India’s Ministry of Home Affairs is warning finance teams that a Windows infection can now turn a senior executive’s genuine WhatsApp account into the delivery channel for a fraudulent payment order. The campaign, described by the Indian Cyber Crime Coordination Centre as the “Boss Scam,” starts with a malicious ZIP archive masquerading as a regulatory or financial document and ends with urgent instructions to transfer money to mule accounts.

The immediate action for Windows administrators is straightforward: treat this as an endpoint-execution and payment-authorization problem, not merely a WhatsApp phishing problem. The I4C’s own advisory says the malware is delivered as a ZIP containing an executable and a DLL, is run on a Windows desktop or laptop, and then steals an active WhatsApp Web session. A finance employee who sees a request from the executive’s real account is therefore not seeing the usual crude impersonation signal.

The warning was detailed in an official Ministry of Home Affairs release published June 22, 2026, and reported at the time by The Economic Times and Moneycontrol. The New Indian Express report published August 7 presents it as a renewed nationwide warning amid rising complaints, but the public MHA release does not publish complaint totals, confirmed loss figures, victim organizations, or a state-by-state breakdown. It also does not identify the malware family, hashes, command-and-control infrastructure, or indicators that administrators can hunt for.

That gap matters. There is enough in the official account to justify immediate hardening, but not enough to establish the claimed scale of the campaign or to turn the I4C description into a reliable set of detection signatures.


Cybersecurity analysts monitor a blocked malware file and suspicious payment request across multiple screens.The attack abuses the trust in a live WhatsApp account​

According to the MHA release, attackers pose as regulators such as the Reserve Bank of India and claim that an executive’s organization faces a compliance issue or must install an urgent security update. The message arrives through email or WhatsApp and carries a compressed archive, usually presented as a document that must be reviewed quickly.

The archive contains an

.exe

file alongside a DLL. Once the recipient extracts and runs the executable, the agency says a Trojan dropper establishes persistence on the Windows device and hijacks active WhatsApp Web session tokens. The attackers can then message subordinates from the compromised executive account and demand an immediate transfer.

This is the material change from ordinary CEO fraud. A typical business email compromise attack depends on a lookalike domain, a spoofed display name, or a newly registered phone number. Those can be caught by a careful employee or an email-security gateway. In this case, the sender identity may be technically authentic because the attacker is operating within the executive’s existing WhatsApp session.

The MHA also described a second path that deserves attention from endpoint teams: if attackers obtain fuller control of the Windows device, they may edit local contact records so that an attacker-operated number is stored under the executive’s name. The resulting fraud does not need a persistent takeover of the original account. It only needs the victim’s contact list to mislead the finance employee at the moment a transfer is requested.

Neither version defeats a bank control on its own. Both exploit organizations that allow a WhatsApp message to act as final authorization for a high-value payment or a beneficiary-account change.


DLL sideloading is a warning that signatures alone may be too late​

The submitted reporting says the campaign uses DLL sideloading to evade detection. The official MHA release confirms the key ingredients — a malicious executable and a DLL in the same ZIP file — though it does not name the legitimate application allegedly abused for sideloading or publish a technical analysis of the loader.

DLL sideloading works by placing a malicious library where a legitimate executable will load it under an expected filename. Windows applications frequently rely on DLLs, and attackers take advantage of that normal behavior to make a trusted or signed process launch attacker-controlled code. The technique does not require a Windows vulnerability; it depends on a user being persuaded to execute the supplied program and on security controls permitting it.

That distinction is important for patch management. Updating Windows and WhatsApp remains necessary, but it is not the primary remediation described by the MHA advisory. The initial compromise occurs when a recipient extracts and runs an untrusted executable. An organization that treats unsolicited “Statement of Account,” “RBI,” “MCA,” or tax-related ZIP files as routine documents has already given the attacker the opening needed.

A separate CERT-In alert, published June 25, reinforces the broader pattern but should not be confused with the Boss Scam’s specific payload. CERT-In warned of a large-scale WhatsApp Desktop and WhatsApp Web campaign distributing malicious VBScript files disguised as invoices, bank statements, payment records, and account statements. That campaign downloads further scripts and installs remote-management tooling. It validates the delivery channel and the business-document lures, but it is technically distinct from the ZIP-and-DLL chain described in the MHA notice.

For defenders, the shared conclusion is more useful than an unsupported claim that every WhatsApp attachment belongs to one operation: compromised accounts are being used to push Windows-executable content through a channel many organizations still consider informal and low risk.


Payment controls, not user suspicion, must break the fraud chain​

The MHA’s recommended control is out-of-band verification: finance departments should verify urgent transactions and account changes through a direct voice call or in-person confirmation rather than relying on a WhatsApp message or email. That should be translated into a written payment-control requirement, not an awareness-training suggestion.

