Skip to content
ANU News ANU News
ANU News ANU News
  • Home
  • Home
ANU News ANU News
ANU News ANU News
  • Home
  • Home
National

I4C warns corporates of ‘Boss Scam’; malicious WhatsApp files target finance teams

By ANU News
August 8, 2026 2 Min Read
0

New Delhi: The Indian Cyber Crime Coordination Centre (I4C) has warned companies and finance professionals about a growing ‘Boss Scam’ involving WhatsApp account takeovers through malicious files disguised as account statements and regulatory communications.

The Ministry of Home Affairs said the scam has been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan. The primary targets include Chartered Accountants, company directors, CFOs and corporate finance teams.

Fraudsters send compressed files such as “Statement of Account.zip”, “RBI.zip” or “MCA.zip” through WhatsApp, SMS or email. The files contain malicious Windows executable and DLL files. Once opened on a computer, the malware can compromise the device and hijack the victim’s active WhatsApp Web session.

The compromised account is then used to automatically circulate the malware to contacts and groups, often asking recipients to forward it to their finance manager for verification.

In the next stage, scammers impersonate senior executives or CEOs and use compromised WhatsApp accounts to instruct finance staff to make urgent fund transfers to mule bank accounts.

I4C said its technical analysis indicates that organised networks operating across national borders are behind the campaign and are using sophisticated malware and DLL sideloading techniques.

To counter the threat, I4C has shared technical indicators with CERT-In, Microsoft Defender and Indian cybersecurity companies. More than 10,000 Indians have been protected through coordinated interventions and malware blocking via the Sahyog Portal.

I4C has also alerted more than 58,000 potential victims in the last 30 days through the SMS header ‘I4CMHA-G’.

Companies have been advised to independently verify every urgent fund-transfer or account-change request through a direct phone call or in-person confirmation.

Users should avoid opening unknown ZIP or executable files, regularly check WhatsApp > Settings > Linked Devices, and immediately log out suspicious sessions. Compromised systems should be scanned with updated security software.

Cyber frauds can be reported through 1930 or the National Cyber Crime Reporting Portal.

Author

ANU News

Follow Me
Other Articles
Previous

ಅರುಣಾಚಲದ 27 ಸ್ಥಳಗಳಿಗೆ ಪ್ರಮಾಣಿತ ಹೆಸರು; ಅಧಿಕೃತ ನಕ್ಷೆಗಳಲ್ಲಿ ಗುರುತಿಸಿದ ಕೇಂದ್ರ

Next

‘ಬಾಸ್ ಸ್ಕ್ಯಾಮ್’ಗೆ I4C ಎಚ್ಚರಿಕೆ; ವಾಟ್ಸಾಪ್ ಮೂಲಕ ಹಣಕಾಸು ತಂಡಗಳೇ ವಂಚಕರ ಟಾರ್ಗೆಟ್

No Comment! Be the first one.

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    Recent Posts

    • Power play in Karnataka Council: BJP-JDS allege pressure on Horatti, petition Governor
    • ಸಭಾಪತಿ ರಾಜೀನಾಮೆ ವಿವಾದ; ರಾಜ್ಯಪಾಲರಿಗೆ ಬಿಜೆಪಿ-ಜೆಡಿಎಸ್ ನಿಯೋಗ ದೂರು
    • ಆ.13ರಿಂದ ವಿಧಾನಸಭೆ ಅಧಿವೇಶನ: ಹಂಗಾಮಿ ಸಭಾಧ್ಯಕ್ಷರಾಗಿ ಟಿ.ಬಿ.ಜಯಚಂದ್ರ
    • ಚಂಡಿಪುರ ವೈರಸ್ ಆತಂಕ; 217 ಶಂಕಿತ ಪ್ರಕರಣ, 23 ಸಾವು
    • NICE row: Kumaraswamy accuses Karnataka govt of ignoring farmers’ interests
    Copyright 2026 — ANU News. All rights reserved. Blogsy WordPress Theme