
KOLKATA — The Indian Cyber Crime Coordination Centre (I4C) highlighted a sharp rise in WhatsApp account takeovers targeting professionals and business personnel through malicious Windows executable files disguised as regulatory documents and bank statements.
The cyber scam, which has impacted multiple states including Delhi, Gujarat, Maharashtra, and Rajasthan, relies on compressed zip files sent via WhatsApp, email, or SMS.
Archives labeled as account statements or notices from regulatory bodies such as the Reserve Bank of India and the Ministry of Corporate Affairs contain malicious software.
When opened on a Windows computer, the payload installs a Trojan horse that compromises the device and hijacks active WhatsApp Web sessions.
According to the Ministry of Home Affairs agency, the compromised accounts are automatically used to propagate the malware to all contacts and group chats.
Attackers then execute the ‘Boss Scam’, using the seized accounts or impersonating senior executives to instruct finance employees to make urgent fund transfers to mule bank accounts.
Technical analysis by the National Cybercrime Threat Analytics Unit indicates the campaign is operated by organised cross-border networks using advanced malware and DLL sideloading techniques.
Because the lure documents mimic corporate financial records, the campaign poses a severe risk to chartered accountants, chief financial officers, and company directors.
In response to the threat, authorities have proactively notified victims and shared threat signals with the Indian Computer Emergency Response Team, Microsoft Defender, and leading domestic anti-virus firms to block the malicious files.
More than 10,000 individuals have been protected from the campaign, while over 58,000 potential victims have received warnings through the official SMS header I4CMHA-G over the last 30 days.
Advisory: Never download or open zip files or executables from unverified sources. Regulators do not distribute files or software updates through messaging apps. Regularly review linked devices in WhatsApp settings.
Further, system administrators should enforce strict endpoint security policies on corporate networks. Suspicious communications should be immediately reported to the National Cyber Crime Helpline, 1930, or via the national reporting portal.
This report was drafted with the assistance of AI and verified by a human editor.
Source: PIB/7.08.26
Excellent insights
cyber crime is real challenge… awareness is biggest safety