Overview
The I4C has issued a fresh advisory on a large‑scale fraud that hijacks WhatsApp accounts of senior corporate officials. The scheme, popularly called the “Boss Scam”, spreads through malicious zip files that appear as RBI, MCA or account‑statement documents. Once a victim opens the file on a Windows PC, a Trojan installs, takes over the victim’s WhatsApp Web session and uses it to request fund transfers from finance teams.
Key Developments (Bullet Points)
- Since 22 June 2026, I4C has recorded a sharp rise in complaints on the NCRP from Delhi, Gujarat, Maharashtra and Rajasthan.
- Malicious zip files are named “Statement of Account.zip”, “RBI.zip” or “MCA.zip” and contain a Windows .exe together with a .dll employing DLL Sideloading.
- Compromised accounts automatically forward the same malicious file to all contacts, urging them to send it to their “company finance manager”.
- In the final stage, attackers, posing as the CEO or senior executive, instruct finance staff to transfer money to mule accounts.
- Over 58,000 potential victims have been alerted via SMS header ‘I4CMHA‑G’ in the last 30 days, and more than 10,000 Indians have been protected through geo‑blocking of command‑and‑control servers via the Sahyog Portal.
Important Facts
The malware activates only on Windows computers, making Chartered Accountants, Company Directors, CFOs and finance teams the prime targets. I4C has shared technical indicators with CERT‑In, Microsoft Defender and leading Indian anti‑virus firms (Quick Heal, K7 Computing, Net Protector) for rapid detection and removal.
Exam Relevance
This incident touches multiple GS papers. GS 2 (Polity) because it involves a central ministry (MHA) and inter‑agency coordination. GS 3 (Economy) as the fraud targets high‑value financial transactions and can affect corporate liquidity. GS 4 (Ethics & Integrity) because it raises questions about cyber‑ethics, digital hygiene and the responsibility of corporate governance in safeguarding information.
Way Forward for Organisations and Citizens
- Do not open zip or executable files from unknown sources; regulators never send software updates via WhatsApp.
- Finance staff must verify any urgent fund‑transfer request through a direct voice call or in‑person confirmation before acting.
- Regularly review WhatsApp linked devices (Settings → Linked Devices) and log out of inactive sessions.
- System administrators should enforce software‑restriction policies to block unknown .exe/.dll files and keep anti‑malware solutions up‑to‑date.
- If an account is compromised, log out of all linked devices, inform contacts not to open any received file, and scan the computer with updated antivirus.
- Report any suspicious communication immediately on the National Cyber Crime Helpline 1930 or at www.cybercrime.gov.in.
Staying vigilant and following these steps can curb the spread of the “Boss Scam” and protect India’s corporate financial ecosystem.