Is Soap2Day Safe in 2026? Fake Clones and Malware Risks

Daniel Zimmermann
17 Min Read
Closed Soap2Day cinema surrounded by clone browser windows, redirects, notifications, and a dangerous download.
The original Soap2Day closed in 2023, while unrelated clones continue to reuse its name.

The original Soap2Day closed in June 2023. A current website, app, or APK using the Soap2Day name is not proof that the service returned or that the former operators are involved. Treat it as an unrelated clone until independently verified. Merely opening and closing a page does not prove that your device is infected; the response depends on whether you clicked a redirect, allowed notifications, downloaded a file, installed or ran something, signed in, or entered payment details.

If a Soap2Day-branded page is open now, do not click Play again, approve a CAPTCHA, call a displayed support number, or install a “required” player. Close the tab or browser window and use the action table below. You do not need to revisit the page to diagnose what happened.

What Happened to the Original Soap2Day?

In June 2023, the network’s known official domains displayed the same message saying that Soap2Day had closed “forever.” Contemporary reporting listed domains such as soap2day.to, soap2day.ac, soap2day.sh, and soap2day.mx among those showing the closure notice.[1] That is the important identity boundary: the original service stopped operating, while the search demand and recognizable name remained.

Later legal proceedings in Canada referred to defendants operating platforms under the “Soap2day” brand and allowed additional domains associated with those platforms to be added to a blocking order.[2] This does not establish one legitimate successor. It shows why the name can appear across changing domains even after the original shutdown.

A copied logo, familiar layout, “official” label, HTTPS padlock, or working video therefore proves very little. It does not verify who controls the page, which advertising network it loads, where a Play overlay redirects, or what an offered download contains.

Are Current Soap2Day Sites All Malware?

No single verdict applies to every site using the name. They are different domains operated by unknown parties, and their content can change. Some may show only intrusive advertising; others may request notification permission, collect account or card data, or push extensions, players, apps, APKs, and fake updates. Calling every clone confirmed malware would be inaccurate. Calling any of them the safe official continuation would also be unsupported.

At the time of our checks, several Soap2Day-branded domains had materially different Gridinsoft Website Reputation Checker results:

Domain report Observed result and why it matters
soap2day[.]to Classified as Browser Notification Spam with a 13/100 trust score and three provider warnings. The report describes fake “Click Allow” prompts that can start a persistent push-ad feed.
soap2day[.]pe Classified as Phishing with a 10/100 trust score. Registration or data-entry forms on an unverified clone create an account-theft and data-harvesting decision, not merely an advertising nuisance.
soap2day[.]my Classified as Suspicious with a 30/100 trust score and provider warnings. The more cautious label also illustrates why risk should be judged from current evidence rather than assumed from the brand alone.

These are point-in-time reports for specific domains. They do not certify every page, ad host, redirect destination, future domain state, or downloaded file. A clone can also move the risky action to a different hostname after the first page loads.

Gridinsoft safety report for the current soap2day.to domain showing a Browser Notification Spam verdict and 13 out of 100 trust score.
The current soap2day.to report shows a Browser Notification Spam verdict, provider warnings, and a 13/100 trust score. This finding describes that domain at the recorded check time, not every Soap2Day clone or the former service.

Common Clone Red Flags

  • Play opens a new tab or several redirects. The visible control may be an advertising overlay, while the destination can change between clicks.
  • A fake CAPTCHA says “Click Allow.” Allow normally grants website notification permission; it does not verify that you are human or unlock a video.
  • A player, codec, extension, app, or APK is required. Modern browsers do not need an unknown installation from a streaming page to play ordinary web video.
  • A page claims it found viruses. A countdown, animated scan, or support number inside a webpage is not a trustworthy local diagnosis. Use the fake virus alert cleanup guide if the warnings continue after the tab is closed.
  • A “free” account requires a card. Do not provide payment details for age, location, identity, or trial verification on an unverified clone.
  • The Back button appears trapped. Close the tab or browser window instead of interacting repeatedly with the page.
  • A VPN is presented as the safety solution. A VPN changes the network path; it does not validate the operator, redirect chain, download, extension, or payment form.

