Close Menu
    What's Hot

    I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files

    October 9, 2026

    Why Colleges Worldwide Are Being Targeted by Cyber Attacks in 2026 – and How VAPT Can Help

    October 5, 2026

    CERT-In Warns of High-Severity Apple Vulnerability: iPhone, iPad and Mac Users Should Update Now

    October 3, 2026

    OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign

    September 28, 2026

    Viral “Rent A Garba Partner” Post Raises Cybersecurity Questions Amid Navratri Scam Warnings

    September 19, 2026
    Facebook X (Twitter) Instagram
    Friday, October 9
    CyberNexora News
    X (Twitter) Instagram LinkedIn
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us
    Get Cyber Alerts
    CyberNexora News
    Home»Cyber Incidents»I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files

    I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files

    Zeel_CyberexpertBy Zeel_CyberexpertOctober 9, 20268 Mins Read
    WhatsApp Account Takeover
    Facebook Twitter LinkedIn Email Telegram

    The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has warned about a cyber-fraud campaign in which malicious files are being distributed through WhatsApp, SMS and email under the appearance of account statements and regulatory communications.

    The campaign targets professionals and businesses, particularly Chartered Accountants, Company Directors, CFOs and corporate finance teams. In reported cases, attackers use malware to compromise Windows systems and active WhatsApp Web sessions, after which compromised accounts can be abused for further distribution and fraudulent financial instructions. Press Information Bureau

    I4C said it had alerted more than 58,000 potential victims through the SMS header “I4CMHA-G” in the previous 30 days and that more than 10,000 Indians had been protected through coordinated interventions. Press Information Bureau

    What Is the WhatsApp Account Takeover Campaign?

    The campaign begins with social engineering.

    A victim may receive a message that appears to be related to an account statement, RBI communication, MCA communication or another urgent financial or regulatory matter.

    The attached file is commonly a compressed .zip archive.

    The objective is to convince the recipient to extract and execute the contents on a Windows computer. According to I4C, the archive can contain a malicious .exe file together with a .dll file. Press Information Bureau

    How the Attack Works

    1. The Attacker Sends a Fake Financial or Regulatory Message

    The initial message may arrive through WhatsApp, SMS or email.

    Reported file names include:

    • Statement of Account.zip
    • RBI.zip
    • MCA.zip

    The message is designed to look like a routine business communication or an urgent regulatory requirement. Press Information Bureau

    2. The Victim Opens the ZIP File

    The archive contains a Windows executable and a DLL file.

    If the executable is extracted and opened on a Windows computer, I4C says a Trojan can be installed on the device. Press Information Bureau

    3. WhatsApp Web Session Can Be Compromised

    The malware can compromise the victim’s device and hijack an active WhatsApp Web session.

    This is a critical part of the attack because the attacker can then misuse a legitimate WhatsApp account rather than relying only on a newly created fake account. Press Information Bureau

    4. The Malicious File Can Spread Further

    I4C reported that compromised WhatsApp accounts can automatically circulate the same malicious file to contacts and groups.

    Messages may encourage recipients to forward the file to a company finance manager for verification, allowing the campaign to reach additional victims. Press Information Bureau

    5. Attackers Can Target Corporate Payments

    In the financial-fraud stage, attackers can misuse a compromised senior executive’s genuine WhatsApp account to instruct accounts or finance employees to make urgent payments to mule bank accounts.

    I4C also described a variant in which an attacker-controlled number can be saved under the name of a CEO or senior executive after device takeover. Press Information Bureau

    This is the stage I4C refers to as the “Boss Scam” or CEO impersonation fraud.

    Why Finance Teams Are a Major Target

    The campaign specifically creates lures around financial statements and regulatory compliance.

    That makes the following groups particularly relevant targets:

    • Chartered Accountants
    • Company Directors
    • Chief Financial Officers
    • Finance and Accounts employees
    • Corporate organizations

    The combination of a trusted communication channel, an apparent regulatory requirement and an urgent financial request can make the attack more convincing. Press Information Bureau

    What Makes This Attack Dangerous?

