Skip to main content

The WhatsApp 'Boss Scam' Explained: How a Single ZIP File Can Drain Your Company's Bank Account

The WhatsApp 'Boss Scam' Explained: How a Single ZIP File Can Drain Your Company's Bank Account

A new WhatsApp fraud is hijacking executives' accounts and tricking finance teams into wiring crores to fraudsters. Here's exactly how the 'Boss Scam' works, real cases, and how to protect your business in 2026.

An Ahmedabad real estate businessman named Pravin received a WhatsApp message one June morning that looked entirely routine  a notification claiming to be from the Reserve Bank of India, warning about unusual transactions on his company's account and requesting urgent cooperation from his finance department. It looked official. It referenced real regulatory language. It asked for exactly the kind of response a genuine compliance notice might require. It was completely fake, and it was the opening move in a fraud that has already cost Indian businesses crores of rupees.

This is the "Boss Scam," a rapidly spreading WhatsApp fraud that India's Cyber Crime Coordination Centre (I4C) has issued formal warnings about after cases surfaced across Delhi, Gujarat, Maharashtra, and Rajasthan. Unlike older impersonation scams that relied on crude fake profiles, this one hijacks a genuine executive's actual WhatsApp account, making the fraud significantly harder to detect. Here's exactly how it works and what every business needs to know to avoid becoming the next case study.

How the Boss Scam Actually Works, Step by Step
Step 1: The Bait Arrives as a Routine Compliance File
The scam begins with what looks like an entirely ordinary message  a ZIP file arriving via WhatsApp, SMS, or email, with an innocuous name like "Statement of Account.zip," "RBI.zip," or "MCA.zip," designed to appear as if it comes from the Reserve Bank of India, the Ministry of Corporate Affairs, or the Income Tax Department.

Step 2: Opening the File Installs Hidden Malware
When the file is extracted and opened on a Windows computer, it triggers a Trojan dropper containing a malicious executable file alongside a supporting DLL file. According to I4C's technical analysis, the malware specifically uses a technique called DLL sideloading, which helps it evade standard antivirus detection while silently installing itself on the victim's system.

Step 3: The Malware Hijacks the Active WhatsApp Web Session
Once installed, the malware compromises the victim's computer and specifically targets their active WhatsApp Web session, effectively giving the attacker control over the victim's genuine, verified WhatsApp account  not a lookalike or spoofed number, but the actual account itself.

Step 4: The Compromised Account Spreads the Infection Further
The hijacked account then automatically forwards the same malicious file to the victim's contacts and WhatsApp groups, frequently accompanied by a message specifically asking the recipient to forward it to their company's finance manager for verification and to open it on a desktop computer  a deliberate mechanism designed to spread the infection deeper into corporate networks and financial teams specifically.

Step 5: The CEO Impersonation Phase Begins
In its most advanced and financially damaging stage, attackers use the genuine, hijacked WhatsApp account of a senior executive  or in some cases, covertly save an attacker-controlled number under the executive's name within the compromised device  to contact accounts and finance employees directly, instructing them to make urgent, unauthorized payments to what are ultimately mule bank accounts controlled by the fraud network.

Why This Version Is More Dangerous Than Typical CEO Fraud
Traditional CEO impersonation scams have existed for years, typically relying on a fake number or a spoofed email address designed to look similar to a real executive's contact details. What makes the Boss Scam significantly more dangerous is that it doesn't require creating a convincing fake  it hijacks the actual, genuine, previously-verified account of the real executive, meaning the message genuinely does arrive from a phone number and account that finance employees have communicated with before and have every reason to trust.

A Delhi Police cybercrime officer noted that these are high-value scams primarily targeting businesspeople, with much of the operational infrastructure run from outside India, while only the mule accounts used for cash withdrawal are based domestically  indicating a level of cross-border organization that goes well beyond opportunistic, low-effort fraud.

