
The Indian Cyber Crime Coordination Centre (I4C) has issued a comprehensive warning to corporates, chartered accountants and finance professionals regarding a surge in 'Boss Scam' frauds. According to reports from The Economic Times, the Union Home Ministry's cybercrime arm has noticed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) involving the takeover of WhatsApp accounts through malicious files. The agency has alerted more than 58,000 potential victims through SMS messages sent under the header 'I4CMHA-G' over the past 30 days.
As reported by The Economic Times, victims receive compressed files through WhatsApp, SMS or email that appear to contain account statements or urgent compliance notices from regulators or the government. The files contain malicious software that, when opened on a Windows computer, installs a Trojan capable of hijacking the user's active WhatsApp Web session. The compromised WhatsApp account is then used to automatically send the same malicious files to the victim's contacts and groups, often with instructions to forward them to a company's finance manager for verification, allowing the malware to spread deeper into corporate networks.
According to I4C's analysis reported by The Economic Times, in the final stage of the fraud, cybercriminals exploit the genuine WhatsApp account of a senior executive or impersonate a chief executive by saving an attacker-controlled number under the CEO's name on the compromised device. Finance and accounts staff are then instructed to urgently transfer funds to mule bank accounts. The campaign is being run by organised cross-border networks using advanced malware with sophisticated evasion techniques, including DLL sideloading.
As reported by The Economic Times, similar incidents have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan. The agency said the campaign poses a particular risk to chartered accountants, company directors, chief financial officers and finance teams because the malware is designed to run on Windows computers and uses account statements and regulatory compliance documents as bait. I4C has shared threat indicators with CERT-In, Microsoft Defender and Indian cybersecurity firms to improve detection and blocking of the malware.
According to The Economic Times, I4C has urged companies to sensitise employees, especially finance personnel, and independently verify any request for urgent fund transfers or changes to bank account details through a direct phone call or in-person confirmation before acting. The agency advised citizens not to download or open ZIP files or executable files received from unknown sources, regularly review and log out of unused WhatsApp Web sessions, and ensure Windows systems are protected with updated anti-malware software. Victims of such frauds are advised to immediately log out of linked devices, warn their contacts against opening suspicious files and report incidents through the national cybercrime helpline 1930 or the National Cyber Crime Reporting Portal.