    The campaign combines multiple attack stages:

    Social Engineering → Malicious ZIP → Windows Malware → WhatsApp Web Takeover → Further Malware Distribution → Executive Impersonation → Financial Fraud

    This means the initial malicious file is not necessarily the final objective.

    The attackers can use the compromised account as a trusted channel to reach other people and potentially manipulate corporate payment processes. Press Information Bureau

    What Is DLL Sideloading?

    I4C’s technical analysis says the campaign uses DLL Sideloading as part of its detection-evasion capabilities.

    In simple terms, DLL Sideloading is a technique where malicious code is loaded through a legitimate executable’s DLL-loading process.

    I4C described the campaign as using advanced malware with propagation and detection-evasion capabilities. Press Information Bureau

    Which Devices Are Affected?

    According to I4C, the malware described in this campaign activates on Windows computers.

    The reported attack specifically involves extracting and executing the malicious contents on a Windows desktop or laptop. Press Information Bureau

    However, a person using another operating system could still receive or forward a malicious file to someone using Windows, so suspicious attachments should not be forwarded.

    I4C’s Response

    I4C has taken several measures against the campaign.

    Victim Notifications

    I4C is proactively informing identified victims and potential victims so they can take steps such as securing accounts and logging out of linked devices. Press Information Bureau

    Threat Intelligence Sharing

    Technical threat information has been shared with:

    • CERT-In
    • Microsoft Defender
    • Quick Heal
    • K7 Computing
    • Net Protector

    The objective is to improve detection, blocking and removal of malicious files. Press Information Bureau

    Protection Through Sahyog Portal

    I4C said that more than 10,000 Indians had been protected through coordinated interventions, including blocking malware infrastructure through the Sahyog Portal. Press Information Bureau

    SMS Alerts

    I4C is using the SMS header “I4CMHA-G” to alert affected or potentially affected citizens. Press Information Bureau

    How to Stay Safe

    1. Do Not Open Unknown ZIP Files

    Do not download, extract or execute suspicious .zip, .exe or .dll files received through WhatsApp, SMS or email.

    2. Do Not Trust Urgent Messages Automatically

    A message claiming to be from a regulator, senior executive or finance department should not automatically be treated as genuine.

    Verify it through an independent communication channel.

    3. Verify Every Urgent Payment Request

    If a senior executive asks the finance team to transfer money through WhatsApp or email, verify the instruction through a direct voice call or in-person confirmation before making the transfer. I4C specifically recommends independent verification. Press Information Bureau

    4. Check WhatsApp Linked Devices

    Regularly review:

    WhatsApp → Settings → Linked Devices

    Log out of WhatsApp Web sessions that are no longer required. Press Information Bureau

    5. Secure Windows Endpoints

    Organizations should use updated endpoint security and restrict execution of unknown .exe and .dll files from user-profile locations. Press Information Bureau

    6. If Your Account Is Compromised

    I4C recommends:

    • Log out of linked devices
    • Warn contacts not to open files received from the compromised account
    • Scan the affected computer with updated antivirus software
    • Take immediate security action Press Information Bureau

    What If Money Has Already Been Lost?

    Cyber financial fraud should be reported immediately through India’s cyber-fraud reporting system.

    Cyber Crime Helpline: 1930

    You can also report the incident through the National Cyber Crime Reporting Portal. I4C’s broader cyber-fraud system is designed to support rapid reporting and coordination with financial institutions and law-enforcement agencies. Press Information Bureau

    The Bigger Cybersecurity Lesson

    This campaign shows why corporate cybersecurity cannot depend only on antivirus software.

    The attack combines:

    Technology + Social Engineering + Trust + Urgency

    The malicious file creates the technical compromise. The compromised WhatsApp account provides a trusted communication channel. The impersonation and urgent payment request then target human decision-making.

    For organizations, security awareness, endpoint protection, account monitoring and independent payment verification all play an important role.

    How CyberNexora Can Help

    Organizations should regularly assess their digital security instead of waiting for an incident to reveal weaknesses.

    CyberNexora provides cybersecurity and VAPT services that can help organizations identify security weaknesses, assess their exposure and strengthen their security posture.

