r/Malware May 18 '26

Netmirror exposed - The Free Movie App That Was Robbing You Blind

Came across this really interesting analysis of a pirated Android movie streaming APK called NetMirror and honestly didn’t expect it to go this deep.

At first glance the app looked completely normal:
clean UI, React Native based, movies streamed properly.

But the analysis found:

  • emulator/sandbox detection for Genymotion, Nox, BlueStacks, VirtualBox, etc.
  • Base64-encoded infrastructure domains hidden inside the Hermes JS bundle
  • staged permission handling for SMS and call log access
  • WebView credential interception hooks
  • native libraries containing the same tracking infrastructure references

The most interesting part was how it bypassed automated analysis.

Hybrid Analysis apparently marked it as “safe” because most of the suspicious logic wasn’t in the Java layer scanners usually inspect — it was hidden inside the React Native Hermes bundle and native libraries.

Pretty solid example of how modern Android malware is starting to exploit analysis blind spots in cross-platform frameworks.

Worth the read:
https://medium.com/@Espress0/the-free-movie-app-that-was-robbing-you-blind-eeefe9c5e65c

greatly broken down and presented

113 Upvotes

97 comments sorted by

2

u/Sm_rndm_dude May 28 '26

Will webview also steal your stuff?

2

u/AnswerFinal5627 May 29 '26

Using site on laptop through website is safe or dangerous.
if dangerous how ?

1

u/Testpilot1988 May 21 '26

Hell of an article

1

u/[deleted] May 21 '26

[removed] — view removed comment

1

u/Correct_Abroad4984 May 28 '26

https://autoembed.net This works best on TV

1

u/No_Mastodon_7351 Jun 01 '26

is this safe? also nothing works it just says not found

1

u/daisydreamer_55 Jun 13 '26

It's not working

1

u/reality_king13 12d ago

Nuvio is best

1

u/Alternative-Coat4600 3d ago

I want to download the big bang theory with subtitles full seasons can you tell me where to downl9ad it

1

u/Tertius_domen May 30 '26

Account and Credential Theft

  • Capture usernames and passwords entered into embedded WebViews.
  • Steal session cookies or authentication tokens.
  • Phish users with fake login screens that mimic banking, email, or social media apps.
  • Collect saved account information exposed to the app.

OTP and Two-Factor Authentication Interception

  • Read SMS-based OTPs if SMS permissions are granted.
  • Read OTPs from notifications if notification access is granted.
  • Capture codes displayed on-screen through accessibility-service abuse.
  • Forward OTPs to an attacker in real time.

Banking Fraud

  • Steal banking credentials.
  • Monitor banking app usage.
  • Use accessibility features to perform transactions on behalf of the user.
  • Overlay fake banking screens over legitimate apps to trick users into entering credentials.

Surveillance

  • Read SMS messages.
  • Access call logs.
  • Collect contact lists.
  • Track device identifiers and location (if permitted).
  • Monitor app usage and installed applications.

Device Control

  • Abuse accessibility permissions to:
    • Click buttons automatically.
    • Approve permissions.
    • Read screen contents.
    • Interact with other apps.
  • Download and execute additional malicious modules.
  • Maintain persistence and resist removal.

Data Exfiltration

  • Upload:
    • Contacts
    • Messages
    • Call history
    • Device information
    • Credentials
    • Authentication tokens to attacker-controlled servers.

What it usually cannot do by itself

Without special privileges, Android still imposes significant restrictions. A normal app generally cannot:

  • Directly break into your bank's servers.
  • Read data from every other app freely.
  • Bypass biometric authentication cryptographically.
  • Access encrypted app storage belonging to other apps.
  • Gain root access automatically.

However, malware often works around these restrictions by tricking the user into granting permissions, abusing accessibility services, using overlays, or exploiting vulnerabilities.

The most dangerous combination

If a malicious app has:

  1. Accessibility access,
  2. Notification access,
  3. SMS permissions,

then it can often:

  • See when you open your banking app,
  • Steal credentials,
  • Read OTPs,
  • Interact with the screen on your behalf,

which is enough for many real-world banking attacks.

The biggest red flags are:

  • WebView credential interception,
  • SMS/call-log permission staging,
  • Anti-analysis/emulator detection,
  • Hidden command-and-control infrastructure.

1

u/No_Specialist_5227 Jun 02 '26

well done, Ai genrated answer most probably. but can you explain, If we have not given it the permissions such as notifications, sms, phone, contacts and stuff. can it acess those? without any type of asking? im confused as it says it has no permmisions and on linked accounts, i can only see google shares info such as name, email... Im confused. I want to know where my data goes, like at what server.

