Scammers are turning Indeed’s trusted name into a malware delivery vehicle, and the bait is something job seekers desperately want: an interview.
Security researchers have uncovered a campaign in which fake recruiters direct Indeed applicants to Android applications that supposedly help them complete an interview. Instead, Malwarebytes found that the applications acted as Trojan droppers, delivering spyware on compromised phones.
The campaign is notable because the attackers do not need to compromise Indeed’s official app or infrastructure for the scheme to work. They chain the platform’s credibility and the urgency of a potential job, then steer the victim toward an APK and other actions that Indeed itself says are not part of its interview process.
How scammers pulled a stunt on Indeed’s trusted experience
Per a Malwarebytes report, several users reported being directed to fake Android interview apps that impersonated Indeed, prompting researchers to investigate.
What Malwarebytes found was more serious than a simple fake app. The Android applications impersonate Indeed’s login page, create a VPN connection after the victim enters an email address, and act as Trojan droppers that install additional malware. In this case, the final payload was spyware.
The attack starts with fake job listings and scammers posing as employers on Indeed. After engaging with a supposed employer, applicants are directed to install an “interview” app, often under the guise of identity verification, an application update, or access to a recruitment portal.
The threat comes when the malware obtains Android’s Accessibility permission, allowing it to interfere with the phone and even prevent victims from uninstalling it through Android Settings.
Importantly, the tactic also appears to predate Malwarebytes’ report.
Reddit users had reported suspicious “Indeed Interview” apps months earlier, including one report from February 2026. Another user later claimed that installing a similar app had compromised their phone and interfered with account access and two-factor authentication.
Why job seekers may be tempted to play along
A job seeker who has already applied on the legitimate Indeed app and received a positive response has a strong reason to believe the next instruction is part of the employer’s process.
That matters because hiring workflows can differ from one company to another, so a request to use a particular interview tool or complete an additional step may not immediately look suspicious.
For some victims, the need to comply to show eagerness may override the space for caution, further making this kind of scam particularly effective.
Indeed, however, leaves little room for ambiguity about its own apps. The company’s Help Center says there are only two official Indeed apps, Indeed Job Search and Indeed Flex.
Worried about a fake Indeed interview app? Here’s what to do
Job applicants should not have to treat every recruiter message as suspicious. But a few requests should immediately trigger a closer look, especially when they involve installing software on your phone or granting unusually powerful permissions.
Indeed says its official mobile apps are Indeed Job Search and Indeed Flex. If someone claiming to be a recruiter asks you to download an “Indeed Interview” app, install an APK file, or get software from somewhere other than an official app store, do not install it.
Instead, verify the request independently. Open Indeed or the employer’s official website yourself rather than following the recruiter’s link. Check whether the job listing still exists, confirm that the recruiter appears to be associated with the company, and contact the employer using contact information you find independently if something feels unusual.
Android users should also be particularly cautious when an unfamiliar app requests Accessibility permissions. Those permissions are legitimate Android features, but malware can abuse them to gain extensive control over a phone. Recent threats, such as the Manic Android malware, have used Accessibility permissions to capture sensitive information and interact with infected devices.
Unexpected VPN permission requests should raise similar concerns. ToxicPanda 2.0 is another example of Android malware that combines VPN and Accessibility permissions with sideloaded software to gain deeper control over a device.
What if you already installed the app?
If you downloaded a suspicious interview app or APK, treat the phone as potentially compromised rather than assuming that deleting the installation file solved the problem.
If you entered passwords or other sensitive information while the suspicious app was installed, use a separate trusted device to change those credentials. Review important accounts for unfamiliar login attempts and check that recovery information and two-factor authentication settings have not been altered.
You should also review the Android device for unfamiliar apps and unexpected Accessibility or VPN permissions. If the suspicious app cannot be removed normally or the phone continues to behave unexpectedly, seek help from your device manufacturer, mobile carrier, or a trusted security professional.
In serious cases, a factory reset may be considered as a last resort. Because a reset erases data stored on the device, users should review their backup and account-recovery options before taking that step.
If the interaction began through Indeed, report the suspicious job listing or recruiter to the platform as well.
The larger lesson is that a legitimate-looking conversation does not automatically make every request within it legitimate. Employers may use different interviewing platforms, but an unexpected request to sideload an app, grant powerful device permissions, or enter credentials in an unfamiliar location deserves independent verification before you proceed.
For job seekers, that extra check matters because scammers are counting on urgency and excitement doing some of the work for them. An interview invitation may feel like the moment to move quickly, but an unusual software request is exactly the moment to slow down and verify.
Also read: Job seekers concerned about their security should also understand how job-search platforms may put personal data at risk, including what information these services collect, share, and sell.





