Fake Indeed Recruiters Push Spyware via “Interview” APK

eSecurity Planet · Medium sophistication
Last updated September 1, 2026

Researchers reported a real scam campaign where criminals pose as employers on Indeed, then pressure applicants to install a fake “interview” Android app. The app impersonates Indeed’s login, requests powerful permissions, and acts as a Trojan dropper that installs spyware on the victim’s phone.

How the Attack Worked

The scam begins with fake job listings on Indeed, where criminals pose as employers or recruiters to start conversations with applicants. Once trust is established, victims are directed to install an "interview" Android app, often distributed as a sideloaded APK rather than through an official app store. The pretext varies: identity verification, an application update, or access to a recruitment portal.

Once installed, the app impersonates Indeed's login page and prompts the victim to enter an email address. After that, it creates a VPN connection and functions as a Trojan dropper, delivering spyware onto the device. The malware also seeks Android's Accessibility permission, which can grant extensive control over the phone and even interfere with the victim's ability to uninstall the app.

Why It Succeeded

This campaign works because it borrows credibility from a platform job seekers already trust. Conversations start on Indeed, a familiar and legitimate job site, which lowers suspicion before the malicious request ever appears. Combining that trust with the natural urgency of a job opportunity or interview process pushes applicants toward installing an app without pausing to verify it. Because the login screen inside the app mimics Indeed's own branding, victims may not realize they are entering credentials into a hostile application rather than the real platform.

What to Watch For

  • Being asked to install an APK or sideload an app instead of using an official app store
  • App names suggesting an unofficial Indeed product, such as an "Indeed Interview" app
  • Pressure framed around urgency to proceed with hiring or an interview
  • A login screen appearing inside an unfamiliar app rather than Indeed's official apps
  • Unexpected requests for Accessibility permission or a VPN connection

Building Resistance

Job seekers and mobile users should treat any request to install an interview app, especially via APK, as a stop-and-verify moment, even when the conversation started on a trusted platform. Rather than following a recruiter's link, open Indeed or the employer's official website directly to confirm the listing and company. Mobile users should be trained to question apps that request Accessibility permissions or unexpected VPN access, since these are uncommon and high-risk requests for a legitimate interview tool. If a suspicious app was already installed, the device should be treated as potentially compromised: change passwords from a separate trusted device and review account security and MFA settings. Building these habits into routine job-search behavior reduces the chance that platform trust can be turned into a malware delivery path.

Key findings

  • Attackers posed as employers/recruiters on Indeed and used fake job listings to start conversations with applicants.
  • Victims were directed to install a fake Android “interview” app (often via an APK), framed as identity verification, an update, or access to a recruitment portal.
  • The fake app impersonated an Indeed login page, created a VPN connection after collecting an email address, and acted as a Trojan dropper that delivered spyware.
  • The malware sought Android Accessibility permission, which could allow extensive control and even interfere with uninstalling the app.

Who’s being targeted

  • Commonly targeted roles: All employees (mobile users), HR/Recruiting, Talent acquisition teams, Anyone job hunting or using job platforms.
  • Affected industries: Cross-industry (job seekers / individual consumers).
  • Attack channels: website.
  • Impersonated: Employer/recruiter communicating via Indeed, Indeed (fake ‘Indeed’ login inside the app).

Red flags to watch for

  • Asked to install an APK / sideloaded app instead of using Google Play
  • App name suggests an unofficial Indeed product (e.g., “Indeed Interview”)
  • Request is framed as urgent to proceed with hiring
  • Login occurs inside an unfamiliar app rather than the official Indeed apps
  • Unexpected VPN connection request
  • Accessibility permission request from an interview app
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake Indeed interview app scam work?

Scammers pose as employers on Indeed and, after engaging applicants, direct them to install an interview app framed as identity verification, an update, or portal access. The app impersonates Indeed's login page, sets up a VPN connection, and acts as a Trojan dropper that installs spyware.

What permissions should raise red flags on a job related app?

Requests for Android Accessibility permission and unexpected VPN connections are major warning signs, since Accessibility access can allow extensive control over a device and even interfere with uninstalling the app.

What should someone do if they already installed the fake app?

Treat the phone as potentially compromised, use a separate trusted device to change passwords, and review accounts and MFA settings.

How can job seekers verify a recruiter is legitimate?

Verify the request independently by opening Indeed or the employer's official website directly rather than following a link sent by the recruiter.

Read the video transcript

You apply on Indeed, a “recruiter” messages: “Please install an interview app to complete your interview.” Sounds legit, right? Here’s the trick: scammers post fake jobs on Indeed, then push an Android APK called something like “Indeed Interview.” It opens a fake Indeed login, then silently sets up a VPN and drops spyware. Aha moment: Indeed says there are only two real apps, Indeed Job Search and Indeed Flex. If an “Indeed Interview” app wants VPN or Accessibility access, it’s not hiring you, it’s hijacking your phone. Your move: if any recruiter tells you to install an interview APK, stop and verify by opening Indeed or the employer’s official site yourself, never from their link.

Similar attacks

Fake Indeed “Interview App” Drops Android Spyware

Fake Indeed “Interview App” Drops Android Spyware

Scammers posted fake jobs on Indeed and then instructed applicants to install a fake Android “interview” app via an APK link. The app impersonates an Indeed login screen and acts as a malware dropper, ultimately installing spyware and attempting to take control of the phone using high-risk…

August 26, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake Firefox Wallet Add-ons Steal Seed Phrases

Fake Firefox Wallet Add-ons Steal Seed Phrases

Researchers found a campaign of malicious Firefox add-ons that look like legitimate crypto wallets, VPNs, or utilities but are designed to trick people into entering wallet recovery phrases or exposing credentials. The add-ons can switch from harmless decoys (like a notepad or sports scores) to a…

August 24, 2026