The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs has warned of a campaign that takes over WhatsApp accounts of finance professionals using malicious files disguised as account statements and regulator communications.
Victims receive a .zip file named like 'Statement of Account.zip', 'RBI.zip' or 'MCA.zip' containing a Windows executable and a DLL file; opening it installs a Trojan that hijacks the active WhatsApp Web session.
Compromised accounts of senior executives are then used to instruct finance staff to transfer funds to mule accounts — the reason it is called a 'Boss Scam'.
I4C has intimated over 58,000 potential victims through the SMS header 'I4CMHA-G' in the last 30 days and says more than 10,000 Indians have been protected so far.
Incidents following an identical modus operandi have been reported from Delhi, Gujarat, Maharashtra and Rajasthan.
The victim receives a compressed .zip file over WhatsApp, SMS or email, named to look routine — 'Statement of Account.zip', often prefixed with a date such as '0714', or 'RBI.zip' and 'MCA.zip'. The covering message is written either as an ordinary account statement or as an urgent regulatory notice demanding compliance in a very short time, which is what pushes the recipient to open it. Inside the archive is a Windows executable file accompanied by a Dynamic Link Library file. When the archive is extracted and the executable opened on a Windows desktop or laptop, a Trojan installs itself, compromises the device and hijacks the user's active WhatsApp Web session. Control of the account is then used to message the victim's own colleagues — typically finance staff, who receive what appears to be an instruction from their senior to transfer funds to accounts controlled by the fraudsters.
Simple Analogy: It is the digital version of stealing a manager's letterhead and signature: nothing about the instruction looks unusual to the clerk who receives it, because it genuinely arrives from the manager's own account.
Coordinates the prevention, detection, investigation and prosecution of cybercrime; established as a scheme of the Ministry of Home Affairs in 2018 and inaugurated on 10 January 2020; became an attached office of the MHA with effect from 1 July 2024. It has seven components — the National Cyber Crime Threat Analytics Unit, National Cyber Crime Reporting Portal, National Cyber Crime Training Centre, Cyber Crime Ecosystem Management Unit, National Cyber Crime Research and Innovation Centre, National Cyber Crime Forensic Laboratory Ecosystem and the Platform for Joint Cyber Crime Investigation Team
The analytics vertical of I4C; it carried out the technical analysis identifying the DLL sideloading technique and the cross-border organised networks running this campaign
The national nodal agency for cyber security incident response, operational since January 2004; it received the threat signals and technical indicators of this malware for wider blocking
The public portal at www.cybercrime.gov.in where cyber crimes are reported; the rise in complaints on this portal is what alerted I4C to the campaign. It was dedicated to the nation on 10 January 2020 along with the inauguration of I4C
Launched in October 2024 by the Ministry of Home Affairs through I4C to automate the issue of content takedown notices to intermediaries under Section 79(3)(b) of the Information Technology Act, 2000; used here to block the malware
Enable immediate reporting of financial cyber fraud so that money can be frozen before it is siphoned away
Key: Launched in 2021 under I4C; reached through helpline 1930 or the NCRP, it connects victims, police, banks and financial intermediaries, and depends on reporting within the first minutes — the 'golden hour'
Give citizens a single national channel to report cyber crime, with a special focus on offences against women and children
Key: Accessible at www.cybercrime.gov.in; complaint analysis on this portal is how I4C identified this campaign and the victims it went on to alert
Streamline and automate takedown notices from authorised agencies to IT intermediaries
Key: Operates under Section 79(3)(b) of the Information Technology Act, 2000 — the provision under which an intermediary can lose safe-harbour protection if it fails to act on a government notice
Give citizens a verifiable government sender identity for cyber-safety alerts
Key: I4C sends alerts to affected and potentially affected citizens only from this header; over 58,000 potential victims were intimated through it in the last 30 days
The provision under which CERT-In functions as the national agency for cyber security, collecting and disseminating information on cyber incidents and issuing directions
The safe-harbour provision under which the Sahyog Portal issues notices: an intermediary that fails to remove or disable unlawful content after being notified by the government can lose its protection from liability
The fraud converts a hijacked identity into money by routing transfers through mule accounts, which is why the freezing window created by CFCFRMS and helpline 1930 matters
The malware succeeds not on technical sophistication alone but on impersonating regulators — the RBI, the Ministry of Corporate Affairs and the Income Tax Department — and imposing artificial urgency
Threat signals were shared with Microsoft Defender and Indian anti-virus firms Quick Heal, K7 Computing and Net Protector, showing how state agencies rely on private security vendors for last-mile blocking
The use of the Sahyog Portal ties this advisory to the wider debate on Section 79(3)(b) and government takedown powers over online intermediaries
GS Paper 3 > Internal Security > Challenges of Cyber Security and Money Laundering
General Awareness > Government Bodies and Current Affairs
General Awareness > Banking and Cyber Fraud Awareness
General Awareness > Current Affairs
Cyber security institutions appear almost every year in Prelims and are a standing GS Paper 3 internal security theme
Indian Cyber Crime Coordination Centre — the Ministry of Home Affairs body coordinating India's response to cyber crime, an attached office of the MHA since 1 July 2024
National Cyber Crime Threat Analytics Unit — the analytics vertical of I4C that performs technical analysis of malware campaigns
A technique in which malicious code is loaded through a Dynamic Link Library file placed alongside a legitimate-looking executable, helping the malware evade detection
A bank account, often opened in another person's name, used to receive and rapidly move the proceeds of fraud
The protection under Section 79 of the IT Act that shields an intermediary from liability for third-party content, which can be lost if it ignores a government takedown notice under Section 79(3)(b)