From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform.
Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market.
What we found
A user in the UK posted on our forums after being instructed by a supposed employer on Indeed to install an “Interview App.”
A user in Brasil submitted an anonymized report after receiving similar instructions to install an APK named MyInterview from a link shared during a job interview.
Meanwhile, Reddit users discussed a “Indeed Interview” app that allegedly completely compromised one user’s phone.
The victim who installed the MyInterview APK said their phone began closing apps by itself after installation. They also shared a screenshot showing MyInterview listed under Android’s downloaded Accessibility services.
Common lures used by the scammers include:
- “Complete your interview by installing the Indeed app.”
- “Update your Indeed application.”
- “Identity verification required.”
- “Download our recruitment portal.”
- “Salary agreement available after app installation.”
An analysis by Malwarebytes Android Malware Researcher Nazeeh Sulaiman showed that these Android apps impersonate Indeed’s login page before creating a VPN connection after an applicant enters an email address. Static analysis identified the apps as Trojan.Droppers, capable of installing additional untrusted apps.
At the time of writing, the final payload was spyware, although we initially expected a banking Trojan. Once the malware is granted the Accessibility permission, it effectively takes over the device. The interesting thing here is that it can prevent users from uninstalling the malicious app. When the user taps Uninstall in Android Settings, the malware simply forces the screen back, preventing removal.
How it works
Scammers advertise fake job openings on Indeed and lure applicants into installing a fake Android app that impersonates Indeed and present itself as an interview tool.
After confirming their application, job seekers receive instructions like these:

In this example the job seeker is instructed by a “recruitment firm” to download and install the app, connect to the VPN, create an account, and enter an invitation code. They are then told to keep the app open while waiting for confirmation.
This malicious app is not affiliated with Indeed. The company’s official Android app, Indeed Job Search, is distributed through Google Play, not through an APK supplied in a recruitment message or an unfamiliar interview website.
The interview process on Indeed does not require applicants to install a separate app, confirmed by an Indeed spokesperson:
“Interviewing through Indeed’s platform happens entirely in a browser and never requires downloading a special app. Any message asking a job seeker to download an app to participate in an interview is not legitimate. We encourage job seekers to avoid clicking links or downloading files from any message directing them to do so.”
It’s worth pointing out that the dropper is not necessarily the final payload. It’s an initial-stage app intended to install another malicious or unwanted app onto the device, often after bypassing a victim’s caution with a seemingly legitimate pretext. Even if the fake Indeed app does not visibly steal data itself, it can serve as a delivery mechanism for more dangerous malware.
A VPN connection is perfectly legitimate in many situations, but there is no obvious reason for an interview app to create one immediately after an applicant supplies an email address.
In a malicious workflow, a VPN can give an app substantial influence over the device’s network traffic. It may allow attackers to route communications through systems they control, hide what the app is doing, or support later stages of the attack. The VPN behavior alone does not prove that traffic was intercepted or modified, but combined with brand impersonation and dropper functionality, it is a serious warning sign.
The fake app’s presence in Accessibility settings is also concerning. Accessibility services can view screen content and perform actions of behalf of the user, making them attractive to malware developers. In the screenshot supplied to us, MyInterview was disabled, so there is no evidence the service was active on that device. Nevertheless, its presence as a downloaded Accessibility service is relevant to the overall risk assessment.
How to stay safe
A job interview should not require you to sideload an Android app, enable a VPN connection, or install software from an unknown source.
In this campaign, the supposed interview app is simply the lure: it impersonates Indeed, establishes a suspicious network connection, and is designed to deliver additional malware.
Before using any recruitment platform, make sure you understand its hiring process and be suspicious of requests that deviates from it or move you to another platform.
Don’t install apps just because someone tell you to, especially if you have to especially if you have to install them outside Google Play.
Verify job offers through independent channels. In some of the reported cases, the companies either did not exist or not have offices in the cities where they claimed to be hiring.
The Indeed spokesperson added:
“Job seekers are at the heart of everything we do, and their safety and trust are a top priority. We are aware of scams involving individuals instructing job seekers to download an app to complete a virtual interview. These are in no way affiliated with Indeed, and we strongly condemn bad actors who exploit the trust job seekers place in our platform and brand.
For more on how to verify a legitimate Indeed app and spot the warning signs of a fake one, visit our Help Center.”
Indicators of compromise (IOCs)
Trojan droppers:
| MD5 | Package name |
|---|---|
D6B7F7C2514AC5AC93C5EB93E80EF317 | com.rodugasewubawo.rzfwhQfswMDX |
7796C6ADC5D9EC00EA41B80648329B37 | com.pogupijabedoku.VXCBLuvjmRcZzL |
Dropped malware payload:
| MD5 | Package name |
|---|---|
8EA8F77C03AC58ACC19C25DDC6D1CD48 | com.dupahu.nTTpEllELgMgD |
Domain: startcareer[.]org