What Happened and What Should You Do?

What happened Risk and next action
You only opened the page Close it. Check the browser’s Downloads and site-permission lists if a prompt appeared. A visit alone is not proof of infection, so do not install random cleanup tools in panic.
Play opened another tab Close both pages. Do not approve a CAPTCHA, notification, download, login, or support call on the destination. Remove any permission you granted to the destination hostname.
You clicked Allow Revoke notification permission for every unfamiliar allowed domain. The push messages can continue after all Soap2Day tabs are closed.
You downloaded a file but did not open it Delete it without launching it and empty the recycle bin or trash. The suspicious download guide explains when a scan is proportionate even if the file never ran.
You installed an extension, player, app, or APK Remove it, review browser and startup changes, then scan the device. Treat an install from a streaming prompt as untrusted even if a video played afterward.
You ran a downloaded file Stop sensitive activity on that device, disconnect it from work or financial accounts, remove obvious related software, and run a full malware scan. Use a clean device for password changes.
You entered a password or card Secure the account from a clean device, revoke sessions, enable MFA, and contact the card issuer if payment data was submitted.

Pop-Ups, Notifications, and Infection Are Different

A pop-up or redirected tab is page behavior. A browser notification is a permission-based message that can appear after the page is closed. An infection means unwanted code or software executed or was installed on the device. The three can occur in the same incident, but one does not automatically prove the others.

Microsoft has documented a large malvertising campaign that began on illegal streaming sites and passed visitors through four or five redirects before some devices received information stealers or remote-access software. Microsoft observed nearly one million devices in that campaign.[3] This is evidence about the illegal-streaming advertising ecosystem, not proof that every Soap2Day clone participated in that specific campaign.

The distinction matters for cleanup. If you only saw a new tab and closed it, browser review may be enough. If you approved a notification, remove the permission. If a file, extension, app, or APK ran, treat it as a device incident and perform a full scan plus account review.

Remove Soap2Day Notifications and Browser Changes

Open the browser’s site or notification settings and remove every unfamiliar domain from the Allowed list. Do not search only for “Soap2Day”: a redirect host may have requested the permission under a completely different name.

If soap2day keeps showing unwanted pop-ups, you likely granted it permission to send notifications. To stop them, you need to revoke that permission in your browser settings.

Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
  1. Copy and paste this into the address bar: chrome://settings/content/notifications
  2. Scroll down to the Allowed to send notifications list.
  3. Find soap2day.
  4. Click the three dots (...) next to it and select Remove (or Block).
Safari
  1. Open Safari and go to Settings (or Preferences).
  2. Click the Websites tab and select Notifications on the left.
  3. Find soap2day in the list on the right.
  4. Select it and click Remove (or change "Allow" to "Deny").
Mozilla Firefox
  1. Copy and paste this into the address bar: about:preferences#privacy
  2. Scroll down to Permissions and click Settings... next to Notifications.
  3. Type soap2day in the search bar or find it in the list.
  4. Select the site and click Remove Website.
Microsoft Edge
  1. Copy and paste this into the address bar: edge://settings/content/notifications
  2. Look under the Allow section.
  3. Find soap2day.
  4. Click the three dots (...) next to it and select Remove (or Block).
Brave
  1. Copy and paste this into the address bar: brave://settings/content/notifications
  2. Scroll to the Allowed to send notifications list.
  3. Find soap2day.
  4. Click the three dots (...) and select Remove (or Block).
Opera
  1. Copy and paste this into the address bar: opera://settings/content/notifications
  2. Check the Allowed to send notifications list.
  3. Find soap2day.
  4. Click the three dots next to it and select Remove.

Then review extensions and remove anything installed during the incident, especially a video player, downloader, search helper, coupon tool, VPN, PDF tool, or “security” extension that you did not already trust.

