Emerging "Boss Scam" Targets Indian Companies via Hijacked WhatsApp Accounts
India’s cybercrime watchdog, the Indian Cyber Crime Coordination Centre (I4C), has issued a warning about a sophisticated CEO impersonation fraud dubbed the "Boss Scam" that exploits hijacked WhatsApp accounts to deceive employees into transferring funds. Unlike traditional business email compromise (BEC) attacks, this scheme bypasses common red flags by compromising the actual accounts of senior executives.
How the Scam Works
- Initial Contact: Attackers pose as regulators, such as the Reserve Bank of India (RBI), sending urgent messages to CEOs or executives via email or WhatsApp. The messages claim a critical regulatory issue requires immediate action.
- Malware Deployment: A compressed ZIP file containing an executable (.exe) and a Dynamic Link Library (.dll) file is attached. When opened on a Windows device, the malware installs a Trojan dropper, hijacking the executive’s WhatsApp Web session tokens.
- Account Takeover: With access to the executive’s genuine WhatsApp account, fraudsters message finance teams, HR, or accounts personnel, instructing urgent transfers to attacker-controlled bank accounts.
- Psychological Manipulation: Requests are framed with urgency, authority, and secrecy phrases like "Handle this discreetly" or "I’m unavailable to talk" discourage verification. Fear of regulatory penalties further pressures victims into compliance.
Why It’s Effective
- Trust Exploitation: Messages originate from real executive accounts, making them appear legitimate.
- Targeted Victims: Finance teams, HR, and newer employees who may lack familiarity with company protocols are primary targets.
- Evolving Tactics: Cybercriminals are increasingly using AI-driven deepfakes and voice cloning to enhance impersonation. A recent case saw a multinational employee transfer $25 million after a deepfake video call.
Key Defenses
The I4C emphasizes that regulators never distribute compliance tools or updates via WhatsApp attachments. Organizations are advised to:
- Verify all urgent financial requests through direct phone calls, video calls, or in-person confirmation.
- Block unauthorized executable files and enforce software restriction policies on corporate devices.
- Implement dual-approval mechanisms for large transactions and conduct regular phishing awareness training.
As workplace communication shifts to messaging platforms, the scam underscores the need for strict verification protocols regardless of how legitimate a request may appear.
Indian Cyber Security Solutions (CyberSecOps Pvt.Ltd.) cybersecurity rating report: https://www.rankiteo.com/company/indian-cyber-security-solutions
"id": "IND1782246360",
"linkid": "indian-cyber-security-solutions",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'location': 'India', 'type': 'Indian Companies'}],
'attack_vector': ['Malware (Trojan dropper)',
'Social Engineering',
'WhatsApp Account Hijacking'],
'data_breach': {'file_types_exposed': ['ZIP', 'EXE', 'DLL']},
'description': 'India’s cybercrime watchdog, the Indian Cyber Crime '
'Coordination Centre (I4C), has issued a warning about a '
"sophisticated CEO impersonation fraud dubbed the 'Boss Scam' "
'that exploits hijacked WhatsApp accounts to deceive employees '
'into transferring funds. Unlike traditional business email '
'compromise (BEC) attacks, this scheme bypasses common red '
'flags by compromising the actual accounts of senior '
'executives.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'fraudulent transactions',
'operational_impact': 'Unauthorized fund transfers, disruption of '
'financial operations',
'systems_affected': ['WhatsApp Web sessions', 'Windows devices']},
'initial_access_broker': {'backdoors_established': 'WhatsApp Web session '
'token hijacking',
'entry_point': 'Malware-laden ZIP file posing as '
'regulatory communication',
'high_value_targets': ['CEOs',
'Executives',
'Finance teams',
'HR personnel']},
'lessons_learned': 'Regulators never distribute compliance tools or updates '
'via WhatsApp attachments. Strict verification protocols '
'are necessary for financial requests, regardless of the '
'communication channel.',
'motivation': ['Financial Gain'],
'post_incident_analysis': {'corrective_actions': ['Enhanced verification '
'protocols',
'Software restriction '
'policies',
'Dual-approval mechanisms',
'Phishing awareness '
'training'],
'root_causes': ['Lack of verification protocols '
'for financial requests',
'Execution of unauthorized '
'executable files',
'Social engineering tactics '
'exploiting urgency and '
'authority']},
'recommendations': ['Verify all urgent financial requests through direct '
'phone calls, video calls, or in-person confirmation.',
'Block unauthorized executable files and enforce software '
'restriction policies on corporate devices.',
'Implement dual-approval mechanisms for large '
'transactions.',
'Conduct regular phishing awareness training.'],
'references': [{'source': 'Indian Cyber Crime Coordination Centre (I4C)'}],
'response': {'containment_measures': ['Verification of urgent financial '
'requests via direct communication',
'Blocking unauthorized executable '
'files'],
'remediation_measures': ['Enforce software restriction policies '
'on corporate devices',
'Implement dual-approval mechanisms for '
'large transactions']},
'title': "Emerging 'Boss Scam' Targets Indian Companies via Hijacked WhatsApp "
'Accounts',
'type': 'CEO Impersonation Fraud (Boss Scam)',
'vulnerability_exploited': 'Lack of verification protocols for financial '
'requests, unauthorized executable file execution'}