عاجل
DENeue Partei in der Türkei gegründet: Özgür Özel führt „Yeni Parti“DETrump droht EU mit hohen Zöllen nach Google-StrafeDEKI-Brechaufklärung: Open AIs Modell brach durch Sicherheitslücken ins InternetDEOpen AI: KI-Modelle brechen aus Testumgebung aus und verüben HackingangriffDEChefankläger des Internationalen Strafgerichtshofes entlassenDETrump kündigt Zölle gegen Mexiko und Kanada an - Kanada wehrt sich mit Alleingang bei BrückeneinweihungDEKabinettsumbau sorgt für Kritik an Merz und LinnemannDEIStGH-Mitgliedstaaten stimmen für Abberufung von Karim Khan als ChefanklägerDEDeutschlands Exportmodell in schwierigen Zeiten: US-Präsident erschüttert Weltwirtschaft mit neuem HandelsinstrumentDEGordie-Howe-Brücke eröffnet: Symbol der Partnerschaft in angespannter ZeitDENeue Partei in der Türkei gegründet: Özgür Özel führt „Yeni Parti“DETrump droht EU mit hohen Zöllen nach Google-StrafeDEKI-Brechaufklärung: Open AIs Modell brach durch Sicherheitslücken ins InternetDEOpen AI: KI-Modelle brechen aus Testumgebung aus und verüben HackingangriffDEChefankläger des Internationalen Strafgerichtshofes entlassenDETrump kündigt Zölle gegen Mexiko und Kanada an - Kanada wehrt sich mit Alleingang bei BrückeneinweihungDEKabinettsumbau sorgt für Kritik an Merz und LinnemannDEIStGH-Mitgliedstaaten stimmen für Abberufung von Karim Khan als ChefanklägerDEDeutschlands Exportmodell in schwierigen Zeiten: US-Präsident erschüttert Weltwirtschaft mit neuem HandelsinstrumentDEGordie-Howe-Brücke eröffnet: Symbol der Partnerschaft in angespannter Zeit
Newsgather
رجوعCybercriminals Use 'Boss Scam' to Defraud Companies via Malware
Cybercriminals Use 'Boss Scam' to Defraud Companies via Malware
يتطور
Economic Times22‏/6‏/2026Crime2 د قراءةIndia

Cybercriminals Use 'Boss Scam' to Defraud Companies via Malware

نظرة سريعة

  • Cybercriminals are using a 'Boss Scam' to defraud companies by impersonating regulators and sending malicious files that hijack WhatsApp sessions, tricking employees into fraudulent financial transfers.
  • The Indian Cyber Crime Coordination Centre (I4C) advises verifying urgent financial requests through multiple channels.

ملخص مُنشأ بالذكاء الاصطناعي

حجم الخط

Cybercriminals are employing a new 'Boss Scam' to defraud companies. Impersonating regulators, they send malicious files via email or WhatsApp to executives, claiming urgent compliance needs. Once opened on Windows devices, the malware hijacks WhatsApp sessions, allowing fraudsters to trick employees into making fraudulent financial transfers. Companies are urged to verify urgent financial requests through multiple channels, not just text or email.

New Delhi: The Indian Cyber Crime Coordination Centre (I4C), under the union home ministry, on Monday said it has observed an emerging trend in cybercrime referred to as the 'Boss Scam' or CEO impersonation fraud.

Cybercriminals are targeting high-ranking officials and executives by delivering malicious archives via email or WhatsApp under the guise of urgent regulatory compliance. Once executed, the malware compromises the executive's Windows device and active Web WhatsApp sessions, enabling fraudsters to message subordinate employees and orchestrate fraudulent financial transfers, according to I4C.

Also Read: What is ‘WhatsApp Screen Mirroring Fraud’ that can drain your bank account and lead to identity theft?

While sharing the modus operandi, I4C noted that sophisticated cybercriminals contact CEO or high-ranking officials via email or WhatsApp, impersonating regulators such as the Reserve Bank of India. The communication falsely claims regulatory violation or mandates an urgent security improvement, demanding a response within a very short timeframe.

The message purportedly contains a compressed . zip archive. Inside this archive is a malicious executable (. exe) accompanied by a Dynamic Link Library (. dll) file. As seen in multiple cases, the CEO forwards the message to the finance officer. Upon receiving the message, the executive extracts and executes the file on a Windows desktop or laptop, a Trojan dropper is initiated. The malware establishes a persistent foothold, compromises the system, and hijacks the active Web WhatsApp session tokens, the I4C said in an advisory.

Live Events

Also Read: PSBs told to tighten scrutiny of government accounts amid fraud concerns

It said finance departments of the companies should verify the request of any urgent financial transactions or account changes based solely on a WhatsApp text or email.

مواضيع ذات صلة

This article was originally published by Economic Times.

أخبار ذات صلة

المزيد حول هذا الموضوعcybercrime