New Delhi: The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs (MHA), has issued a nationwide alert over a sophisticated cyber fraud campaign that is hijacking WhatsApp accounts of professionals, businesspersons and finance executives through malware disguised as account statements and regulatory documents.
The warning comes after a sharp surge in complaints received on the National Cyber Crime Reporting Portal (NCRP), with similar incidents reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan.
According to I4C, cybercriminals are sending compressed (.zip) files through WhatsApp, SMS and email using deceptive names such as “Statement of Account.zip,” “RBI.zip” and “MCA.zip.” Victims are tricked into believing the files contain financial statements or urgent compliance notices purportedly issued by regulators like the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA).
Once the attachment is downloaded, extracted and opened on a Windows computer, it installs a Trojan malware that compromises the system and hijacks the victim’s active WhatsApp Web session. In several cases, fraudsters have also impersonated the Income Tax Department through deceptive emails.
After gaining control of the account, the attackers automatically forward the same malicious file to the victim’s contacts and WhatsApp groups, typically asking recipients to share it with their company’s finance department or open it on a desktop computer. This enables the malware to spread rapidly across corporate networks.
The fraud often escalates into the so-called “Boss Scam” or CEO impersonation fraud, where criminals misuse the compromised WhatsApp account of a senior executive, or create a fake contact using the CEO’s name, to instruct finance and accounts personnel to transfer funds urgently into fraudulent bank accounts.
Technical analysis by the National Cybercrime Threat Analytics Unit (NCTAU) has revealed that the campaign is being operated by organised cross-border cybercrime syndicates using advanced malware capable of evading detection through sophisticated techniques such as DLL sideloading. Investigations are being carried out in coordination with law enforcement agencies and cybersecurity experts.
The advisory states that the malware specifically targets Windows-based computers, making Chartered Accountants, Company Directors, Chief Financial Officers (CFOs), finance professionals and corporate accounts teams particularly vulnerable.
I4C has urged organisations to sensitise employees about the threat and verify all urgent financial instructions received through WhatsApp or email by making a direct phone call or obtaining in-person confirmation before transferring funds.
To contain the campaign, I4C has launched several countermeasures, including proactively alerting victims and potential targets, sharing malware indicators with CERT-In, Microsoft Defender, and leading Indian cybersecurity firms such as Quick Heal, K7 Computing and Net Protector, and continuously blocking malicious files through the Sahyog Portal.
The agency said its coordinated response has already protected more than 10,000 Indians, while over 58,000 potential victims have received precautionary SMS alerts during the past month through the official “I4CMHA-G” sender ID.
Citizens have been advised not to download or open ZIP files or executable files received from unknown or unverified sources, periodically review and log out of unused WhatsApp Web sessions, keep anti-virus software updated, and immediately disconnect compromised accounts from linked devices.
The Ministry has urged anyone encountering such cyber fraud or suspicious communications to report the incident immediately by calling the National Cyber Crime Helpline 1930 or by filing a complaint on the National Cyber Crime Reporting Portal.





