Última hora
EUHouthis, Backed by Iran, Plan to Charge Ships Transiting Bab el-Mandeb, Threatening Global Energy MarketsRUSaudi Arabia's Abqaiq Oil Facility Damaged in Drone StrikeINTLBerlin Pride Attack Sparks Debate on Islamism and Queer HostilityDEKI von OpenAI brach in Systeme einer anderen Firma ein - Zwei Fälle bekanntINTLLebanon's Pilot Zone Plan Faces Skepticism Amid Ongoing Israeli OccupationCN中国商务部驳斥美国AI技术窃取指控TRGülistan Doku Soruşturmasında Bomba İddialar: 'Kızı Öldürdü, Babası Halletti'DESophie Brocas: Die Präfektin, die dem Atlantik-Feuer ein Gesicht gibtRUПрезидент Казахстана призвал Путина остановить войну в УкраинеRUДжаред Лето обвинили в сексуальных преступлениях: 10 женщин рассказали о своих историяхEUHouthis, Backed by Iran, Plan to Charge Ships Transiting Bab el-Mandeb, Threatening Global Energy MarketsRUSaudi Arabia's Abqaiq Oil Facility Damaged in Drone StrikeINTLBerlin Pride Attack Sparks Debate on Islamism and Queer HostilityDEKI von OpenAI brach in Systeme einer anderen Firma ein - Zwei Fälle bekanntINTLLebanon's Pilot Zone Plan Faces Skepticism Amid Ongoing Israeli OccupationCN中国商务部驳斥美国AI技术窃取指控TRGülistan Doku Soruşturmasında Bomba İddialar: 'Kızı Öldürdü, Babası Halletti'DESophie Brocas: Die Präfektin, die dem Atlantik-Feuer ein Gesicht gibtRUПрезидент Казахстана призвал Путина остановить войну в УкраинеRUДжаред Лето обвинили в сексуальных преступлениях: 10 женщин рассказали о своих историях
Newsgather
AtrásCybercriminals Use 'Boss Scam' to Defraud Companies via Malware
Cybercriminals Use 'Boss Scam' to Defraud Companies via Malware
En desarrollo
Economic Times22/6/2026Crime2 min de lecturaIndia

Cybercriminals Use 'Boss Scam' to Defraud Companies via Malware

En resumen

  • Cybercriminals are using a 'Boss Scam' to defraud companies by impersonating regulators and sending malicious files that hijack WhatsApp sessions, tricking employees into fraudulent financial transfers.
  • The Indian Cyber Crime Coordination Centre (I4C) advises verifying urgent financial requests through multiple channels.

Resumen generado por IA

Tamaño de fuente

Cybercriminals are employing a new 'Boss Scam' to defraud companies. Impersonating regulators, they send malicious files via email or WhatsApp to executives, claiming urgent compliance needs. Once opened on Windows devices, the malware hijacks WhatsApp sessions, allowing fraudsters to trick employees into making fraudulent financial transfers. Companies are urged to verify urgent financial requests through multiple channels, not just text or email.

New Delhi: The Indian Cyber Crime Coordination Centre (I4C), under the union home ministry, on Monday said it has observed an emerging trend in cybercrime referred to as the 'Boss Scam' or CEO impersonation fraud.

Cybercriminals are targeting high-ranking officials and executives by delivering malicious archives via email or WhatsApp under the guise of urgent regulatory compliance. Once executed, the malware compromises the executive's Windows device and active Web WhatsApp sessions, enabling fraudsters to message subordinate employees and orchestrate fraudulent financial transfers, according to I4C.

Also Read: What is ‘WhatsApp Screen Mirroring Fraud’ that can drain your bank account and lead to identity theft?

While sharing the modus operandi, I4C noted that sophisticated cybercriminals contact CEO or high-ranking officials via email or WhatsApp, impersonating regulators such as the Reserve Bank of India. The communication falsely claims regulatory violation or mandates an urgent security improvement, demanding a response within a very short timeframe.

The message purportedly contains a compressed . zip archive. Inside this archive is a malicious executable (. exe) accompanied by a Dynamic Link Library (. dll) file. As seen in multiple cases, the CEO forwards the message to the finance officer. Upon receiving the message, the executive extracts and executes the file on a Windows desktop or laptop, a Trojan dropper is initiated. The malware establishes a persistent foothold, compromises the system, and hijacks the active Web WhatsApp session tokens, the I4C said in an advisory.

Live Events

Also Read: PSBs told to tighten scrutiny of government accounts amid fraud concerns

It said finance departments of the companies should verify the request of any urgent financial transactions or account changes based solely on a WhatsApp text or email.

Temas relacionados

This article was originally published by Economic Times.

Noticias relacionadas

जुनैद की कहानी: जंतर-मंतर पर खाना बांटने वाले की अवैध हिरासत की दावेदारी
Crime·hace 2 horas

जुनैद की कहानी: जंतर-मंतर पर खाना बांटने वाले की अवैध हिरासत की दावेदारी

जुनैद, जो जंतर-मंतर पर प्रदर्शनकारियों के लिए खाना बांट रहे थे, का दावा है कि दिल्ली पुलिस ने उन्हें अवैध हिरासत में रखा और उनके परिवार को परेशान किया।

BBC हिंदी
6 min de lectura
बिहार सरकार ने नीट प्रदर्शनकारियों पर मुक़दमे वापस लेने की घोषणा की, लेकिन गिरफ़्तार छात्रों की रिहाई पर अभी भी संदेह
En desarrollo·ayer

बिहार सरकार ने नीट प्रदर्शनकारियों पर मुक़दमे वापस लेने की घोषणा की, लेकिन गिरफ़्तार छात्रों की रिहाई पर अभी भी संदेह

बिहार सरकार ने 27 जुलाई को नीट प्रदर्शनकारियों पर दर्ज मुक़दमे वापस लेने की घोषणा की, लेकिन गिरफ़्तार छात्रों की रिहाई पर अभी भी संदेह है। पटना हाई कोर्ट में महाधिवक्ता कार्यालय ने ज़िलाधिकारियों और पब्लिक प्रॉसिक्यूटर्स को निर्देश दिया है।

BBC हिंदी
23 min de lectura
बिहार: पूर्व मंत्री तेज प्रताप यादव को 14 दिन की न्यायिक हिरासत में भेजा गया
Crime·hace 4 días

बिहार: पूर्व मंत्री तेज प्रताप यादव को 14 दिन की न्यायिक हिरासत में भेजा गया

बिहार के पूर्व मंत्री तेज प्रताप यादव को नीट पेपर लीक के ख़िलाफ़ बिहार बंद में भाग लेने के बाद गिरफ़्तार किया गया और 14 दिन की न्यायिक हिरासत में भेज दिया गया है. राजद नेता तेजस्वी यादव ने सरकार की आलोचना की.

BBC हिंदी
3 min de lectura
Más sobre este temacybercrime