Malicious ZIP files disguised as RBI, MCA and Income Tax documents are being used to hijack WhatsApp accounts and target corporate finance personnel
New Delhi: The Indian Cyber Crime Coordination Centre (I4C) has warned companies and finance professionals about a growing WhatsApp malware campaign that can take over users’ accounts and potentially turn them into targets of a larger financial fraud.
The cybercriminals are reportedly sending malicious ZIP files through WhatsApp, SMS and email while disguising them as legitimate account statements or regulatory communications. Files carrying names such as “Statement of Account.zip”, “RBI.zip” and “MCA.zip” are being used as bait.
According to I4C, complaints involving the same modus operandi have been reported from Delhi, Gujarat, Maharashtra and Rajasthan.
How the scam works
The attack typically begins with a message that appears to be from a financial institution or government authority and urges the recipient to open an attached document immediately.
The ZIP archive contains malicious Windows executable (.exe) and DLL files. When a user extracts and runs the files on a Windows computer, malware is installed on the system.
The malware can then compromise the user’s active WhatsApp Web session, allowing attackers to take control of the account.
Once inside, fraudsters can send the same malicious file to the victim’s contacts and WhatsApp groups. In some cases, recipients are told to forward the document to their company’s finance or accounts team for verification, helping the malware spread further within organisations.
From malware attack to ‘Boss Scam’
I4C said the compromise can eventually lead to what is commonly known as a ‘Boss Scam’ or CEO impersonation fraud.
In this stage, criminals exploit a compromised WhatsApp account belonging to a senior executive, or use an attacker-controlled number saved under the executive’s name.
They then send urgent messages to finance or accounts employees, instructing them to make payments or transfer funds to mule bank accounts.
The combination of a familiar WhatsApp account, an apparent senior executive and an urgent financial request can make the fraud particularly convincing.
Finance professionals at higher risk
I4C has identified chartered accountants, company directors, CFOs and finance and accounts personnel as particularly vulnerable targets.
The agency said the campaign is being operated by organised cross-border networks using sophisticated malware, including DLL side-loading techniques designed to evade detection.
Technical indicators linked to the campaign have been shared with CERT-In, Microsoft Defender and cybersecurity companies to help identify and block the malicious files.
I4C takes preventive action
I4C said coordinated interventions have already helped protect more than 10,000 people from the campaign.
The agency has also sent alerts to more than 58,000 potential victims over the past 30 days through the SMS header “I4CMHA-G”.
The malware associated with the campaign is also being blocked through the Sahyog Portal, according to the agency.
How to stay safe
I4C has advised users and organisations to:
- Never open ZIP, EXE or DLL files received from unknown or unverified sources.
- Do not trust attachments simply because they appear to come from a known contact.
- Remember that regulatory authorities do not send software updates, security fixes or account statements through suspicious WhatsApp attachments.
- Verify every urgent payment or account-change request through a voice call or in-person confirmation.
- Regularly check WhatsApp’s linked devices and log out of sessions that are no longer required.
- Ensure Windows systems have updated antivirus and anti-malware protection.
- Organisations should restrict the execution of unknown executable and DLL files.
If a WhatsApp account is compromised, users should immediately log out of all linked devices, inform their contacts not to open suspicious files sent from the account and scan the affected computer with updated security software.
Cyber fraud and suspicious communications can be reported through the 1930 cybercrime helpline or the National Cyber Crime Reporting Portal.
