The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has warned about a cyber-fraud campaign in which malicious files are being distributed through WhatsApp, SMS and email under the appearance of account statements and regulatory communications.
The campaign targets professionals and businesses, particularly Chartered Accountants, Company Directors, CFOs and corporate finance teams. In reported cases, attackers use malware to compromise Windows systems and active WhatsApp Web sessions, after which compromised accounts can be abused for further distribution and fraudulent financial instructions. Press Information Bureau
I4C said it had alerted more than 58,000 potential victims through the SMS header “I4CMHA-G” in the previous 30 days and that more than 10,000 Indians had been protected through coordinated interventions. Press Information Bureau
What Is the WhatsApp Account Takeover Campaign?
The campaign begins with social engineering.
A victim may receive a message that appears to be related to an account statement, RBI communication, MCA communication or another urgent financial or regulatory matter.
The attached file is commonly a compressed .zip archive.
The objective is to convince the recipient to extract and execute the contents on a Windows computer. According to I4C, the archive can contain a malicious .exe file together with a .dll file. Press Information Bureau
How the Attack Works
1. The Attacker Sends a Fake Financial or Regulatory Message
The initial message may arrive through WhatsApp, SMS or email.
Reported file names include:
Statement of Account.zipRBI.zipMCA.zip
The message is designed to look like a routine business communication or an urgent regulatory requirement. Press Information Bureau
2. The Victim Opens the ZIP File
The archive contains a Windows executable and a DLL file.
If the executable is extracted and opened on a Windows computer, I4C says a Trojan can be installed on the device. Press Information Bureau
3. WhatsApp Web Session Can Be Compromised
The malware can compromise the victim’s device and hijack an active WhatsApp Web session.
This is a critical part of the attack because the attacker can then misuse a legitimate WhatsApp account rather than relying only on a newly created fake account. Press Information Bureau
4. The Malicious File Can Spread Further
I4C reported that compromised WhatsApp accounts can automatically circulate the same malicious file to contacts and groups.
Messages may encourage recipients to forward the file to a company finance manager for verification, allowing the campaign to reach additional victims. Press Information Bureau
5. Attackers Can Target Corporate Payments
In the financial-fraud stage, attackers can misuse a compromised senior executive’s genuine WhatsApp account to instruct accounts or finance employees to make urgent payments to mule bank accounts.
I4C also described a variant in which an attacker-controlled number can be saved under the name of a CEO or senior executive after device takeover. Press Information Bureau
This is the stage I4C refers to as the “Boss Scam” or CEO impersonation fraud.
Why Finance Teams Are a Major Target
The campaign specifically creates lures around financial statements and regulatory compliance.
That makes the following groups particularly relevant targets:
- Chartered Accountants
- Company Directors
- Chief Financial Officers
- Finance and Accounts employees
- Corporate organizations
The combination of a trusted communication channel, an apparent regulatory requirement and an urgent financial request can make the attack more convincing. Press Information Bureau
What Makes This Attack Dangerous?
The campaign combines multiple attack stages:
Social Engineering → Malicious ZIP → Windows Malware → WhatsApp Web Takeover → Further Malware Distribution → Executive Impersonation → Financial Fraud
This means the initial malicious file is not necessarily the final objective.
The attackers can use the compromised account as a trusted channel to reach other people and potentially manipulate corporate payment processes. Press Information Bureau
What Is DLL Sideloading?
I4C’s technical analysis says the campaign uses DLL Sideloading as part of its detection-evasion capabilities.
In simple terms, DLL Sideloading is a technique where malicious code is loaded through a legitimate executable’s DLL-loading process.
I4C described the campaign as using advanced malware with propagation and detection-evasion capabilities. Press Information Bureau
Which Devices Are Affected?
According to I4C, the malware described in this campaign activates on Windows computers.
The reported attack specifically involves extracting and executing the malicious contents on a Windows desktop or laptop. Press Information Bureau
However, a person using another operating system could still receive or forward a malicious file to someone using Windows, so suspicious attachments should not be forwarded.
I4C’s Response
I4C has taken several measures against the campaign.
