Fake Indeed Recruiters Push Spyware via “Interview” APK

eSecurity Planet · Medium sophistication
Last updated September 1, 2026

Researchers reported a real scam campaign where criminals pose as employers on Indeed, then pressure applicants to install a fake “interview” Android app. The app impersonates Indeed’s login, requests powerful permissions, and acts as a Trojan dropper that installs spyware on the victim’s phone.

How the Attack Worked

The scam begins with fake job listings on Indeed, where criminals pose as employers or recruiters to start conversations with applicants. Once trust is established, victims are directed to install an "interview" Android app, often distributed as a sideloaded APK rather than through an official app store. The pretext varies: identity verification, an application update, or access to a recruitment portal.

Once installed, the app impersonates Indeed's login page and prompts the victim to enter an email address. After that, it creates a VPN connection and functions as a Trojan dropper, delivering spyware onto the device. The malware also seeks Android's Accessibility permission, which can grant extensive control over the phone and even interfere with the victim's ability to uninstall the app.

Why It Succeeded

This campaign works because it borrows credibility from a platform job seekers already trust. Conversations start on Indeed, a familiar and legitimate job site, which lowers suspicion before the malicious request ever appears. Combining that trust with the natural urgency of a job opportunity or interview process pushes applicants toward installing an app without pausing to verify it. Because the login screen inside the app mimics Indeed's own branding, victims may not realize they are entering credentials into a hostile application rather than the real platform.

What to Watch For

  • Being asked to install an APK or sideload an app instead of using an official app store
  • App names suggesting an unofficial Indeed product, such as an "Indeed Interview" app
  • Pressure framed around urgency to proceed with hiring or an interview
  • A login screen appearing inside an unfamiliar app rather than Indeed's official apps
  • Unexpected requests for Accessibility permission or a VPN connection

Building Resistance

Job seekers and mobile users should treat any request to install an interview app, especially via APK, as a stop-and-verify moment, even when the conversation started on a trusted platform. Rather than following a recruiter's link, open Indeed or the employer's official website directly to confirm the listing and company. Mobile users should be trained to question apps that request Accessibility permissions or unexpected VPN access, since these are uncommon and high-risk requests for a legitimate interview tool. If a suspicious app was already installed, the device should be treated as potentially compromised: change passwords from a separate trusted device and review account security and MFA settings. Building these habits into routine job-search behavior reduces the chance that platform trust can be turned into a malware delivery path.

Key findings

  • Attackers posed as employers/recruiters on Indeed and used fake job listings to start conversations with applicants.
  • Victims were directed to install a fake Android “interview” app (often via an APK), framed as identity verification, an update, or access to a recruitment portal.
  • The fake app impersonated an Indeed login page, created a VPN connection after collecting an email address, and acted as a Trojan dropper that delivered spyware.
  • The malware sought Android Accessibility permission, which could allow extensive control and even interfere with uninstalling the app.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile users), HR/Recruiting, Talent acquisition teams, Anyone job hunting or using job platforms.
  • Affected industries: Cross-industry (job seekers / individual consumers).
  • Attack channels: website.
  • Impersonated: Employer/recruiter communicating via Indeed, Indeed (fake ‘Indeed’ login inside the app).

Red flags to watch for

  • Asked to install an APK / sideloaded app instead of using Google Play
  • App name suggests an unofficial Indeed product (e.g., “Indeed Interview”)
  • Request is framed as urgent to proceed with hiring
  • Login occurs inside an unfamiliar app rather than the official Indeed apps
  • Unexpected VPN connection request
  • Accessibility permission request from an interview app
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Indeed interview app scam work?

Scammers pose as employers on Indeed and, after engaging applicants, direct them to install an interview app framed as identity verification, an update, or portal access. The app impersonates Indeed's login page, sets up a VPN connection, and acts as a Trojan dropper that installs spyware.

What permissions should raise red flags on a job related app?

Requests for Android Accessibility permission and unexpected VPN connections are major warning signs, since Accessibility access can allow extensive control over a device and even interfere with uninstalling the app.

What should someone do if they already installed the fake app?

Treat the phone as potentially compromised, use a separate trusted device to change passwords, and review accounts and MFA settings.

How can job seekers verify a recruiter is legitimate?

Verify the request independently by opening Indeed or the employer's official website directly rather than following a link sent by the recruiter.

Read the video transcript

You apply on Indeed, a “recruiter” messages: “Please install an interview app to complete your interview.” Sounds legit, right? Here’s the trick: scammers post fake jobs on Indeed, then push an Android APK called something like “Indeed Interview.” It opens a fake Indeed login, then silently sets up a VPN and drops spyware. Aha moment: Indeed says there are only two real apps, Indeed Job Search and Indeed Flex. If an “Indeed Interview” app wants VPN or Accessibility access, it’s not hiring you, it’s hijacking your phone. Your move: if any recruiter tells you to install an interview APK, stop and verify by opening Indeed or the employer’s official site yourself, never from their link.

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Indeed “Interview App” Drops Android Spyware

Fake Indeed “Interview App” Drops Android Spyware

Scammers posted fake jobs on Indeed and then instructed applicants to install a fake Android “interview” app via an APK link. The app impersonates an Indeed login screen and acts as a malware dropper, ultimately installing spyware and attempting to take control of the phone using high-risk…

August 26, 2026
Fake Recruiters Push Malware Git Repos

Fake Recruiters Push Malware Git Repos

The article describes real-world scams where attackers pose as recruiters on LinkedIn and send developers “take-home assessment” code repositories that contain hidden malware triggers. Simply cloning and opening the project in an IDE or coding agent can execute malicious hooks/configs that download…

September 3, 2026
Fake IT Support on Teams Tricks Users Into Remote Access

Fake IT Support on Teams Tricks Users Into Remote Access

Microsoft reports a real campaign where attackers contact employees through Microsoft Teams while pretending to be IT/helpdesk and persuade them to grant remote control (for example via Teams “request control” or Quick Assist). Once they get an interactive session, the attacker silently installs…

September 3, 2026
Meta Ads Lure Users Into StreamRat Android Takeover

Meta Ads Lure Users Into StreamRat Android Takeover

Researchers reported a real malvertising campaign where ads on Meta platforms promoted a fake TV-streaming app to Spanish-speaking users, leading them to sideload an Android app. After victims approved a chain of permissions (including Accessibility), the StreamRat trojan could remotely control the…

September 2, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026