Who Is Being Specifically Targeted
I4C's advisory identifies a clear pattern in who these attacks are aimed at, and it isn't random consumers:
Chartered accountants, who routinely handle sensitive financial documentation and are accustomed to receiving compliance-related files
Company directors, whose authority makes their instructions carry significant weight with finance teams
Chief Financial Officers (CFOs), who are directly positioned to authorize large fund transfers
Finance and accounts teams broadly, who are trained to respond quickly to instructions from senior leadership, particularly around regulatory compliance matters

This targeting pattern reflects a deliberate strategy  rather than casting a wide net toward random individuals, the scam specifically pursues roles with direct authority over company funds and a professional obligation to respond promptly to what appears to be urgent regulatory correspondence.

The Real Financial Damage Already Documented
Cases following this exact pattern have resulted in significant losses, with reports describing incidents involving transfers of ₹1.5 crore or more from a single compromised executive account, executed through instructions that finance employees had no clear reason to doubt at the time, given that the messages arrived from a genuine, previously trusted WhatsApp account. I4C first flagged this specific threat pattern in a June 22, 2026 advisory, and the fact that fresh cases across multiple states prompted a renewed warning in August indicates the fraud network remains active and continues finding new targets.

Official Warning Signs and Red Flags
Any ZIP file or executable program arriving via WhatsApp, SMS, or email claiming to be from a regulatory body  the Reserve Bank of India, the Ministry of Corporate Affairs, or the Income Tax Department never distribute software updates, account statements, or compliance notices through WhatsApp attachments
Urgent payment or verification requests tied to a compressed file requiring extraction and execution on a computer  this specific technical requirement is central to how the malware spreads and should immediately raise suspicion
A message from a known contact's WhatsApp account requesting the file be forwarded to a finance manager or opened on a desktop specifically  this unusual, specific instruction is a deliberate propagation mechanism, not a normal communication pattern
Payment instructions arriving via WhatsApp from a senior executive that deviate from established company payment verification protocols, even when the account itself appears completely genuine

How Businesses Can Protect Themselves
Never Open Unsolicited ZIP Files or Executable Attachments
Regulators including the RBI never distribute official communications, statements, or software updates through WhatsApp attachments. Any file matching this pattern, regardless of how official it appears, should be treated as a threat and reported rather than opened.

Regularly Audit Linked WhatsApp Devices
Checking WhatsApp's linked devices setting periodically and logging out of any unfamiliar or inactive sessions helps limit the window during which a hijacked Web session can be exploited, and can help identify a compromise before significant damage occurs.

Implement Independent Verification for Any Fund Transfer Instruction
Regardless of how urgent or authoritative a payment instruction appears, and regardless of which channel it arrives through, businesses should maintain a strict policy requiring independent, out-of-band verification  a direct phone call to a known number, not a reply to the same message thread  before executing any significant fund transfer.

Deploy Software Restriction Policies on Corporate Systems
System administrators are specifically advised to implement policies blocking unknown executable and DLL files from running in user directories, alongside ensuring all Windows systems maintain updated anti-malware protection capable of detecting this specific attack pattern.

Train Finance Teams Specifically on This Threat Pattern
Because this scam specifically targets finance professionals and executives with a plausible, well-disguised compliance narrative, targeted training that walks through the exact mechanics of this fraud  rather than generic cybersecurity awareness  significantly improves the odds that an employee recognizes the pattern before opening a malicious file or acting on a fraudulent instruction.

What to Do If Your Account Is Already Compromised
Immediately log out of all linked WhatsApp devices through the app's settings menu to cut off the attacker's access to the active session.
Inform your contacts directly through another channel not to open any files recently sent from your account, since the malware automatically propagates through your existing contact list.
Run a full scan using updated anti-malware software on any computer where the file may have been opened.
Report the incident immediately through India's National Cyber Crime Helpline at 1930 or the National Cyber Crime Reporting Portal, particularly if any unauthorized fund transfers have already occurred.

What This Reveals About the Evolving Nature of Corporate Fraud
The Boss Scam represents a meaningful evolution in how financial fraud targets businesses  moving away from crude impersonation toward genuinely hijacking trusted communication channels themselves. This shift matters because it defeats one of the most commonly recommended fraud-prevention habits: checking whether a message is coming from a known, verified contact. In this scam, it genuinely is, which is precisely what makes independent, out-of-band verification protocols  rather than simply trusting the apparent source of a message  an increasingly essential safeguard for any business handling significant fund transfers.

