tl;dr: student circumvented Jamf Pro to install App Store alternative... how?
In the high-school I'm at, we have restricted the App Store for some students and predictably they seem to have found a way around it and are installing apps like Minecraft and so forth. Fairly harmless in general, but persistently we've noticed the presence of TutuApp. In the brief reading I've done, TutuApp is apparently an App Store alternative. I'm still trying to figure out how it was installed.
We're concerned because iOS 11 apparently breaks many of TutuApp's features and while recent updates to TutuApp supposedly fixes this, it also installs a Nesstool profile. According to the forums, nobody is really sure what this is or where it came from or why it installs a VPN profile on their machine.
We first observed this when a student came into the office citing Wifi issues. No VPN should be present but there was a VPN toggle in his Settings. It was automatically toggling on and the off again rapidly, as if the software were fighting with itself. We then observed, in addition to our school profile in General, two additional profiles. One with TutuApp and the associated apps listed (Minecraft, etc) and a second profile with Nesstool. The student of course claims he doesn't know where it came from. Removal of the 2nd profile did stop the VPN and the toggle went away.
I suspect our profile was actively trying to prevent a VPN from running while something else was actively trying to enable it. My main worry is the forums have expressed concern or have evidence of this app copying payment information and other personal data and sending it… somewhere.
I am still new to Jamf as a whole, but I'm trying to learn as quickly as I can. My boss has asked me to hunt down solutions for an issue we've been having. Has anyone had experience dealing either with this exact app or with similar issues?