'Boss Scam' hits WhatsApp; government issues warning—one mistake could lead to a loss of lakhs..
Amid rising cyber fraud in the country, the Indian Cyber Crime Coordination Centre (I4C) has issued a warning regarding a new and highly dangerous 'Boss Scam.' In this scam, hackers gain control over people's computers and WhatsApp accounts by sending fake ZIP files via WhatsApp, email, or SMS. Subsequently, the compromised account is used to defraud company employees of sums running into crores of rupees. Let us understand what the 'Boss Scam' is and how you can protect yourself from it.
**How the 'Boss Scam' Works**
According to the I4C, which operates under the Ministry of Home Affairs (MHA), cybercriminals send files with names like "Statement of Account.zip," "RBI.zip," or "MCA.zip" via WhatsApp, email, or SMS. These files are crafted to resemble bank statements or important notifications from government departments.
The files are often accompanied by messages that create pressure for immediate action. As soon as a person downloads the ZIP file and opens it on a Windows computer, the malware contained within installs itself on the system.
**WhatsApp Accounts Can Be Hacked**
According to the I4C, the ZIP file contains a dangerous Windows Executable (.exe) and a DLL file. Upon opening it, Trojan malware installs on the computer and hijacks the active WhatsApp Web session. Cybercriminals then use the victim's WhatsApp account to send the same infected file to all their contacts and groups. In many instances, the accompanying message instructs the recipient to forward the file to the company's finance manager for verification.
**Targeting Finance Teams**
The I4C reports that this cyber campaign specifically targets Chartered Accountants, company directors, CFOs, finance managers, and accounts department staff. Since the files are named to suggest associations with account statements, the RBI, the MCA, or income tax matters, finance department employees can easily fall prey to this ruse.
Then comes the multi-crore scam...
When a senior official's WhatsApp account is hacked, cybercriminals use that account to instruct the finance team to transfer funds immediately. In some instances, cybercriminals save their own number as "CEO" on the victim's mobile phone. Subsequently, they message the accounts department, directing an immediate transfer of funds to a specific bank account. Since the message appears to come from the CEO, many employees process the payment without verification.
I4C issues crucial advice
The Ministry of Home Affairs has issued several important guidelines for individuals and companies. Do not download or open ZIP files received via unknown WhatsApp messages, SMS, or emails. Government bodies—such as the RBI, MCA, or the Income Tax Department—do not send updates via ZIP files on WhatsApp. Periodically check your linked devices by navigating to Settings > Linked Devices on WhatsApp and immediately log out of any unrecognized devices. Always use updated antivirus software or Microsoft Defender on Windows computers.
Always verify instructions regarding urgent payments or changes to bank account details through a phone call or in-person conversation. If your WhatsApp account is compromised, immediately log out from all linked devices and alert all your contacts.
Major steps taken by I4C
I4C stated that it is collaborating with multiple agencies to combat this campaign. Information regarding the malware has been shared with CERT-In, Microsoft Defender, Quick Heal, K7 Computing, and Net Protector. Additionally, malicious files are being continuously blocked through the 'Sahyog' portal.
Where to report cyber fraud?
If you receive any such suspicious file, WhatsApp message, or email, or if you fall victim to cyber fraud, immediately call the National Cyber Crime Helpline at 1930 or file a complaint at www.cybercrime.gov.in.
Disclaimer: This content has been sourced and edited from NDTV India. While we have made modifications for clarity and presentation, the original content belongs to its respective authors and website. We do not claim ownership of the content.

