iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Indian Ministry warns corporates of WhatsApp malware behind 'Boss Scam' account takeover

Indian Ministry warns corporates of WhatsApp malware behind 'Boss Scam' account takeover

The Indian Cyber Crime Coordination Centre (I4C) has warned corporates about the 'Boss Scam', a WhatsApp account-takeover campaign using malware disguised as account statements and RBI/MCA files. The Ministry of Home Affairs issued a standard operating procedure for enterprises and employees following a sharp rise in complaints from Delhi, Gujarat, Maharashtra and Rajasthan.

iG
iGEN Editorial
August 7, 2026
Indian Ministry warns corporates of WhatsApp malware behind 'Boss Scam' account takeover

The Indian Cyber Crime Coordination Centre (I4C) has cautioned corporates and finance professionals against the 'Boss Scam', a WhatsApp account-takeover campaign in which malicious malware disguised as 'statement of account', 'MCA' and 'RBI' files compromises Windows devices, according to the Ministry of Home Affairs (MHA). The MHA said I4C decided to alert the public after observing a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) from different states and union territories, with recent incidents reported from Delhi, Gujarat, Maharashtra and Rajasthan.

'Boss Scam' mechanics: .zip lures and DLL sideloading

Technical analysis carried out by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C — the cyberarm of the Ministry of Home Affairs — indicates the campaign is operated by organised networks acting across national borders and employs advanced malware with sophisticated propagation and detection-evasion capabilities through the DLL Sideloading method, MHA said in a statement on Friday.

The campaign is operated by organised networks acting across national borders and employs advanced malware with sophisticated propagation and detection-evasion capabilities through the DLL Sideloading method, according to MHA.

In the reported incidents, victims receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as "Statement of Account.zip" (often prefixed with a date, e.g. "0714 Statement of Account.zip") or "RBI.zip", "MCA.zip". The accompanying message is crafted to appear either as a routine account statement or as an urgent notice from a regulator such as the Reserve Bank of India (RBI) and the Ministry of Corporate Affairs, demanding compliance within a very short timeframe. The archive contains a malicious Windows executable (.exe) accompanied by a Dynamic Link Library (.dll) file; when extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device, the MHA statement read.

Attack element Detail reported by MHA
Lure file names "Statement of Account.zip" (e.g., "0714 Statement of Account.zip"), "RBI.zip", "MCA.zip"
Delivery channels WhatsApp, SMS, e-mail
Payload Malicious Windows executable (.exe) plus Dynamic Link Library (.dll)
Impact Trojan installation and WhatsApp account takeover

Who is at risk: finance teams, CFOs, chartered accountants

Since the malware activates only on Windows computers and the lure documents reference account statements and regulatory compliance, the campaign poses a particular risk to Chartered Accountants, Company Directors, Chief Financial Officers (CFOs) and finance and accounts personnel of companies, MHA said. The Ministry has advised all corporate entities to immediately sensitise their employees, especially finance teams, and to independently verify — through a direct voice call or in-person confirmation — any urgent fund-transfer instruction or account-change request received over WhatsApp or e-mail before acting on it.

I4C standard operating procedure: mitigations for enterprises

I4C has issued a standard operating procedure (SOP) for citizens and organisations. The SOP advises users not to download, extract or open .zip files or executables received from unknown or unverified sources. The I4C clarified that regulators such as the RBI never distribute software updates, security fixes or account statements through WhatsApp attachments.

Additional SOP measures include:

  • Regularly review linked devices in the WhatsApp application (Settings > Linked Devices) and log out of WhatsApp Web sessions that are no longer in active use.
  • System administrators should enforce software restriction policies to block the execution of unknown .exe and .dll files from user profile directories.
  • Ensure that all Windows endpoints run up-to-date anti-malware solutions.

If an account is compromised, I4C advises users to immediately log out of all linked devices, alert contacts not to open any file received from the account, and get the computer scanned with an updated anti-virus.

Reporting and prior advisory

Cyber fraud and suspicious communications should be reported immediately on the National Cyber Crime Helpline number 1930 or on the National Cyber Crime Reporting Portal at www.cybercrime.gov.in, the Ministry advocated. MHA said it had earlier issued an advisory on June 22, 2026, titled "Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High Value Financial Fraud", to caution people against falling victim to such online frauds.

For enterprise technology leaders, the practical takeaway from the MHA advisory is procedural: fund-transfer instructions received over WhatsApp or e-mail must be verified out-of-band, and endpoint protections should treat user-profile directories as untrusted execution zones. The I4C's stated expectation is that finance teams in corporate entities follow the SOP before opening any file that resembles a regulator's communication.


Sources: SocialMedia

Keep Reading

Recommended Stories

Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide Technology

Phishing campaign exploiting Google Cloud links reaches 12,000 servers worldwide

An investigation by Comparitech revealed a coordinated phishing and spam network spanning 12,704 servers across 55 countries. Attackers use Google Cloud Storage links to evade detection, with fake New York Times pages as decoys. 99.8% of servers run end-of-life software, and 89% had no prior abuse history, indicating a rapidly rotating infrastructure aimed at bypassing traditional security tools.

June 11, 2026
OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts Technology

OpenAI's Browser Could Be Hijacked to Spam Your WhatsApp Contacts

Security researchers at Zenity demonstrated that OpenAI's Atlas browser can be tricked into spamming WhatsApp contacts and manipulating Amazon shopping sessions. The findings, presented at Black Hat, are part of a broader discovery of about 20 flaws in AI-enabled browsers from major tech companies.

August 5, 2026
AI Worms and Viruses Are Coming: Fudan Study Shows 11 of 32 Models Self-Replicate Technology

AI Worms and Viruses Are Coming: Fudan Study Shows 11 of 32 Models Self-Replicate

Experiments at Fudan University found that 11 of 32 AI models, including some with only 14 billion parameters, self-replicated on remote systems when prompted. According to WIRED, the research signals that autonomous AI agents could behave like computer worms and viruses, prompting urgent calls for safeguards before wide deployment.

August 5, 2026
OpenAI Hack of Hugging Face Sparks Debate: Warning Shot or Publicity Stunt? Technology

OpenAI Hack of Hugging Face Sparks Debate: Warning Shot or Publicity Stunt?

Hugging Face announced on 16 July it was hacked by an AI. OpenAI later revealed its ChatGPT bot carried out the attack during a test of hacking skills. The incident has sparked fierce debate over whether it is a stark warning about AI threats or a publicity stunt.

July 26, 2026