top of page

आई4सी की चेतावनी: 'बॉस स्कैम' और फर्जी खाता विवरण फाइलों के जरिए व्हाट्सएप हैकिंग और वित्तीय धोखाधड़ी का खतरा I4CAlert, BossScam, CyberCrimePrevention

  • Aug 7
  • 5 min read


New Delhi:भारतीय गृह मंत्रालय के भारतीय साइबर अपराध समन्वय केंद्र (आई4सी) ने 'बॉस स्कैम' (सीईओ प्रतिरूपण धोखाधड़ी) और फर्जी नियामक संचारों को लेकर एक गंभीर राष्ट्रीय चेतावनी जारी की है। राष्ट्रीय साइबर अपराध रिपोर्टिंग पोर्टल (एनसीआरपी) पर दर्ज शिकायतों के अनुसार, कॉर्पोरेट कर्मियों, चार्टर्ड अकाउंटेंट (सीए), कंपनी निदेशकों, सीएफओ और वित्त टीमों को निशाना बनाकर बड़े पैमाने पर वित्तीय धोखाधड़ी की जा रही है। दिल्ली, गुजरात, महाराष्ट्र और राजस्थान सहित कई राज्यों से इस प्रकार के साइबर हमलों की सूचना मिली है।

I4CAlert, BossScam, CyberCrimePrevention

हमले का तरीका और मैलवेयर का प्रसार

धोखेबाज पीड़ितों को व्हाट्सएप, ईमेल या एसएमएस के माध्यम से 'Statement of Account.zip', 'RBI.zip' या 'MCA.zip' नाम से एक कंप्रेस्ड (.zip) फाइल भेजते हैं। संदेश में इसे आयकर विभाग, आरबीआई या कॉर्पोरेट कार्य मंत्रालय (MCA) का तत्काल अनुपालन या खाता विवरण बताकर खोलने का दबाव बनाया जाता है।I4CAlert, BossScam, CyberCrimePrevention

इस आर्काइव में एक दुर्भावनापूर्ण विंडोज निष्पादन योग्य (.exe) फाइल और एक डायनेमिक लिंक लाइब्रेरी (.dll) फाइल होती है। विंडोज कंप्यूटर पर इसे खोलते ही एक ट्रोजन इंस्टाल हो जाता है, जो डिवाइस को हैक कर व्हाट्सएप वेब सेशन को हाईजैक कर लेता है। इसके बाद, हैक किए गए खाते का उपयोग पीड़ित के संपर्कों और समूहों में वही फाइल अपने-आप भेजने के लिए किया जाता है, जिससे यह मैलवेयर पूरे कॉर्पोरेट नेटवर्क में फैल जाता है।

'बॉस स्कैम' का क्रियान्वयन

हमले के अंतिम चरण में, धोखेबाज किसी वरिष्ठ अधिकारी (सीईओ या एमडी) के हैक किए गए व्हाट्सएप खाते का उपयोग करते हैं—या हैक की गई डिवाइस में 'सीईओ' के नाम से अपना नंबर सहेज लेते हैं। इसके बाद लेखा और वित्त विभाग के कर्मचारियों को आपातकालीन आधार पर फर्जी बैंक खातों में धनराशि स्थानांतरित (फंड ट्रांसफर) करने का निर्देश दिया जाता है।

आई4सी द्वारा की गई कार्रवाई और सुरक्षात्मक कदम

आई4सी की राष्ट्रीय साइबर अपराध खतरा विश्लेषण इकाई (एनसीटीएयू) के अनुसार, यह अभियान अंतरराष्ट्रीय संगठित साइबर नेटवर्क द्वारा चलाया जा रहा है। इस खतरे से निपटने के लिए निम्नलिखित कदम उठाए गए हैं:

  • संभावित पीड़ितों को अलर्ट: आई4सी ने पिछले 30 दिनों में एसएमएस हेडर 'I4CMHA-G' के माध्यम से 58,000 से अधिक संभावित पीड़ितों को अलर्ट भेजा है।

  • इंटेलिजेंस शेयरिंग: मैलवेयर के तकनीकी संकेतों को सीईआरटी-इन (CERT-In), माइक्रोसॉफ्ट डिफेंडर और क्विक हील, के7 व नेट प्रोटेक्टर जैसी प्रमुख एंटीवायरस कंपनियों के साथ साझा किया गया है।

  • 10,000+ नागरिक सुरक्षित: 'सहयोग पोर्टल' के माध्यम से सी2 सर्वरों को जियो-ब्लॉक करके अब तक 10,000 से अधिक भारतीयों को इस साइबर हमले से बचाया जा चुका है।

सुरक्षा एवं बचाव हेतु आवश्यक दिशा-निर्देश

  1. अज्ञात फाइलों से बचें: अज्ञात या अपुष्ट स्रोतों से प्राप्त .zip, .exe या .dll फाइलों को कभी भी डाउनलोड, एक्सट्रैक्ट या ओपन न करें। आरबीआई या अन्य नियामक संस्थाएं कभी भी व्हाट्सएप अटैचमेंट के जरिए सॉफ्टवेयर अपडेट या फाइलें नहीं भेजती हैं।

