I4C has warned more than 58,000 potential victims about a malware campaign using fake RBI, MCA and account-statement ZIP files to hijack WhatsApp Web sessions. Attackers then impersonate senior executives and direct finance teams to transfer money to mule accounts.

I4C Warns 58,000 Users as Malware-Laced ZIP Files Hijack WhatsApp Web Sessions

The420 Correspondent
4 Min Read

New Delhi: The Indian Cyber Crime Coordination Centre (I4C), operating under the Union Ministry of Home Affairs, has issued a nationwide warning over a sharp rise in “Boss Scam” frauds, in which cybercriminals hijack WhatsApp accounts and impersonate senior company executives to trick finance teams into transferring large sums of money to fraudulent bank accounts. According to I4C, complaints related to the scam have increased significantly on the National Cyber Crime Reporting Portal (NCRP), with cases reported from Delhi, Gujarat, Maharashtra, Rajasthan and several other states.

According to the agency, cybercriminals are distributing compressed ZIP files such as “Statement of Account.zip,” “RBI.zip,” and “MCA.zip” through WhatsApp, email and SMS. These files appear to contain legitimate bank statements, regulatory documents or compliance notices. However, once opened on a Windows computer, they install malware that hijacks the user’s active WhatsApp Web session.

India’s Largest Cybercrime Conference Nears: FutureCrime Summit 2026 Set for 6–7 August at Bharat Mandapam

Investigators said that after compromising a WhatsApp Web session, the malware automatically sends the same malicious files to the victim’s contacts and WhatsApp groups. In many cases, the messages instruct recipients to forward the files to the company’s finance manager or accounts department for verification, allowing the malware to spread further within corporate networks and infect additional systems.

I4C said that in the final stage of the operation, cybercriminals either exploit the genuine WhatsApp account of a senior executive or save an attacker-controlled mobile number under the name of a company’s Chief Executive Officer (CEO) or another senior official. Finance personnel are then instructed to urgently transfer funds to mule bank accounts under the pretext of vendor payments or emergency financial requirements. Believing the instructions to be genuine, employees complete the transactions before realising they have been defrauded.

Technical analysis by I4C’s National Cybercrime Threat Analytics Unit has found that the campaign is being operated by organised cross-border cybercrime networks. The agency said the attackers are using advanced malware equipped with sophisticated evasion techniques, including DLL sideloading, to bypass security systems. Chartered accountants, company directors, chief financial officers (CFOs), and finance and accounts teams have been identified as the primary targets of the campaign.

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said that finance professionals should never rely solely on WhatsApp messages instructing urgent fund transfers, bank account changes or confidential financial transactions. He advised organisations to verify such requests directly through a phone call, video call or in-person confirmation with the concerned executive before processing any payment. He also cautioned against opening ZIP or executable (EXE) files received without proper verification, as they may contain malicious software capable of compromising corporate systems.

I4C has urged companies to conduct regular cybersecurity awareness programmes for employees, particularly those working in finance and accounts, independently verify all urgent payment requests, and periodically review and log out of inactive WhatsApp Web sessions. The agency said it has sent warning SMS messages to more than 58,000 potential victims under the “I4CMHA-G” header over the past 30 days. It has also shared threat indicators with CERT-In, Microsoft Defender and Indian cybersecurity firms to strengthen malware detection and blocking capabilities. Victims of such attacks have been advised to immediately log out of all linked WhatsApp devices, alert their contacts about the compromise, and report the incident through the national cybercrime helpline 1930 or the National Cyber Crime Reporting Portal.

About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.

Stay Connected