Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Technology

I4C Warns Finance Teams of WhatsApp 'Boss Scam' Using Fake RBI, MCA Files

· · 3 min read

India's I4C has issued a warning to companies and finance professionals about a sophisticated "Boss Scam." Fraudsters use malicious ZIP files disguised as RBI or MCA documents to hijack WhatsApp accounts, leading to high-value financial fraud.

The Indian Cybercrime Coordination Centre (I4C) has issued a critical alert regarding a growing cyber fraud campaign targeting corporate finance teams and professionals. Dubbed the "Boss Scam" or CEO impersonation fraud, the scheme leverages malicious files disguised as official communications from regulatory bodies like the Reserve Bank of India (RBI) and the Ministry of Corporate Affairs (MCA) to compromise WhatsApp accounts and facilitate significant financial theft.

How the WhatsApp 'Boss Scam' Unfolds

According to the I4C, victims typically receive compressed ZIP files via WhatsApp, SMS, or email. These files often bear names such as "Statement of Account.zip," "RBI.zip," or "MCA.zip," designed to appear as routine financial communications or urgent regulatory notices. Some might even include date prefixes, like "0714 Statement of Account.zip," to enhance their legitimacy.

Upon extraction and opening on a Windows computer, these archives unleash a malicious Windows executable (.exe) and a Dynamic Link Library (.dll) file. This malware installs a Trojan that compromises the user's device and hijacks their active WhatsApp Web session, giving fraudsters unauthorized access to their account.

From Account Takeover to Financial Fraud

Once a WhatsApp account is compromised, the malware automatically propagates by sending the same malicious file to the victim's contacts and WhatsApp groups. Recipients are often urged to forward the file to their company's finance manager for verification and open it on a computer, thereby spreading the malware further within corporate networks.

This initial compromise then escalates into the "Boss Scam." Fraudsters, either using the genuine WhatsApp account of a senior executive or an attacker-controlled number saved under the CEO's name, send urgent instructions to finance and accounts employees. These instructions typically demand immediate fund transfers to mule bank accounts, exploiting the trust associated with a senior executive's identity.

I4C's Response and Advisory

The I4C's National Cybercrime Threat Analytics Unit has indicated that organized networks operating across national borders are behind this sophisticated campaign, employing advanced propagation and detection-evasion techniques, including DLL sideloading.

In response, the I4C has shared threat signals and technical indicators with CERT-In, Microsoft Defender, and leading Indian cybersecurity firms like Quick Heal, K7 Computing, and Net Protector to enhance detection and blocking capabilities. Coordinated interventions have already protected over 10,000 individuals, and more than 58,000 potential victims have been alerted via SMS within the last 30 days.

The agency urges companies to:

  • Sensitize Employees: Especially finance teams, about the nature of these scams.
  • Verify Requests: Independently verify urgent fund-transfer or account-change requests through a direct voice call or in-person confirmation, never relying solely on digital messages.
  • Exercise Caution: Do not download, extract, or open ZIP files or executables from unknown or unverified sources.
  • Review WhatsApp Sessions: Regularly review WhatsApp's linked devices and log out of any inactive sessions.

In the event of a compromise, users should immediately log out of all linked devices, alert their contacts not to open files received from their account, and scan their computer with updated antivirus software. Suspicious cyber fraud incidents should be reported promptly via the national helpline 1930 or through the National Cyber Crime Reporting Portal at cybercrime.gov.in.

Related