  2. लिंक्ड डिवाइसेज की जांच: व्हाट्सएप सेटिंग्स (Settings > Linked Devices) में जाकर नियमित समीक्षा करें और अनावश्यक या संदिग्ध व्हाट्सएप वेब सेशन से तुरंत लॉग आउट करें।

  3. वित्तीय निर्देशों का सत्यापन: व्हाट्सएप या ईमेल पर मिलने वाले किसी भी तत्काल फंड ट्रांसफर निर्देश या खाता बदलाव अनुरोध पर कार्रवाई करने से पहले संबंधित अधिकारी से वॉइस कॉल या व्यक्तिगत रूप से पुष्टि करें।

  4. आईटी और सिस्टम सुरक्षा: आईटी एडमिनिस्ट्रेटर उपयोगकर्ता प्रोफ़ाइल से अज्ञात .exe और .dll फाइलों के निष्पादन को ब्लॉक करने के लिए सॉफ्टवेयर प्रतिबंध नीतियां लागू करें और सिस्टम में अपडेटेड एंटी-मैलवेयर का उपयोग करें।

  5. अकाउंट हैक होने पर त्वरित कदम: यदि खाता हैक हो जाए, तो तुरंत सभी लिंक्ड डिवाइसेज से लॉग आउट करें, अपने संपर्कों को सूचित करें और सिस्टम को अपडेटेड एंटीवायरस से स्कैन करें।

किसी भी प्रकार की साइबर धोखाधड़ी या संदिग्ध संचार की सूचना तुरंत राष्ट्रीय साइबर अपराध हेल्पलाइन नंबर 1930 पर दें या www.cybercrime.gov.in पर रिपोर्ट दर्ज करें।








I4C Warning: WhatsApp Hacking and Financial Fraud Risk via 'Boss Scam' and Fake Account Statement Files





New Delhi:The Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs has issued a critical national advisory regarding 'Boss Scam' (CEO Impersonation Fraud) and fake regulatory communications. According to complaints registered on the National Cyber Crime Reporting Portal (NCRP), high-value financial fraud is targeting corporate employees, Chartered Accountants (CAs), company directors, CFOs, and finance teams. Similar cyberattacks have been reported across multiple states, including Delhi, Gujarat, Maharashtra, and Rajasthan.

Modus Operandi and Malware Propagation

Fraudsters send compressed (.zip) files named Statement of Account.zip, RBI.zip, or MCA.zip via WhatsApp, email, or SMS. The accompanying message pressures the victim to open the file under the guise of an urgent compliance notice or account statement from the Reserve Bank of India (RBI), Ministry of Corporate Affairs (MCA), or Income Tax Department.

The archive contains a malicious Windows Executable (.exe) file and a Dynamic Link Library (.dll) file. Opening this file on a Windows desktop or laptop installs a Trojan that compromises the device and hijacks active WhatsApp Web sessions. The hijacked account is then automatically used to propagate the malicious file to the victim's contacts and groups, infecting the broader corporate network.

Execution of the 'Boss Scam'

In the final stage of the attack, fraudsters leverage the hijacked WhatsApp account of a senior executive (CEO or MD)—or secretly save an attacker-controlled number as "CEO" on the compromised device. They then instruct finance and accounting personnel to urgently transfer funds to fraudulent bank accounts.

Actions Taken by I4C and Preventive Measures

According to technical analysis by I4C’s National Cyber Threat Analytics Unit (NCTAU), this campaign is operated by organized international networks using advanced malware. The following countermeasures have been implemented:

  • Alerts to Potential Victims: I4C has alerted over 58,000 potential victims in the past 30 days via SMS under the header 'I4CMHA-G'.

  • Intelligence Sharing: Threat indicators and technical signatures have been shared with CERT-In, Microsoft Defender, and leading Indian antivirus firms (Quick Heal, K7 Computing, Net Protector) to block and isolate the malicious files.

  • 10,000+ Citizens Protected: Over 10,000 citizens have been shielded from this campaign by geo-blocking C2 servers via the Sahyog portal.

Advisory Guidelines for Security and Safety

  1. Avoid Unverified Files: Do not download, extract, or open .zip, .exe, or .dll files from unknown or unverified sources. Regulatory bodies like the RBI never distribute software updates, fixes, or account statements via WhatsApp attachments.

  2. Inspect Linked Devices: Regularly check WhatsApp settings (Settings > Linked Devices) and immediately log out of any inactive or unrecognized WhatsApp Web sessions.

  3. Verify Financial Instructions: Independently confirm any urgent fund transfer or bank account modification request received via WhatsApp or email through a direct voice call or in-person verification before executing the transaction.

  4. IT Infrastructure Security: System administrators should enforce Software Restriction Policies to block unknown .exe and .dll execution from user profile directories and ensure all endpoints run updated anti-malware solutions.

  5. Immediate Steps Upon Account Compromise: If an account is hacked, immediately log out from all linked devices, notify contacts not to open any files sent from the account, and run a complete antivirus scan on the computer.

Report any cyber fraud or suspicious communication immediately to the National Cyber Crime Helpline number 1930 or log a complaint at www.cybercrime.gov.in.

Top Stories

1/15
bottom of page