Victim Notifications
I4C is proactively informing identified victims and potential victims so they can take steps such as securing accounts and logging out of linked devices. Press Information Bureau
Threat Intelligence Sharing
Technical threat information has been shared with:
- CERT-In
- Microsoft Defender
- Quick Heal
- K7 Computing
- Net Protector
The objective is to improve detection, blocking and removal of malicious files. Press Information Bureau
Protection Through Sahyog Portal
I4C said that more than 10,000 Indians had been protected through coordinated interventions, including blocking malware infrastructure through the Sahyog Portal. Press Information Bureau
SMS Alerts
I4C is using the SMS header “I4CMHA-G” to alert affected or potentially affected citizens. Press Information Bureau
How to Stay Safe
1. Do Not Open Unknown ZIP Files
Do not download, extract or execute suspicious .zip, .exe or .dll files received through WhatsApp, SMS or email.
2. Do Not Trust Urgent Messages Automatically
A message claiming to be from a regulator, senior executive or finance department should not automatically be treated as genuine.
Verify it through an independent communication channel.
3. Verify Every Urgent Payment Request
If a senior executive asks the finance team to transfer money through WhatsApp or email, verify the instruction through a direct voice call or in-person confirmation before making the transfer. I4C specifically recommends independent verification. Press Information Bureau
4. Check WhatsApp Linked Devices
Regularly review:
WhatsApp → Settings → Linked Devices
Log out of WhatsApp Web sessions that are no longer required. Press Information Bureau
5. Secure Windows Endpoints
Organizations should use updated endpoint security and restrict execution of unknown .exe and .dll files from user-profile locations. Press Information Bureau
6. If Your Account Is Compromised
I4C recommends:
- Log out of linked devices
- Warn contacts not to open files received from the compromised account
- Scan the affected computer with updated antivirus software
- Take immediate security action Press Information Bureau
What If Money Has Already Been Lost?
Cyber financial fraud should be reported immediately through India’s cyber-fraud reporting system.
Cyber Crime Helpline: 1930
You can also report the incident through the National Cyber Crime Reporting Portal. I4C’s broader cyber-fraud system is designed to support rapid reporting and coordination with financial institutions and law-enforcement agencies. Press Information Bureau
The Bigger Cybersecurity Lesson
This campaign shows why corporate cybersecurity cannot depend only on antivirus software.
The attack combines:
Technology + Social Engineering + Trust + Urgency
The malicious file creates the technical compromise. The compromised WhatsApp account provides a trusted communication channel. The impersonation and urgent payment request then target human decision-making.
For organizations, security awareness, endpoint protection, account monitoring and independent payment verification all play an important role.
How CyberNexora Can Help
Organizations should regularly assess their digital security instead of waiting for an incident to reveal weaknesses.
CyberNexora provides cybersecurity and VAPT services that can help organizations identify security weaknesses, assess their exposure and strengthen their security posture.
For businesses handling sensitive financial information, security testing and employee security awareness can be valuable parts of a broader cybersecurity strategy.
The key lesson from this I4C warning is simple: never open an unverified financial ZIP file, and never approve an urgent fund transfer based only on a WhatsApp or email instruction.
What is the Boss Scam?
I4C describes the Boss Scam as CEO or executive impersonation fraud in which attackers can use a compromised executive account or an attacker-controlled number saved under an executive’s name to instruct finance staff to transfer funds. Press Information Bureau
What file types are being used?
The reported campaign uses compressed ZIP files containing malicious Windows executables and DLL files.
Does the malware target Windows?
Yes. I4C states that the malware described in the campaign activates on Windows computers.
What should I do if I receive an RBI or MCA ZIP file on WhatsApp?
Do not extract or execute it. Verify the communication independently and report suspicious activity to your organization’s security team. I4C specifically warns against opening unverified ZIP files and recommends independent verification of urgent financial instructions.
How can companies protect their finance teams?
Companies should combine endpoint security, employee awareness, restrictions on unknown executables, WhatsApp linked-device monitoring and independent verification of payment instructions.