A call placed using a number supplied in the suspicious message is not independent verification. A finance employee must use a number from a trusted company directory, an approved payment workflow, or a pre-established executive contact list that is not editable from the same compromised Windows endpoint. For large or unusual transfers, organizations should require two approvals from people using separate communications channels.

The policy should also explicitly cover changes to beneficiary details. Fraud campaigns frequently use the “urgent payment” message as the visible event, but a quietly altered account number can be equally damaging if it bypasses the normal supplier-verification process. The MHA’s contact-manipulation variant is a reminder that a familiar name on a handset is not proof of identity.

For IT leaders, the operational consequence is that finance, security, and endpoint-management teams need one incident playbook. A WhatsApp takeover is not solely a mobile-device issue, a Windows malware alert is not solely a SOC issue, and a wire-transfer request is not solely an accounts-payable decision. The attack crosses all three controls in minutes.


Windows controls should focus on execution from user-writable locations​

The MHA specifically advises administrators to use Software Restriction Policies to block unknown

.exe

and

.dll

files from user-profile directories. That is a sensible baseline for this attack chain because downloaded archives are commonly extracted into Downloads, Desktop, AppData, Temp, or other user-writable paths rather than approved application directories.

For managed Windows environments, Microsoft’s App Control for Business and AppLocker can enforce allowlisting policies for executables, scripts, installers, and DLLs. App Control’s practical value here is that it shifts the question from whether an antivirus engine recognizes a new loader to whether the device is permitted to run that code at all. Organizations should begin in audit mode, identify legitimate exceptions, then move finance workstations and executive endpoints toward enforcement rather than deploying broad exclusions that recreate the original risk.

Microsoft Defender Attack Surface Reduction rules also fit the adjacent threat pattern. Microsoft documents rules that block executable content from email clients and webmail, block potentially obfuscated scripts, block JavaScript or VBScript from launching downloaded executable content, and restrict executable files that do not meet prevalence, age, or trusted-list criteria. They must be tested in audit mode before broad enforcement, particularly in organizations with older finance or accounting applications, but the I4C campaign is precisely the sort of user-driven execution path these controls were designed to constrain.

Security teams should immediately review whether executives who use WhatsApp Web have local administrator rights, whether they can run arbitrary executables from Downloads and AppData, and whether endpoint telemetry retains process-launch and DLL-load events. A file opened from a ZIP archive, followed by an unfamiliar executable and a browser or WhatsApp Web session anomaly, should be investigated as an endpoint compromise rather than handled as a simple account-reset ticket.


The fastest containment step is to assume the Windows device is compromised​

If an executive has opened a suspicious ZIP or executable, logging out of WhatsApp Web alone is insufficient. The MHA recommends reviewing WhatsApp’s Linked Devices list and terminating inactive or unknown web sessions, but the advisory also says the malware establishes a persistent foothold on the Windows system. The device must therefore be isolated, triaged, and reimaged or remediated according to the organization’s incident-response standard before the user resumes financial communications.

The response should include a review of recently sent WhatsApp messages, affected groups, contact changes, payment instructions, mailbox activity, and any files forwarded by the compromised account. Finance teams must be told that previous transfer instructions from that account may be fraudulent, not merely future messages. Banks and internal payment approvers should be alerted before attackers can cash out through mule accounts.

The MHA says regulators such as the RBI will not distribute mandatory software updates or security fixes through WhatsApp attachments. That is a useful employee-facing rule, but the stronger operational rule is simpler: no payment instruction received through WhatsApp, including one from a real executive account, authorizes a transfer by itself.

The August reporting may have revived attention to the Boss Scam, but the underlying government warning has been public since June 22. The evidence does not yet show how many organizations have been hit. It does show exactly where the attack can be stopped: prevent untrusted code from running on Windows, terminate compromised linked sessions, and require an independently verified approval before money leaves the company.


References​

  1. Primary source: newindianexpress.com
    Published: August 7, 2026 at 2:14 PM UTC
  2. Related coverage: ministryofcyberaffairs.com
  3. Related coverage: tech.getinfotoyou.com
  4. Related coverage: hendryadrian.com
  5. Related coverage: informacje.wp.pl
  6. Related coverage: economictimes.indiatimes.com
  7. Related coverage: economictimes.indiatimes.com
  8. Related coverage: outlookmoney.com
  9. Related coverage: dailypioneer.com
  10. Related coverage: moneycontrol.com
  11. Related coverage: stateoig.gov
  12. Related coverage: ncsc.gov.ie
  13. Related coverage: kaspersky.com
  14. Related coverage: newsbytesapp.com
  15. Related coverage: thestar.com.my
  16. Related coverage: nvd.nist.gov
  17. Related coverage: techradar.com
  18. Related coverage: techradar.com
  19. Related coverage: itpro.com
  20. Related coverage: learn.microsoft.com
  21. Related coverage: learn.microsoft.com