[REVISION HISTORY]
Malicious interview apps targeting job seekers
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-09-16 23:21 UTC → 2026-09-17 15:23 UTC ·
added
removed
Cybercriminals are targeting job seekers through fraudulent Android applications designed to install spyware. These malicious APK files, such as “MyInterview”, are presented to applicants under the guise of completing interviews, verifying identities, or accessing salary agreements on platforms like Indeed. Technical analysis indicates these apps function as Trojan droppers. They impersonate legitimate login pages to steal credentials and establish VPN connections. Once users grant the apps Accessibility permissions, the malware can take control of the mobile device and prevent uninstallation by forcing the screen back during the process. Reports of these activities have emerged from users in the UK and Brazil. More recent observations note that these technical schemes are occurring alongside broader social engineering trends, where criminal networks use structured training to impersonate authorities such as police or doctors to manipulate victims. In September 2026, the use of the “MyInterview” Android malware was identified as part of a wider wave of cyberattacks and phishing scams targeting consumers in Germany and Austria. This broader criminal activity includes impersonating financial institutions like Sparkasse and Volksbanken Raiffeisenbanken, as well as service providers such as Asfinag and Deutsche Telekom, to steal sensitive personal and financial data.
Versions
- 2026-09-17 15:23 UTC Malicious interview apps targeting job seekers
- 2026-09-16 23:21 UTC Malicious interview apps targeting job seekers
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.