Google ChromeSafariMozilla FirefoxMicrosoft EdgeBraveOpera
Google Chrome
Extension Manager
  1. Launch Chrome.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions > Manage Extensions.
  4. Click Remove next to the extension you want to delete.

Quick Access: Type chrome://extensions/ in the address bar.

Safari
Settings > Extensions
  1. Open Safari.
  2. In the menu bar, click Safari and select Settings (or Preferences).
  3. Click on the Extensions tab.
  4. Select the extension and click Uninstall.
Mozilla Firefox
Add-ons and Themes
  1. Click the menu button, select Add-ons and themes.
  2. Go to the Extensions tab.
  3. Click the three dots (...) next to the extension and select Remove.

Quick Access: Type about:addons in the address bar.

Microsoft Edge
Browser Extensions
  1. Launch Microsoft Edge.
  2. Click the three dots (...) in the top right corner.
  3. Select Extensions.
  4. Find the extension and click Remove.

Quick Access: Type edge://extensions/ in the address bar.

Brave
Shields and Extensions
  1. Launch Brave browser.
  2. Click the menu icon > Extensions.
  3. Find the extension and click Remove.

Quick Access: Type brave://extensions/ in the address bar.

Opera
Extension Management
  1. Launch Opera.
  2. Click the Opera logo in the top left corner.
  3. Select Extensions > Extensions.
  4. Click the X or Remove button next to the extension.

Quick Access: Type opera://extensions/ in the address bar.

Open Extensions/Add-ons again and remove any entry linked to soap2day or clearly out of place.

Clear the affected site’s data and check the homepage, default search engine, startup tabs, and managed-browser policies. If changes return after the extension is removed, follow the broader browser hijacker cleanup workflow. A bundled desktop app or policy can reinstall a removed extension.

If You Installed or Ran a File

Clearing cookies is not enough after an installation or execution. Cookies do not remove a program, scheduled task, service, startup entry, browser policy, or file created outside the browser profile.

  1. Pause sensitive activity. Do not use banking, email administration, password managers, work dashboards, or crypto wallets on the affected device.
  2. Remove the visible item. Uninstall the player or app through the operating system and remove the extension through the browser. Do not run an uninstaller offered by the clone page.
  3. Review recent changes. Sort installed apps and downloads by date. Check startup items and scheduled tasks created around the incident.
  4. Run a full malware scan. Remove detections, reboot, and scan again if redirects, pop-ups, high resource use, unfamiliar processes, or security warnings return.
  5. Update safely. Install browser and operating-system updates only through the browser menu, system settings, or a verified app store.

If you see soap2day or other suspicious applications that you don't remember installing, you should remove them as well.

WindowsMacAndroid
Windows 10/11
  1. Right-click the Start button and select Installed Apps (or Apps & Features).
  2. Scroll through the list to find soap2day or any other unfamiliar program.
  3. Click the three dots (...) next to it and select Uninstall.
Mac OS
  1. Open Finder and go to the Applications folder.
  2. Locate soap2day or any app you don't recognize.
  3. Drag it to the Trash.
  4. Empty the trash to remove it permanently.
Android 11+
  1. Go to Settings > Apps > See all apps.
  2. Find soap2day or any suspicious app in the list.
  3. Tap on it and select Uninstall.

Removing the visible download may not remove everything it created. A loader, scheduled task, service, browser policy, extension, or bundled module can remain and recreate the symptom after reboot. Gridinsoft Anti-Malware can check for malware files, startup entries, scheduled tasks, browser changes, bundled apps, and other persistence after the manual review.

Scan files downloaded from this scam.

If the page or email made you download an invoice, coupon, tracking app, browser extension, or support tool, scan the PC before opening it again or logging into sensitive accounts.

Scan after a Soap2Day download

For an Android APK, remove the app, revoke any Device Administrator or Accessibility access it did not legitimately need, turn off installation from unknown sources for the browser or file manager used, update Android, and run the device’s built-in security scan. If the app had Accessibility, SMS, notification, or banking access, perform account recovery from another device.

If You Entered a Password or Card

Use a different, clean device for recovery when a file, extension, app, or APK was installed. A password changed on the same compromised device can be captured again.

