I4C warns corporates of ‘Boss Scam’; malicious WhatsApp files target finance teams

New Delhi: The Indian Cyber Crime Coordination Centre (I4C) has warned companies and finance professionals about a growing ‘Boss Scam’ involving WhatsApp account takeovers through malicious files disguised as account statements and regulatory communications.

The Ministry of Home Affairs said the scam has been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan. The primary targets include Chartered Accountants, company directors, CFOs and corporate finance teams.

Fraudsters send compressed files such as “Statement of Account.zip”, “RBI.zip” or “MCA.zip” through WhatsApp, SMS or email. The files contain malicious Windows executable and DLL files. Once opened on a computer, the malware can compromise the device and hijack the victim’s active WhatsApp Web session.

The compromised account is then used to automatically circulate the malware to contacts and groups, often asking recipients to forward it to their finance manager for verification.

In the next stage, scammers impersonate senior executives or CEOs and use compromised WhatsApp accounts to instruct finance staff to make urgent fund transfers to mule bank accounts.

I4C said its technical analysis indicates that organised networks operating across national borders are behind the campaign and are using sophisticated malware and DLL sideloading techniques.

To counter the threat, I4C has shared technical indicators with CERT-In, Microsoft Defender and Indian cybersecurity companies. More than 10,000 Indians have been protected through coordinated interventions and malware blocking via the Sahyog Portal.

I4C has also alerted more than 58,000 potential victims in the last 30 days through the SMS header ‘I4CMHA-G’.

Companies have been advised to independently verify every urgent fund-transfer or account-change request through a direct phone call or in-person confirmation.

Users should avoid opening unknown ZIP or executable files, regularly check WhatsApp > Settings > Linked Devices, and immediately log out suspicious sessions. Compromised systems should be scanned with updated security software.

Cyber frauds can be reported through 1930 or the National Cyber Crime Reporting Portal.