Frequently Asked Questions (FAQs)
Q1: What is the WhatsApp 'Boss Scam'?
It's a cyber fraud where criminals compromise a senior executive's actual WhatsApp account through malware, then use that genuine account to instruct finance employees to transfer money to fraudulent mule bank accounts.
Q2: How does the malware initially infect a device?
It arrives as a ZIP file disguised as a regulatory document from bodies like the RBI or Ministry of Corporate Affairs; opening and extracting it on a Windows computer installs malware that hijacks the active WhatsApp Web session.
Q3: Which states have reported Boss Scam cases?
Cases following this pattern have been reported in Delhi, Gujarat, Maharashtra, and Rajasthan, according to India's Cyber Crime Coordination Centre.
Q4: Who is most at risk from this scam?
Chartered accountants, company directors, CFOs, and finance and accounts teams are specifically identified as primary targets, given their authority over and access to company funds.
Q5: What should a business do if it receives a suspicious payment instruction via WhatsApp?
Independently verify the instruction through a direct phone call to a known, trusted number rather than replying within the same WhatsApp thread, regardless of how urgent or legitimate the message appears.

Conclusion
The Boss Scam illustrates how cybercriminals are increasingly targeting trust itself rather than simply attempting to impersonate it  hijacking genuine, verified accounts rather than creating convincing fakes. With cases actively spreading across multiple Indian states and I4C issuing repeated advisories as the threat evolves, businesses that rely on WhatsApp for internal communication need to treat unsolicited compliance-themed attachments with the same suspicion as any other unverified financial instruction, and build independent verification into their payment approval process regardless of how legitimate the source appears to be.

Comments

Popular posts from this blog

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late

AI Job Scams in 2026: 7 Red Flags Every Job Seeker Must Know Before It's Too Late AI-powered job scams have pushed losses past $500 million as deepfake recruiters and fake offer letters flood LinkedIn and email inboxes. Here are the 7 red flags that still expose them in 2026, and what to do if you've already been targeted. For years, job seekers were told that bad grammar and awkward phrasing were the easiest way to spot a fake recruiter. That advice no longer holds. Generative AI can now produce outreach messages, offer letters, and even live video interviewers that are functionally indistinguishable from the real thing. Reported losses from job search fraud jumped from $90 million in 2020 to more than $500 million in 2024, and industry researchers project that by 2028, roughly one in four candidate profiles circulating online will be entirely fake. This isn't a distant future risk  it's actively reshaping how hiring works right now, targeting new graduates...

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It

The New UPI Scam That's Draining Bank Accounts in Seconds: How It Works and How to Spot It UPI fraud has surged as scammers exploit fake customer care numbers, QR codes, and screen-sharing apps. Here's exactly how India's most common UPI scams work in 2026, real cases, and the 3-day rule that could save your money. A Bihar grocer lost ₹58,000 from his bank account without clicking a single link or receiving a single call. A Chennai user complained about a failed transaction on Twitter and had ₹1.8 lakh drained from his SBI account within minutes, after a fake "Paytm Care" account responded to his post and talked him into installing a screen-sharing app. A Jaipur street vendor scanned a QR code a "customer" sent him to receive payment  and instead authorized a debit. None of these victims were reckless. All of them fell for scams built around a simple, unchanging truth about UPI: the system is instant, irreversible, and requires the victim...

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026

AI-Generated Investment Scams: How Fake Crypto Platforms Are Stealing Billions in 2026 Every year, artificial intelligence gets better at doing useful things  writing code, analyzing data, generating images. Unfortunately, scammers have been paying just as much attention to these advances as legitimate businesses have, and in 2026, they've turned AI into the most effective fraud tool the financial world has ever seen. What used to be obvious, badly-written scam emails have evolved into polished trading platforms with real-looking dashboards, AI-generated "proof" of returns, and even deepfake videos of celebrities and CEOs vouching for products that don't exist. The result is a wave of losses running into the billions of dollars, hitting everyone from retirees to tech-savvy young professionals who assumed they were too smart to fall for it. Understanding exactly how these scams work  not just that they exist  is the difference between recognizing one in the...