
The Indian Cyber Crime Coordination Centre (I4C) has flagged a growing cybercrime trend known as the 'Boss Scam' or CEO impersonation fraud, cautioning organisations and senior officials to remain vigilant against increasingly sophisticated attacks. As per the latest advisory from the National Cybercrime Threat Analytics Unit (NCTAU) under the Union Home Ministry, cybercriminals are specifically targeting high-ranking executives and decision-makers by sending malicious files disguised as urgent regulatory compliance documents. The agency emphasizes that regulators such as the Reserve Bank of India do not distribute mandatory software updates or security patches through WhatsApp attachments, making such messages a clear red flag for potential fraud. The effectiveness of these scams lies in their exploitation of organisational hierarchy and trust, with employees less likely to question directives appearing to come from top leadership, especially when conveyed through legitimate communication platforms.
The latest variant of the 'Boss Scam' begins with cybercriminals impersonating regulators such as the Reserve Bank of India (RBI) and sending urgent messages to CEOs or other senior officials via email or WhatsApp. According to the I4C advisory, these messages claim a regulatory violation or mandate an immediate security update and contain a malicious file disguised as a compliance document. The hackers deliver their malware through a compressed ZIP archive containing an executable program accompanied by a Dynamic Link Library file. When executives extract and execute the file on Windows desktop or laptop, a Trojan dropper is initiated. The malware establishes persistent control, compromises the system, and hijacks active Web WhatsApp session tokens, effectively granting attackers access to the executive's authentic messaging account. The I4C statement confirms that "the malware establishes persistence on the device, compromises its security controls and captures active Web WhatsApp session tokens, effectively granting attackers access to the executive's authentic messaging account."
Armed with access to the executive's WhatsApp account, fraudsters can operate from a position of unusual credibility. The I4C advisory notes that "these messages often contain instructions to process urgent financial transactions, leading to fraudulent fund transfers without raising immediate suspicion." In alternative scenarios, if attackers achieve complete device takeover, they covertly modify the device's contact list, saving fraudulent, attacker-controlled phone numbers under the name of the company's chief executive. The Home Ministry warns of a more sophisticated variant where attackers gain complete control over a device and secretly alter the contact list, allowing criminals to maintain control even after initial access is detected. The advisory highlights that "in multiple cases, the CEO forwards the message to the finance officer," demonstrating how the scam exploits trust within organisations. As per recent reports, victims receive urgent messages claiming compliance verification, regulatory violations, or security concerns that require immediate attention, with fraudsters often using pressure tactics to force quick action.
The I4C has issued comprehensive recommendations to companies to strengthen security measures against the growing 'Boss Scam' threat. Companies should strengthen verification procedures for financial transactions and not approve urgent payments or account changes based exclusively on WhatsApp messages or emails. The centre recommends confirmation through direct voice calls or face-to-face verification and advises executives to avoid opening unsolicited attachments, even if they appear work-related, and to regularly monitor active sessions on messaging platforms. Additionally, system administrators should enforce strict software restriction policies to block execution of unknown .exe and .dll files originating from user profile directories. The Home Ministry emphasizes that "system administrators should enforce strict software restriction policies (SRP) configurations to block the execution of unknown .exe and .dll files originating from the user profile directories." To counter the threat, I4C has urged organisations to independently verify any urgent payment requests or account changes through voice calls or face-to-face confirmation rather than relying solely on WhatsApp messages or emails. Victims or those encountering suspicious applications have been urged to report incidents through the cybercrime helpline number 1930 or the National Cyber Crime Reporting Portal.