The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs (MHA), has issued a stern warning regarding a significant increase in cyber fraud incidents. These frauds involve the malicious takeover of WhatsApp accounts through compromised files disguised as official financial or regulatory documents.
Information was available with The Chenab Times indicating that the surge in complaints, reported through the National Cyber Crime Reporting Portal (NCRP), has been particularly sharp in recent days. The modus operandi of these attacks has been consistent across Delhi, Gujarat, Maharashtra, and Rajasthan. The I4C had previously alerted the public to this developing threat via an advisory on June 22.
The fraudulent scheme commences when unsuspecting individuals receive a compressed file, typically in .zip format, via WhatsApp, SMS, or email. These files are often named to appear legitimate, such as “Statement of Account.zip,” “RBI.zip,” or “MCA.zip.” The accompanying messages are crafted to mimic routine account statements or urgent communications from regulatory bodies like the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA), necessitating immediate attention.
In numerous reported cases, the fraudulent communications have also impersonated the Income Tax Department, further enhancing their deceptive appearance. Upon extraction and execution on a Windows operating system, the archive contains a malicious Windows executable (.exe) file, often accompanied by a Dynamic Link Library (.dll) file. The malware then installs a Trojan that infiltrates the victim’s device, compromising its security and seizing control of their active WhatsApp Web session.
Once the attackers gain unauthorized access to a WhatsApp account, they automatically disseminate the same malicious file to the victim’s contacts and WhatsApp groups. This often involves instructing recipients to forward the file to their company’s finance manager for verification and to open it on a computer, facilitating the rapid spread of the malware across corporate networks.
The I4C highlighted that this fraudulent activity frequently escalates into what is commonly recognized as the “Boss Scam” or CEO impersonation fraud. By leveraging a compromised WhatsApp account belonging to a senior executive, or by establishing a fraudulent number under an executive’s name, perpetrators issue urgent instructions to finance and accounts personnel, compelling them to transfer funds into illicit mule bank accounts.
Technical analysis conducted by the National Cybercrime Threat Analytics Unit (NCTAU) has revealed that these campaigns are orchestrated by organized, cross-border criminal networks. These groups employ sophisticated malware that utilizes DLL side-loading techniques, designed to evade detection by cybersecurity measures. Investigations into these operations are ongoing, with active coordination between law enforcement agencies and technical experts.
The advisory specifically noted the elevated risk posed by this campaign to professionals such as chartered accountants, company directors, chief financial officers (CFOs), and finance and accounts personnel. This heightened risk is due to the malware’s activation being contingent on Windows systems and its reliance on financial statements and regulatory compliance notices as deceptive bait.
The I4C has strongly urged companies to proactively sensitize their employees, particularly those within finance departments. It is crucial to independently verify any urgent fund transfer or account change requests received via WhatsApp or email through voice calls or in-person confirmation before proceeding. This verification process is vital to prevent falling victim to these scams.
To counter this evolving threat, the I4C has commenced proactive notification of victims and potential victims. These individuals are identified through rigorous analysis of complaints and technical intelligence. This enables timely action to secure compromised accounts by logging out of any linked devices, thereby disrupting the attackers’ access.
Furthermore, the agency has shared critical malware indicators and technical threat intelligence with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender, and prominent Indian cybersecurity firms, including Quick Heal, K7 Computing, and Net Protector. This collaborative effort aims to expedite the detection and blocking of malicious files across various platforms.
According to I4C, coordinated intervention efforts have successfully protected over 10,000 individuals from this campaign thus far. Malware associated with these operations is actively being blocked through the Sahyog Portal. In the preceding 30 days, the agency has also dispatched alert messages to more than 58,000 potential victims via the SMS header “I4CMHA-G,” providing timely advice for citizens to adopt immediate preventive measures.
The advisory strongly cautioned users against downloading or opening ZIP files or executable files received from unknown or unverified sources. It emphasized that regulatory bodies such as the RBI do not distribute software updates, security fixes, or account statements through WhatsApp attachments. Users are also advised to regularly review and log out of inactive WhatsApp Web sessions. Organizations are recommended to implement software restriction policies to prevent the execution of unauthorized executable and DLL files, and to ensure all Windows systems are equipped with up-to-date anti-malware solutions.
In the event of an account compromise, the I4C advises users to immediately log out of all linked WhatsApp devices and to alert their contacts about the suspicious files to prevent further spread. Affected users should also scan their computers with updated antivirus software. Citizens are encouraged to report cyber fraud incidents and suspicious communications by calling the National Cyber Crime Helpline at 1930 or by lodging a complaint through the National Cyber Crime Reporting Portal.
The Chenab Times News Desk

