Indian cybercrime alert as WhatsApp malware turns into boss scam threat

Indian authorities warn of a rising ‘Boss Scam’ exploiting WhatsApp to spread malware and facilitate executive impersonation, with organised networks operating across borders and affecting top corporate officials.

India’s cybercrime watchdog has warned of a fast-growing fraud campaign that turns WhatsApp itself into a delivery system for malware and executive impersonation. The Indian Cyber Crime Coordination Centre, or I4C, said the so-called “Boss Scam” is spreading through compressed ZIP files masquerading as account statements, tax notices or regulatory paperwork, with incidents reported in Delhi, Gujarat, Maharashtra, Rajasthan and elsewhere.

According to the I4C, the files are being sent through WhatsApp, SMS and e-mail with names designed to look routine, such as “Statement of Account.zip”, often prefixed with dates, or files labelled “RBI.zip” and “MCA.zip”. If opened on a Windows computer, the file can install a Trojan that compromises the device and takes over an active WhatsApp Web session. The infected account then forwards the same file to contacts and groups, sometimes alongside a message urging recipients to pass it to a finance manager or open it on a computer.

The scam can escalate into CEO impersonation fraud, where attackers use the hijacked WhatsApp account of a senior executive or create a number saved under a boss’s name to pressure staff into making urgent transfers to mule accounts. The I4C said the campaign is linked to organised networks operating across borders and uses more advanced techniques, including DLL sideloading, to evade detection. It has also warned that some messages spoof the Income Tax Department.

The threat is particularly acute for accountants, company directors, chief financial officers and finance teams because the malware is designed to activate on Windows machines and the lures are built around compliance and payment duties. In a separate case reported by The Indian Express, fraudsters allegedly used this method to siphon Rs 7.8 crore from a company linked to former MP Naresh Gujral, while The Economic Times reported losses of nearly Rs 3.5 crore at two other firms after staff opened ZIP files sent as urgent documents. NDTV has also reported a case in which a WhatsApp message from a supposed boss led to a loss of more than Rs 10 crore.

The I4C says it has shared technical indicators with CERT-In, Microsoft Defender and Indian antivirus firms including Quick Heal, K7 Computing and Net Protector, helping block malicious files through the Sahyog Portal. It said more than 10,000 people have been protected through these efforts, while over 58,000 warning SMS messages have been sent in the past 30 days from the sender ID “I4CMHA-G”. The agency has advised users not to open ZIP files or executable programmes from unverified sources, to check linked devices in WhatsApp settings and to verify urgent payment instructions by voice call or in person before acting.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.