  1. Change the affected password and every reused password.
  2. Sign out other sessions and remove unknown trusted devices.
  3. Turn on multi-factor authentication, then review recovery addresses, phone numbers, forwarding rules, app passwords, and connected applications.
  4. Check recent activity for unfamiliar logins, messages, purchases, subscriptions, or password-reset requests.
  5. Contact the card issuer if card details were entered. Ask about blocking or replacing the card and disputing unauthorized transactions.

The account recovery checklist covers session revocation and recovery settings in more detail. A malware scan can find device-side threats, but it cannot reverse a stolen password, cancel a card transaction, or prove that no data was exposed.

Does a VPN or Clean URL Scan Make a Clone Safe?

No. A URL report describes the domain and page state observed at one point in time. It cannot certify every embedded player, advertising host, future redirect, login page, or downloaded file. Check the exact destination you encountered, but use the result as one signal rather than permission to install software or submit data.

A VPN also does not validate a site. It may hide the destination from part of the local network and change the apparent IP address, but it cannot make a fake player genuine, prevent every malicious redirect, inspect every download, or protect credentials typed into a phishing form.

For the broader pattern, read the free movie streaming site scam guide. It explains why copied brands, rotating domains, deceptive controls, and third-party ad chains create similar risks across many streaming labels.

How to Avoid the Same Trap

  • Use licensed streaming services reached through a verified publisher or app store.
  • Do not treat a search-result title, “official” label, copied design, or HTTPS padlock as identity proof.
  • Keep website notifications blocked by default unless a site has a clear reason to send them.
  • Do not install a player, codec, extension, app, APK, or update offered by a streaming page.
  • Show file extensions and inspect Downloads before opening a new file.
  • Do not use a primary password or payment card for “free” stream verification.
  • Close the browser if Play launches a redirect, fake CAPTCHA, support number, or infection warning.
  • Do not revisit a suspicious clone to collect proof. Use browser history, permission lists, download timestamps, installed-app dates, and security logs instead.

FAQ

Is Soap2Day still active in 2026?

The original Soap2Day closed in June 2023. Sites and apps using the name today should be treated as unrelated clones unless independently proven otherwise; a familiar design or “official” claim is not proof that the old service returned.

Is there an official Soap2Day website or app?

We found no authoritative source establishing one current official successor. Do not trust a domain, app, APK, or extension only because it uses the Soap2Day name.

Can Soap2Day give me a virus just by visiting?

Opening and closing a page does not by itself prove infection. Risk rises if the page exploited an unpatched browser or if you allowed notifications, downloaded and opened a file, installed an extension or app, or entered credentials. Update the browser and respond to the actions that actually occurred.

Why do Soap2Day pop-ups continue after I close the site?

You may have granted notification permission to the clone or a redirect domain. Remove unfamiliar sites from the browser’s Allowed notification list. If redirects continue while browsing, also review extensions, startup pages, policies, and installed apps.

Should I delete a Soap2Day download if I did not open it?

Yes. Delete the file without launching it. Check the Downloads list and remove unfamiliar executables, disk images, archives, scripts, shortcuts, or APKs. A movie-like filename can still hide an installer when extensions are not visible.

Should I change my password after visiting a clone?

Change it if you typed it into the page, installed an extension or app, ran a suspicious file, or later saw account warnings. Merely opening and closing a page normally does not require a password change.

References

  1. Maxwell, Andy. “Soap2Day Shuts Down, Millions of Pirate Movie & TV Streamers Homeless.” TorrentFreak, June 14, 2023. torrentfreak.com
  2. Federal Court of Canada. “Default Judgment: Platforms Under the Brand ‘Soap2day,’ T-1125-23.” December 16, 2024, accessed July 27, 2026. court document (PDF)
  3. Microsoft Threat Intelligence. “Malvertising campaign leads to info stealers hosted on GitHub.” Microsoft Security Blog, March 6, 2025, accessed July 27, 2026. microsoft.com
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?