New Delhi, August 7: The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, has issued a fresh warning to businesses and finance professionals after detecting a significant increase in a sophisticated cyber fraud campaign popularly known as the “Boss Scam.” The scam primarily targets corporate executives, chartered accountants, chief financial officers (CFOs), company directors and finance departments by compromising their WhatsApp accounts and exploiting them for financial fraud.
According to I4C, cybercriminals are circulating malicious compressed files through WhatsApp, SMS and email by disguising them as bank account statements or official communications from government bodies such as the Reserve Bank of India (RBI), Ministry of Corporate Affairs (MCA) and, in some cases, the Income Tax Department. The files often carry names suggesting urgent financial or regulatory action, encouraging recipients to open them immediately.
Once downloaded and extracted on a Windows computer, the files install malware capable of taking control of the user’s active WhatsApp Web session. After gaining access, attackers use the compromised account to automatically forward the same malicious file to the victim’s contacts and groups, increasing the spread of the malware within business networks.
Investigators say the fraud becomes more dangerous when cybercriminals impersonate senior company officials. Using the genuine WhatsApp account of an executive—or by manipulating contact names—they send urgent payment instructions to finance staff, directing them to transfer money to fraudulent bank accounts. This social engineering tactic has led to several high-value financial fraud attempts.
The I4C Boss Scam advisory highlights how cybercriminals are exploiting WhatsApp accounts of finance professionals and company executives to carry out high-value financial fraud.
The National Cybercrime Threat Analytics Unit (NCTAU) has found that the malware uses advanced techniques to avoid detection and appears to be operated by organised cybercrime groups working across international borders. Authorities are continuing investigations in coordination with law enforcement agencies and technical experts.
I4C noted that professionals handling financial records are particularly vulnerable because the malicious files are designed to resemble routine accounting documents or regulatory notices. Organisations have been urged to strengthen internal verification procedures and ensure that any request involving fund transfers or changes to banking details is confirmed through direct voice calls or face-to-face communication before action is taken.
To curb the campaign, I4C has launched multiple preventive measures. The agency has been proactively informing affected and potentially affected individuals through SMS alerts sent under the header “I4CMHA-G.” More than 58,000 people have received such alerts over the past month. Technical indicators associated with the malware have also been shared with CERT-In, Microsoft and major Indian cybersecurity companies to improve detection and blocking of the threat.
Officials said coordinated efforts through the Sahyog Portal have already helped prevent the malware from reaching more than 10,000 users by blocking its command-and-control infrastructure.
The cybercrime agency has advised individuals and organisations to avoid opening ZIP files or executable programs received from unknown or unverified sources. It also reminded users that regulators such as the RBI do not send software updates or official account statements through WhatsApp attachments.
Users have been encouraged to regularly review linked devices within WhatsApp, remove inactive sessions, maintain updated antivirus software and restrict the execution of unknown programs on office computers. In case of a suspected compromise, immediate logout from all linked devices, antivirus scanning and notifying contacts are recommended.
Citizens who encounter such fraud attempts have been asked to report them immediately through the National Cyber Crime Helpline (1930) or the National Cyber Crime Reporting Portal.
No Comments: