Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fake Android interview application impersonating Indeed. It creates a VPN connection after credential entry, can install additional untrusted applications, and is associated with delivery of a spyware payload. It may abuse Accessibility permissions to control the device and prevent uninstall attempts.
A malicious Android app distributed through fake Indeed job-interview lures. It impersonates Indeed, requests or exposes Accessibility-service functionality, establishes a suspicious VPN connection, delivers an additional spyware payload, and can prevent its own removal by forcing users away from Android's uninstall screen.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.