The Indian Cyber Crime Coordination Centre (I4C) has cautioned corporates and finance professionals against the 'Boss Scam', a WhatsApp account-takeover campaign in which malicious malware disguised as 'statement of account', 'MCA' and 'RBI' files compromises Windows devices, according to the Ministry of Home Affairs (MHA). The MHA said I4C decided to alert the public after observing a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) from different states and union territories, with recent incidents reported from Delhi, Gujarat, Maharashtra and Rajasthan.
'Boss Scam' mechanics: .zip lures and DLL sideloading
Technical analysis carried out by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C — the cyberarm of the Ministry of Home Affairs — indicates the campaign is operated by organised networks acting across national borders and employs advanced malware with sophisticated propagation and detection-evasion capabilities through the DLL Sideloading method, MHA said in a statement on Friday.
The campaign is operated by organised networks acting across national borders and employs advanced malware with sophisticated propagation and detection-evasion capabilities through the DLL Sideloading method, according to MHA.
In the reported incidents, victims receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as "Statement of Account.zip" (often prefixed with a date, e.g. "0714 Statement of Account.zip") or "RBI.zip", "MCA.zip". The accompanying message is crafted to appear either as a routine account statement or as an urgent notice from a regulator such as the Reserve Bank of India (RBI) and the Ministry of Corporate Affairs, demanding compliance within a very short timeframe. The archive contains a malicious Windows executable (.exe) accompanied by a Dynamic Link Library (.dll) file; when extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device, the MHA statement read.
| Attack element | Detail reported by MHA |
|---|---|
| Lure file names | "Statement of Account.zip" (e.g., "0714 Statement of Account.zip"), "RBI.zip", "MCA.zip" |
| Delivery channels | WhatsApp, SMS, e-mail |
| Payload | Malicious Windows executable (.exe) plus Dynamic Link Library (.dll) |
| Impact | Trojan installation and WhatsApp account takeover |
Who is at risk: finance teams, CFOs, chartered accountants
Since the malware activates only on Windows computers and the lure documents reference account statements and regulatory compliance, the campaign poses a particular risk to Chartered Accountants, Company Directors, Chief Financial Officers (CFOs) and finance and accounts personnel of companies, MHA said. The Ministry has advised all corporate entities to immediately sensitise their employees, especially finance teams, and to independently verify — through a direct voice call or in-person confirmation — any urgent fund-transfer instruction or account-change request received over WhatsApp or e-mail before acting on it.
I4C standard operating procedure: mitigations for enterprises
I4C has issued a standard operating procedure (SOP) for citizens and organisations. The SOP advises users not to download, extract or open .zip files or executables received from unknown or unverified sources. The I4C clarified that regulators such as the RBI never distribute software updates, security fixes or account statements through WhatsApp attachments.
Additional SOP measures include:
- Regularly review linked devices in the WhatsApp application (Settings > Linked Devices) and log out of WhatsApp Web sessions that are no longer in active use.
- System administrators should enforce software restriction policies to block the execution of unknown .exe and .dll files from user profile directories.
- Ensure that all Windows endpoints run up-to-date anti-malware solutions.
If an account is compromised, I4C advises users to immediately log out of all linked devices, alert contacts not to open any file received from the account, and get the computer scanned with an updated anti-virus.
Reporting and prior advisory
Cyber fraud and suspicious communications should be reported immediately on the National Cyber Crime Helpline number 1930 or on the National Cyber Crime Reporting Portal at www.cybercrime.gov.in, the Ministry advocated. MHA said it had earlier issued an advisory on June 22, 2026, titled "Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High Value Financial Fraud", to caution people against falling victim to such online frauds.
For enterprise technology leaders, the practical takeaway from the MHA advisory is procedural: fund-transfer instructions received over WhatsApp or e-mail must be verified out-of-band, and endpoint protections should treat user-profile directories as untrusted execution zones. The I4C's stated expectation is that finance teams in corporate entities follow the SOP before opening any file that resembles a regulator's communication.