New Delhi, Aug 7: The Indian Cyber Crime Coordination Centre (I4C) has warned of a sharp rise in WhatsApp account takeover cases involving finance professionals and businesspersons, cautioning that self-propagating malware disguised as account statements and regulatory files is being used to execute high-value “Boss Scam” frauds across multiple states.
The Ministry of Home Affairs’ cybercrime wing said complaints received through the National Cyber Crime Reporting Portal indicate that victims are being targeted with malicious `.zip` files sent over WhatsApp, SMS and e-mail under names such as “Statement of Account.zip”, “RBI.zip” and “MCA.zip”. Once opened on Windows computers, the files install malware that hijacks active WhatsApp Web sessions.
According to I4C, compromised WhatsApp accounts are then used to spread the malware further and, in advanced cases, impersonate senior executives to instruct finance teams to make urgent fund transfers to fraudulent bank accounts in what is commonly known as the “Boss Scam” or CEO impersonation fraud.
Technical analysis by the National Cybercrime Threat Analytics Unit found that the campaign is being operated by organised cross-border networks using advanced malware with sophisticated evasion techniques.
I4C said Chartered Accountants, company directors, Chief Financial Officers and finance personnel face the highest risk because the malware specifically targets Windows systems through fake account statements and regulatory compliance notices. It advised organisations to verify all urgent fund-transfer requests through direct voice calls or in-person confirmation before acting.
The agency said it has alerted potential victims, shared threat intelligence with CERT-In, Microsoft Defender and Indian anti-virus companies, and protected more than 10,000 citizens through coordinated interventions. It has also sent warning messages to over 58,000 potential victims via the SMS header “I4CMHA-G” during the past 30 days.
I4C urged citizens not to open unknown `.zip` files or executables, regularly review linked WhatsApp devices, keep anti-malware software updated, and immediately report cyber fraud through the National Cyber Crime Helpline 1930 or the National Cyber Crime Reporting Portal.