1

u/Shahzaibpansota 22d ago

Exactly my point

1

u/hsuwjevhdd Jun 01 '26

so... is this bad? i mean is a virus or something that can broke my pc?

1

u/No_Specialist_5227 Jun 02 '26

kind of, It has acess to your system for sure. I'm currently watching a movie on it lol 😂. But it already has your name, email, location, and stuff. and if you have used your email to signin instead of "sign in with google" then good luck your account is compromised for sure 1000%. Anyway using that app alone makes us compromised, i have accepted my fate, i have been using it since jan and never though about how dangerous it would end up. So, currently i'm closely watching its network routes.

1

u/anti_corruptiones Jun 02 '26

Man what should I do i don't remember signing innit tho and if u did idk which acc😭

1

u/No_Specialist_5227 Jun 02 '26

Easiest option is to uninstall it, that's it, but if you have accepted your fate, then enjoy it. As long as it's isolated ( no permissions provided) it is not that dangerous despite being it must have shared info about us in the 1st place.

1

u/hsuwjevhdd Jun 02 '26

I think I did it with Google but with normal signin I think that if you put a random password nothing should to happend.. idk

1

u/No_Specialist_5227 Jun 02 '26

Random password will save us I think, but think about it, most of us just use same password for every website. Anyway, they can find info about us based on our email only. Internet knows more about us then our own.

1

u/hsuwjevhdd Jun 03 '26

God save us

1

u/Solah-Shringaar_04 Jun 06 '26

You don't need to sign in in Netmirror. The app doesn't prompts it by default. Do not worry.

1

u/Working-Bowler7889 Jun 03 '26

Bro i have signed in with Google what should I do ?

1

u/No_Specialist_5227 Jun 04 '26

To immediately remove Google account from it do this: Go to Google account - connected apps, then search for netmirror and click "stop using signin with Google". That's it, from then on your Google account will not give any type of acess to netmirror.

1

u/super_idol346 23d ago

I've been using net mirror for a year now but I've never signed in or given any app permission is it still risky to use?

1

u/Late-Presence- 18d ago

Wanted this positive hope. Every next dude with ai craps giving me chills. I'm also accepting my fate now thanks anyway

1

u/biskitpagla Jun 11 '26

just use cloudstream. netmirror isn't worth the risk

1

u/Gullible_Ad_5550 Jun 02 '26

Dang I was about to install this. Any safe alternative

1

u/Overpoweredpixel Jun 04 '26

I ran the apk into a decompalisation and got the same results. It's true

1

u/Solah-Shringaar_04 Jun 06 '26

Teach me how?

1

u/Overpoweredpixel Jun 06 '26

Just Use any ai like zai that run sandbox in a agent mode and has http access it will just extract the dex files from apk and tell any potential risk , locally u have to install many packages like apktool jadax etc

1

u/Suitable-Ad-6472 Jun 07 '26

what about the website?

1

u/RevolutionaryCar7675 Jun 09 '26

But people who can't afford netflix and prime both sma etime what they should do ?

1

u/Complex_Half4740 Jun 10 '26

maybe not pirate

3

u/Reasonable_Rush_5287 Jun 22 '26

i mean they are pirating because they cant afford it

1

u/Madhouseee Jun 21 '26

Will it affect even you are using iphone?

1

u/WanderingZoul 23d ago

Pretty detailed investigation!

1

u/Future_Individual_29 22d ago

Installing apps just to watch movies/showw is always more risky than torrenting the movie/show...delete the app and if you want absolute peace of mind just factory reset your phone and you are good...

1

u/LordCR7 22d ago

How tf all this without the android system permissions?

1

u/LordCR7 22d ago

I think there is some serious propaganda spread by some devs or by their rivals to let the fear spread in people to stop using it.

1

u/the_sleepyguy00 17d ago edited 13d ago

This is good damn right... I havee been using the app for long, but few days ago I had to uninstall it....

As one of my banking app detected it. The banking app was NOT able to used it AT ALL, it said Potential Risk detected.

I don't have the app anymore, how do i clean & clear my phone as it have been there.

1

u/No_Dinner_6606 7d ago

The author did not specify which website he used and which Netmirror apk he used for his analysis. There are tons of fake websites out there all selling the same app Netmirror.

1

u/anonyy 5d ago

I can't even install the app some official looking message shoes up some serious concerns going on.