Scammers Distribute Fake Indeed Interview Android Apps to Install Spyware
What Happened — Scammers posting bogus job listings on Indeed have been sending applicants a malicious Android APK masquerading as an “Interview App.” The app mimics Indeed’s login page, establishes a VPN, and then installs a Trojan‑Droppers payload that gains Accessibility permission, hijacks the device, and prevents uninstallation.
Why It Matters for Compliance & Audit Readiness
- The scenario exemplifies a classic SOC 2 Access Controls failure: users bypass approved software channels and grant excessive privileges, undermining the CC6.1 – Logical Access and CC6.2 – Least Privilege criteria.
- Demonstrates the need for documented Security Awareness Training and policy enforcement to provide audit‑ready evidence that employees (or contractors) are regularly educated on phishing/social‑engineering threats.
Who Is Affected — Job seekers worldwide, recruiting platforms, and any organization that allows employees to use personal mobile devices for work‑related communications (tech‑SaaS, professional services, HR tech).
Recommended Actions
- Update mobile device policies to require installation only from official app stores and to block unknown APKs.
- Deploy or refresh Security Awareness Training that includes specific modules on fake job‑application scams and malicious app detection.
- Enable Mobile Device Management (MDM) controls to monitor app installations, enforce least‑privilege permissions, and generate audit logs for SOC 2 evidence.
Source: Malwarebytes Labs
Technical Notes
- Attack vector: Social engineering → malicious APK (Trojan.Droppers) → VPN creation → Accessibility service abuse.
- Payload: Spyware capable of exfiltrating contacts, messages, and location data; blocks uninstallation.
- Indicators: APK named MyInterview, requests Accessibility permission, registers as a VPN service.
Source: Malwarebytes Labs