Selected menu has been deleted. Please select the another existing nav menu.
=

Sophisticated WhatsApp malware targeting finance pros, businesses, warns cyber crime centre

Lorem ipsum dolor sit amet consectetur. Facilisis eu sit commodo sit. Phasellus elit sit sit dolor risus faucibus vel aliquam. Fames mattis.

HTML tutorial

The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs (MHA), on Friday issued a fresh warning over a surge in cyber fraud cases involving the takeover of WhatsApp accounts through malicious files disguised as account statements and regulatory communications.According to the I4C, complaints received on the National Cyber Crime Reporting Portal (NCRP) have increased sharply in recent days, with incidents following an identical modus operandi reported from Delhi, Gujarat, Maharashtra and Rajasthan. The agency said it had already alerted the public to the emerging threat through an advisory issued on June 22.The fraud begins when victims receive a compressed (.zip) file via WhatsApp, SMS or email with names such as “Statement of Account.zip”, “RBI.zip” or “MCA.zip”. The accompanying message is designed to appear as either a routine account statement or an urgent communication from regulatory authorities such as the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA), demanding immediate action. In several instances, emails have also impersonated the Income Tax Department.The archive contains a malicious Windows executable (.exe) along with a Dynamic Link Library (.dll) file. Once extracted and opened on a Windows desktop or laptop, the malware installs a Trojan that compromises the device and hijacks the victim’s active WhatsApp Web session.After gaining control of the account, the attackers automatically send the same malicious file to the victim’s contacts and WhatsApp groups, often asking recipients to forward it to their company’s finance manager for verification and open it on a computer. This enables the malware to spread rapidly across corporate networks.I4C said the fraud often progresses into what is commonly known as the “Boss Scam” or CEO impersonation fraud. Using the compromised WhatsApp account of a senior executive, or by saving an attacker-controlled number under the executive’s name, fraudsters send urgent instructions to finance and accounts personnel to transfer money into mule bank accounts.Technical analysis by the National Cybercrime Threat Analytics Unit (NCTAU) has found that the campaign is being operated by organised cross-border networks using advanced malware that employs DLL side-loading techniques to evade detection. Investigations are underway in coordination with law enforcement and technical agencies.The advisory noted that the campaign poses a particularly high risk to chartered accountants, company directors, chief financial officers (CFOs) and finance and accounts personnel because the malware is activated only on Windows systems and uses account statements and regulatory compliance notices as bait.I4C has urged companies to immediately sensitise employees, especially finance teams and independently verify through voice calls or in-person confirmation any urgent fund transfer or account change request received via WhatsApp or email before acting on it.To mitigate the threat, I4C said it has begun proactively notifying victims and potential victims identified through complaint analysis and technical intelligence, enabling them to secure compromised accounts by logging out of linked devices.The agency has also shared malware indicators and technical threat signals with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender and Indian cybersecurity firms including Quick Heal, K7 Computing and Net Protector to facilitate rapid detection and blocking of the malicious files.According to I4C, coordinated interventions have protected more than 10,000 people from the campaign so far, while malware associated with the operation is being blocked through the Sahyog Portal. Over the past 30 days, the agency has also sent alert messages to more than 58,000 potential victims through the SMS header “I4CMHA-G”, advising citizens to take immediate preventive measures.The advisory cautioned users against downloading or opening ZIP files or executable files received from unknown or unverified sources, stressing that regulators such as the RBI do not distribute software updates, security fixes or account statements through WhatsApp attachments. Users have also been advised to regularly review and log out of inactive WhatsApp Web sessions, while organisations should implement software restriction policies to block the execution of unknown executable and DLL files and ensure all Windows systems are protected with updated anti-malware solutions.In case of a compromise, I4C advised users to immediately log out of all linked WhatsApp devices, alert their contacts not to open any suspicious files received from their account and scan the affected computer using updated antivirus software. Citizens have also been urged to report cyber frauds and suspicious communications to the National Cyber Crime Helpline at 1930 or through the National Cyber Crime Reporting Portal.

HTML tutorial

Tags :

Search

Popular Posts


Useful Links

Selected menu has been deleted. Please select the another existing nav menu.

Recent Posts

©2025 – All Right Reserved. Designed and Developed by JATTVIBE.