Business News

3 min read | Updated on August 07, 2026, 13:57 IST
SUMMARY
The malware compromises WhatsApp Web sessions and is then used to impersonate senior executives, tricking finance teams into making high-value transfers to fraudulent accounts.

Boss Scam: I4C said the campaign is being carried out by organised cross-border cybercrime networks and has affected multiple states.
The Indian Cyber Crime Coordination Centre (I4C) on Friday warned corporates, chartered accountants and finance professionals against a surge in "Boss Scam" frauds in which cybercriminals take over WhatsApp accounts before duping companies into making high-value fund transfers.
The Union Home Ministry's cybercrime arm said it has noticed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) involving the takeover of WhatsApp accounts through malicious files circulated as "Statement of Account.zip", "RBI.zip" or "MCA.zip".
Similar incidents have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.
According to I4C, victims receive compressed files through WhatsApp, SMS or email that appear to contain account statements or urgent compliance notices from regulators or the government.
The files contain malicious software that, when opened on a Windows computer, installs a Trojan capable of hijacking the user's active WhatsApp Web session.
The compromised WhatsApp account is then used to automatically send the same malicious files to the victim's contacts and groups, often with instructions to forward them to a company's finance manager for verification, allowing the malware to spread deeper into corporate networks.
In the final stage of the fraud, cybercriminals exploit the genuine WhatsApp account of a senior executive or impersonate a chief executive by saving an attacker-controlled number under the CEO's name on the compromised device.
Finance and accounts staff are then instructed to urgently transfer funds to mule bank accounts, I4C said.
Technical analysis by I4C's National Cybercrime Threat Analytics Unit found that the campaign is being run by organised cross-border networks using advanced malware with sophisticated evasion techniques, including DLL sideloading.
The agency said the campaign poses a particular risk to chartered accountants, company directors, chief financial officers and finance teams because the malware is designed to run on Windows computers and uses account statements and regulatory compliance documents as bait.
I4C urged companies to sensitise employees, especially finance personnel, and independently verify any request for urgent fund transfers or changes to bank account details through a direct phone call or in-person confirmation before acting.
The agency said it has alerted more than 58,000 potential victims through SMS messages sent under the header "I4CMHA-G" over the past 30 days and shared threat indicators with CERT-In, Microsoft Defender and Indian cybersecurity firms to improve detection and blocking of the malware.
I4C advised citizens not to download or open ZIP files or executable files received from unknown sources, regularly review and log out of unused WhatsApp Web sessions, and ensure Windows systems are protected with updated anti-malware software.
It also urged victims of such frauds to immediately log out of linked devices, warn their contacts against opening suspicious files and report incidents through the national cybercrime helpline 1930 or the National Cyber Crime Reporting Portal.
About The Author

Next Story