I4C Warns of WhatsApp Account Takeover Scam Targeting Professionals, Businesses
New Delhi, Aug. 7 (TNT): The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs on Friday warned of a sharp rise in cyber frauds involving the takeover of WhatsApp accounts of professionals and businesspersons through malicious files disguised as account statements and regulatory communications.
The I4C said complaints received on the National Cyber Crime Reporting Portal (NCRP) indicate that the scam has been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.
It had earlier issued an advisory on the emerging threat on June 22, 2026.
According to I4C, victims receive compressed (.zip) files through WhatsApp, SMS or email with names such as “Statement of Account.zip”, “RBI.zip” or “MCA.zip”. The messages are designed to appear as routine account statements or urgent notices from regulators such as the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA). In some cases, emails impersonating the Income Tax Department are also used.
The archive contains a malicious executable (.exe) file and a Dynamic Link Library (.dll) file. When opened on a Windows computer, the malware installs a Trojan that compromises the device and hijacks the victim’s active WhatsApp Web session.
The compromised account is then used to automatically forward the malicious file to the victim’s contacts and WhatsApp groups, often with instructions to send it to a company’s finance manager for verification, thereby spreading the infection.
The I4C said the fraudsters subsequently carry out the so-called “Boss Scam” or CEO impersonation fraud, using the compromised WhatsApp account of a senior executive—or an attacker-controlled number saved under the executive’s name—to instruct finance personnel to transfer funds to fraudulent bank accounts.
Technical analysis by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C indicates that the campaign is being operated by organised cross-border networks using advanced malware employing DLL sideloading techniques to evade detection.
The agency said the campaign poses a particular threat to chartered accountants, company directors, chief financial officers (CFOs), and finance and accounts personnel, as the malicious files are disguised as financial documents and regulatory notices.
Corporate organisations have been advised to sensitise employees, particularly finance teams, and independently verify any urgent fund transfer or account change request received through WhatsApp or email by contacting the sender directly.
The I4C said it has initiated several countermeasures, including proactively alerting victims, sharing malware indicators with CERT-In, Microsoft Defender and leading Indian antivirus companies, and blocking malicious files through the Sahyog Portal.
According to the agency, more than 10,000 citizens have been protected through coordinated interventions, while over 58,000 potential victims have been alerted during the past 30 days through SMS sent under the header “I4CMHA-G”.
The I4C advised citizens not to download or open ZIP files or executable files received from unknown or unverified sources, regularly review linked WhatsApp Web sessions, keep anti-malware software updated, and immediately report cyber frauds through the National Cyber Crime Helpline 1930 or the National Cyber Crime Reporting Portal.
TNT KS