    For businesses handling sensitive financial information, security testing and employee security awareness can be valuable parts of a broader cybersecurity strategy.

    The key lesson from this I4C warning is simple: never open an unverified financial ZIP file, and never approve an urgent fund transfer based only on a WhatsApp or email instruction.

    What is the Boss Scam?

    I4C describes the Boss Scam as CEO or executive impersonation fraud in which attackers can use a compromised executive account or an attacker-controlled number saved under an executive’s name to instruct finance staff to transfer funds. Press Information Bureau

    What file types are being used?

    The reported campaign uses compressed ZIP files containing malicious Windows executables and DLL files.

    Does the malware target Windows?

    Yes. I4C states that the malware described in the campaign activates on Windows computers.

    What should I do if I receive an RBI or MCA ZIP file on WhatsApp?

    Do not extract or execute it. Verify the communication independently and report suspicious activity to your organization’s security team. I4C specifically warns against opening unverified ZIP files and recommends independent verification of urgent financial instructions.

    How can companies protect their finance teams?

    Companies should combine endpoint security, employee awareness, restrictions on unknown executables, WhatsApp linked-device monitoring and independent verification of payment instructions.

    Related Articles

  • 7-Zip Mark-of-the-Web Bypass: Critical SmartScreen Risk Introduction: Why It Matters Researchers have identified a security concern...
  • Boss Scam Warning: MHA Alerts Businesses to CEO Fraud Introduction: Boss Scam Warning — Why It Matters India’s Boss...
  • Fake 7-Zip Installers: Lurking Lizard Builds Proxy Botnet Introduction: Fake 7-Zip Installers — Why It Matters Cybersecurity researchers...
  • WhatsApp OTP Scam: How Indian Accounts Are Stolen Introduction: WhatsApp OTP Scam — Why It Matters The WhatsApp...
  • BambooToken Malware: Critical MQTT C2 Campaign Introduction: BambooToken Malware — Why It Matters BambooToken Malware is...
  • Share. Facebook Twitter LinkedIn Email Telegram

    latest news

    I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files

    October 9, 2026

    Why Colleges Worldwide Are Being Targeted by Cyber Attacks in 2026 – and How VAPT Can Help

    October 5, 2026

    CERT-In Warns of High-Severity Apple Vulnerability: iPhone, iPad and Mac Users Should Update Now

    October 3, 2026

    OpenAI AI Agents Breached Australian Government Portal in Wider Hacking Campaign

    September 28, 2026

    Viral “Rent A Garba Partner” Post Raises Cybersecurity Questions Amid Navratri Scam Warnings

    September 19, 2026

    Azure AI Foundry Vulnerability: CVSS 10.0

    September 18, 2026

    T-Mobile Rewards Phishing: Fake Expiry Scam Texts

    September 18, 2026

    Docker Sandboxes Vulnerabilities: Critical Flaws

    September 17, 2026

    HEAVYGRAM Malware: Telegram Surveillance Backdoor

    September 17, 2026

    SparroWocky Backdoor: FamousSparrow Targets Governments

    September 17, 2026
    Recent Posts
    • I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files
    • Why Colleges Worldwide Are Being Targeted by Cyber Attacks in 2026 – and How VAPT Can Help
    • CERT-In Warns of High-Severity Apple Vulnerability: iPhone, iPad and Mac Users Should Update Now
    Top Posts

    I4C Warns of WhatsApp Account Takeover Through Malicious ZIP Files

    October 9, 2026

    Unauthorized Access Incident at Coupang Exposes Customer Data

    December 29, 2025

    Significant Data Breach at Korean Air Subcontractor Exposes Employee Records

    December 29, 2025
    About

    CyberNexora Blog provides trusted cybersecurity news, attack analysis, and security awareness updates. Our goal is to educate and inform readers about emerging cyber threats and best protection practices.

    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Pages
    • Home
    • Cyber Incidents
    • laws & government
    • Penalties
    • Learn & Protect
    • Resources
    • Contact Us

    Get Cyber Security Alerts

    Thanks! Please check your email to confirm subscription.

    • About CyberNexora News
    • Privacy Policy
    © 2026 CyberNexora News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.