Is this Medium article about "NetMirror" malware legit?
I came across this detailed write-up on Medium about NetMirror.
The author claims the app was sophisticated spyware/adware that:
- Detects emulators/sandboxes to avoid analysis (Hybrid Analysis gave it a "Safe" verdict).
- Uses Base64 encoded C2 domains (
mobidetects[.]live, etc.). - Had hidden permissions like
READ_CALL_LOGandREAD_SMSready to request dynamically. - Performs device fingerprinting, credential scraping via WebView, and ad fraud.
The article is very technical (includes decompilation steps, code snippets, MITRE ATT&CK table), but it was published on April 5, 2026 (just last month). The author, "Espress0", doesn't have a long history on Medium.
Has anyone else analyzed this APK or heard of NetMirror? Is this a real threat or a well-written but fake/scareware post? I want to know if I should warn friends who sideload movie apps.