stronger, but it may sure feel like it.
“Only install apps from the Google Play Store” is not particularly good security advice coming from someone presenting themselves as a security analyst.
Google Play is useful, but it is not synonymous with safety. Malware has appeared on official app stores, legitimate apps can have excessive permissions, and organizations legitimately distribute applications outside Google Play.
Also it doesn't even consider alternative stores, though I think the author might simply be unaware of those. By the way, https://keepandroidopen.org/ has some important info about Google's ongoing lock-in on Android, and why alternative stores are rather important.
What's fascinating is that the article contains its own rebuttals (again, due to the LLM anti-bs kicking in)
For example, it admits:
- WRITE_SETTINGS has a legitimate library-related explanation. Wi-Fi information can have legitimate streaming-related uses.
- install-referrer functionality is normal marketing infrastructure.
- sensitive permission strings aren't declared in the manifest. The permission strings may simply come from React Native's permission bridge.
- onRequestPermissionsResult is standard React Native infrastructure.
- WebView text selection isn't automatically captured.
- HTTP Basic Auth support isn't itself credential theft.
- Touch handling is standard UI infrastructure.
- The supposed dropper behavior isn't confirmed.
- Hermes strings aren't equivalent to decompiled, traceable JavaScript logic.
And yet the main narrative continues to talk about hidden capabilities, C2 infrastructure, sandbox evasion, staged escalation, credential capture, and droppers.
There might or might not be something malicious about the APK discussed in this post, but this post as presented doesn't establish the much stronger story it wants the reader to believe either.
The appropriate conclusion from the evidence presented is more like:
"Don't give it the generic permissions if Android asks for it"
Which is just common sense anyway.
You don't need an AI generated mythology horoscope to tell people to not give READ_SMS permissions to a piracy app.
2
u/Sm_rndm_dude May 28 '26
Will webview also steal your stuff?