Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Business

WhatsApp 'Boss Scam' Hijacks Executive Accounts with Fake Regulatory Files

· · 4 min read

The Indian Cyber Crime Coordination Centre (I4C) warns businesses about a sophisticated "Boss Scam" where cybercriminals use malicious fake RBI or MCA files to compromise senior executives' WhatsApp Web sessions, then trick finance teams into urgent, fraudulent payments.

The Indian Cyber Crime Coordination Centre (I4C) has issued a critical warning to professionals and businesses regarding a sophisticated cyber fraud known as the "Boss Scam." This evolving threat leverages fake regulatory documents to gain control of senior executives' communication channels, ultimately coercing employees into making unauthorized financial transfers.

How the Sophisticated Scam Unfolds

The operation typically commences with a deceptive message sent to a senior executive via WhatsApp, SMS, or email. These messages are crafted to appear as urgent compliance requirements from legitimate regulators, such as the Reserve Bank of India (RBI) or the Ministry of Corporate Affairs (MCA).

Attached to these messages are seemingly innocuous ZIP files, often named like “Statement of Account.zip,” “RBI.zip,” or “MCA.zip,” sometimes prefixed with a date. The objective is to trick the recipient into believing the attachment is a crucial financial or regulatory document that demands immediate attention.

Upon opening and extracting these ZIP archives on a Windows computer, malicious executable (.exe) and Dynamic Link Library (.dll) files are deployed. I4C's technical analysis reveals that this campaign utilizes DLL sideloading, a technique designed to help malware evade detection by security software. Once executed, the malware compromises the computer and, critically, hijacks any active WhatsApp Web sessions.

Beyond Traditional Impersonation

What distinguishes this new iteration of the Boss Scam from conventional CEO impersonation fraud is its advanced technical sophistication. While older scams typically involved creating fake accounts or spoofing identities, this method takes control of the executive's actual WhatsApp Web session. This eliminates one of the most common red flags for employees: verifying the sender's number. The fraudulent payment requests then appear to come directly from the genuine WhatsApp account of the CEO or another senior executive, exploiting both technical access and an employee's trust in senior management.

I4C's Response and Safeguards

The I4C has taken coordinated action, reportedly protecting over 10,000 Indians from this campaign. Threat signals and technical indicators associated with the malware have been shared with major cybersecurity entities, including CERT-In, Microsoft Defender, and Indian antivirus companies like Quick Heal, K7 Computing, and Net Protector. The government's Sahyog Portal is also being used to block these malicious files.

Additionally, I4C has proactively alerted more than 58,000 potential victims through SMS headers like “I4CMHA-G,” advising them to follow security instructions promptly.

Protecting Your Business and Employees

To mitigate the risk of falling victim to this scam, I4C advises companies and employees to implement several critical safeguards:

  • Verify All Urgent Instructions: Independently verify every urgent payment instruction received via WhatsApp or email. For large or unusual transfers, always confirm the request through a direct voice call or in-person communication, rather than relying solely on a message.
  • Exercise Caution with Attachments: Avoid opening ZIP files or executable files from unknown or unverified sources. Never assume a file is genuine simply because it appears to come from a known contact.
  • Regularly Check Linked Devices: Employees should frequently check WhatsApp > Settings > Linked Devices and remove any sessions that are no longer in use or appear suspicious.
  • Maintain System Security: Keep Windows operating systems and antivirus software consistently updated to protect against the latest threats.
  • Restrict File Execution: Configure systems to restrict the execution of unknown .exe and .dll files from user profile directories.
  • Act Immediately if Compromised: If an account is suspected of being compromised, immediately log out of all linked devices and warn contacts not to open any files sent from the affected account. Scan the affected computer using updated security software.

The I4C advisory also reiterates that regulatory bodies like the RBI do not send software updates, security fixes, or account statements through WhatsApp attachments. Anyone who receives a suspicious file or believes their account or computer has been compromised should report it immediately through the National Cyber Crime Helpline at 1930 or the National Cyber Crime Reporting Portal.

Related