Beware Of ‘Boss Scam’: MHA Warns Finance Professionals Of WhatsApp Hijack Fraud

Cyber fraud Boss scam

Pic courtesy pixabay.com


New Delhi: There’s a new scam that fraudsters have come up with recently – the ‘Boss Scam’.

The Ministry of Home Affairs (MHA) issued an advisory through which it has warned corporate entities, Chartered Accountants, company directors, Chief Financial Officers (CFOs) and other finance professionals about a rapidly spreading cyber fraud.

There have been a significant rise in complaints received through the National Cyber Crime Reporting Portal (NCRP). Such incidents have been reported from states like Delhi, Gujarat, Maharashtra and Rajasthan.

The modus operandi of scamsters is to compromise WhatsApp accounts and orchestrate high-value financial fraud.

According to the Indian Cyber Crime Coordination Centre (I4C) under the MHA, cybercriminals are using malicious files disguised as ‘Statement of Account’, ‘RBI’ or ‘MCA’ documents to infect Windows computers and hijack victims’ active WhatsApp Web sessions.

The malware, distributed through WhatsApp, SMS and email, is often accompanied by messages posing as routine account statements or urgent regulatory notices requiring immediate compliance.

The National Cybercrime Threat Analytics Unit (NCTAU), cyber intelligence arm of I4C, found that the campaign is being operated by organised cross-border cybercrime networks using advanced malware which can evade detection through the DLL sideloading technique.

Thorough investigation is ongoing in coordination with law enforcement and technical agencies.

The malware specifically targets Windows devices.

Once a victim extracts and opens the malicious ZIP archive, a Trojan is installed that compromises the computer and takes control of the user’s active WhatsApp Web session. In several cases, fraudsters have impersonated the Income Tax Department through phishing emails.

Once access is gained, attackers use the compromised WhatsApp account to circulate the malicious files to the victim’s contacts and groups, often asking recipients to forward the document to their company’s finance manager for verification. This way, the malware spreads within corporate networks.

In the final stage of the fraud, hackers exploit the genuine WhatsApp account of a senior executive or manipulate contact details to impersonate a company’s CEO. Urgent instructions are sent to finance and accounts personnel, directing them to transfer funds to mule bank accounts.

Going by the nature of the attack, the finance departments are at highest risk. Organisations have been advised to sensitise employees, particularly those handling financial transactions, and to independently verify any urgent fund transfer request or account change instruction received via WhatsApp or email through a direct phone call or in-person confirmation before taking action.

SOP issued

The I4C has issued a standard operating procedure (SOP) advising individuals and organisations not to download, extract or open ZIP files or executable programmes received from unknown or unverified sources. Regulators such as Reserve Bank of India (RBI) don’t distribute software updates, security patches or account statements through WhatsApp attachments, it was reminded.

Users have also been advised to regularly review WhatsApp’s ‘Linked Devices’ section and log out of inactive WhatsApp Web sessions. System administrators should block the execution of unknown executable (.exe) and Dynamic Link Library (.dll) files from user profile directories and ensure that all Windows systems are protected with up-to-date anti-malware software.

In case an account is suspected to have been compromised, users should immediately log out of all linked devices, inform their contacts not to open any files received from the affected account, and scan the computer using updated antivirus software.

MHA said coordinated efforts have protected more than 10,000 users, while over 58,000 potential victims have been alerted over the past month through SMS messages sent under the header ‘I4CMHA-G’.

The Home ministry appealed to citizens to promptly act on such alerts and report suspected cyber fraud by calling the National Cyber Crime Helpline (1930) or through the National Cyber Crime Reporting Portal.



Exit mobile version