A job seeker in Brazil was told to install an app called MyInterview to finish a hiring process. Shortly after the APK went on the phone, apps started closing by themselves, and MyInterview turned up in Android's list of downloaded Accessibility services. A user in the UK reported getting the same instruction from a supposed employer on Indeed.
Malwarebytes has pulled those reports together and says scammers are running fake recruitment on one of the world's largest job platforms, using the interview itself as the pretext to get malware onto Android phones. Indeed told the company that interviewing through its platform happens entirely in a browser and never requires an app download.
The interview is the lure
The pitch varies but the shape does not. Applicants who answer a fake listing are told to install the Indeed app to complete their interview, to update an existing one, to verify their identity, or to download a recruitment portal. In one case the applicant was walked through installing the app, connecting to a VPN, creating an account, entering an invitation code, then keeping the app open while waiting for confirmation.
Malwarebytes Android malware researcher Nazeeh Sulaiman found that the apps impersonate Indeed's login page and then open a VPN connection once an applicant types in an email address. Static analysis classified them as Trojan droppers, meaning their job is to install other apps rather than to steal anything themselves. In the samples analysed the payload that followed was spyware, though the team says it had initially expected a banking trojan.
Why a VPN in a hiring app is a red flag
A VPN is ordinary software in plenty of contexts. There is no obvious reason for an interview tool to build one the moment you supply an email address. Routing a phone's traffic through infrastructure the attacker controls gives them influence over what the device talks to and helps hide later stages of an attack. Malwarebytes is careful here: the VPN behaviour on its own does not prove traffic was intercepted or modified, but stacked on brand impersonation and dropper code, it is a serious warning sign.
The Accessibility angle is what turns a nuisance into a takeover. Accessibility services can read what is on screen and act on the user's behalf, which is exactly why Android malware wants them. Once the permission is granted, Malwarebytes says the malware effectively takes over the device, and it resists removal: tap Uninstall in Settings and it forces the screen back. In the one screenshot supplied to the researchers the service was switched off, so there is no evidence it was ever active on that particular phone.
Refuse the sideload, keep the phone
The defence is unglamorous and it works. No legitimate interview needs you to sideload an APK, switch on a VPN, or install software from outside Google Play. Indeed's real app, Indeed Job Search, ships through Google Play. Learn how a recruitment platform actually runs its hiring before you use it, and be suspicious of any request that departs from it or moves you somewhere else. Verify an employer through a channel you found yourself rather than one they sent you: in several of the reported cases the hiring companies either did not exist or had no office in the city where they claimed to be recruiting.
Fake recruitment keeps working because it targets people who are motivated to comply, the same pressure at work when fake job applications were used to spread the Vidar infostealer. And it lands on the same Android permission model that on-device fraud trojans already abuse.
Indicators
From the original Malwarebytes report. Trojan droppers: MD5 d6b7f7c2514ac5ac93c5eb93e80ef317 (package com.rodugasewubawo.rzfwhQfswMDX) and MD5 7796c6adc5d9ec00ea41b80648329b37 (com.pogupijabedoku.VXCBLuvjmRcZzL). Dropped payload: MD5 8ea8f77c03ac58acc19c25ddc6d1cd48 (com.dupahu.nTTpEllELgMgD). Domain: startcareer[.]org.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.