By Rajnish Singh

New Delhi [India], August 7 (ANI): Be alert if you receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as “Statement of Account.zip” (often prefixed with a date, e.g. “0714 Statement of Account.zip”) or “RBI.zip”, “MCA.zip”.

This is part of the infamous ‘Boss Scam’ linked to “takeover of WhatsApp accounts” of professionals and businesspersons through malicious files circulated in the guise of account statements and regulatory communications, and an identical modus operandi has been reported from Delhi, Gujarat, Maharashtra and Rajasthan among multiple states.

In the last few days, the Indian Cybercrime Coordination Centre (I4C) wing of the Ministry of Home Affairs (MHA) noticed incidents with an identical modus operandi being reported from these four major states among others. The cybercrime controlling wing has circulated a warning after it observed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) relating to the fraud, which includes compromised WhatsApp accounts of senior executives and their misuse to instruct finance staff to transfer funds to mule accounts

The I4C wing has cautioned about the rising malicious activity and mentioned that “the compromised WhatsApp account is misused soon after the victim clicks on a compressed (.zip) file received over WhatsApp, SMS or e-mail.

Explaining the modus operandi of the accused, the wing said: “The compromised WhatsApp account is thereafter misused to automatically circulate the same malicious file to all the contacts and groups of the victim, typically with a request to forward the file to the recipient’s “company finance manager for verification” and to open it on a computer, thereby extending the chain of infection deeper into corporate networks.”

In the advanced stage of the fraud, commonly referred to as the “Boss Scam” or CEO impersonation fraud, 14C mentioned, “the fraudsters use the genuine WhatsApp account of a senior executive – or covertly save an attacker-controlled number under the name of the “CEO” in the compromised device – to instruct accounts and finance employees to make urgent transfers of funds to mule bank accounts.”

I4C had alerted citizens to this emerging threat through its Advisory issued on June 22 this year, titled “Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High Value Financial Fraud”.

In the reported incidents, the I4C further said the “victims receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as ‘Statement of Account.zip’ (often prefixed with a date, e.g. ‘0714 Statement of Account.zip’) or ‘RBI.zip’, ‘MCA.zip’. The accompanying message is crafted to appear either as a routine account statement or as an urgent notice from a regulator such as the Reserve Bank of India (RBI) and the Ministry of Corporate Affairs, demanding compliance within a very short timeframe. The archive contains a malicious Windows executable (.exe) accompanied by a Dynamic Link Library (.dll) file. When the file is extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device and hijacks the victim’s active WhatsApp Web session. In many cases, emails are also sent impersonating the Income Tax Department.”

Technical analysis carried out by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C indicates that the campaign is being operated by organised networks acting across national borders and employs advanced malware with sophisticated propagation and detection-evasion capabilities through the DLL Sideloading method.

Officials said the investigation is being pursued in coordination with the concerned law enforcement and technical agencies.

“Since the malware activates only on Windows computers and the lure documents reference account statements and regulatory compliance, the campaign poses a particular risk to Chartered Accountants, Company Directors, Chief Financial Officers (CFOs) and finance and accounts personnel of companies,” warns the I4C, advicing “all corporate entities should immediately sensitise their employees, especially finance teams, and to independently verify – through a direct voice call or in-person confirmation – any urgent fund-transfer instruction or account-change request received over WhatsApp or e-mail before acting upon it.”

The I4C wing further said threat signals and technical indicators of the malware have been shared with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender and leading Indian anti-virus companies, namely Quick Heal, K7 Computing and Net Protector, to enable rapid detection, blocking and removal of the malicious files across platforms and security products.

“Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malware is being blocked regularly through Sahyog Portal.”

The cybercrime security wing said it is sending alerts to affected citizens through the SMS header ‘I4CMHA-G’, and has intimated over 58000 potential victims through the SMS header in the last 30 days. It said threat signals are shared with CERT-In, Microsoft, Indian Anti-virus and Threat Intelligence companies. Citizens are requested to keep a watch on messages received from the SMS header ‘I4CMHA-G’ and to act promptly on the advice contained therein.

The MHA’s cybercrime controlling unit has advised the citizens to “not download, extract or open .zip files or executables received from unknown or unverified sources. “Regulators such as the RBI never distribute software updates, security fixes or account statements through WhatsApp attachments. Regularly review linked devices in the WhatsApp application (Settings > Linked Devices) and log out of WhatsApp Web sessions that are no longer in active use.”

It is also advised that system administrators should enforce software restriction policies to block the execution of unknown .exe and .dll files from user profile directories, and ensure that all Windows endpoints run up-to-date anti-malware solutions.

If an account is compromised, it is warned to immediately log out of all linked devices, alert contacts not to open any file received from the account, and get the computer scanned with an updated anti-virus. Cyber frauds and suspicious communications of this nature should be reported immediately on the National Cyber Crime Helpline number 1930 or on the National Cyber Crime Reporting Portal. (ANI)