Beware of the 'Boss Scam': Cybercriminals Target Companies Across Delhi and Mumbai Using Malicious ZIP Files

Beware of the 'Boss Scam': Cybercriminals Target Companies Across Delhi and Mumbai Using Malicious ZIP Files

The Indian Cyber Crime Coordination Centre (I4C) under the Union Home Ministry has issued an urgent nationwide security alert regarding a sharp surge in sophisticated cyber frauds known as "boss scams." Exploiting communication platforms like WhatsApp, SMS, and email, organized cybercriminal rings are targeting business owners, corporate professionals, and finance executives across major states including Delhi, Gujarat, Maharashtra, and Rajasthan. Operating through malware disguised as routine financial or regulatory documents, these fraudsters manage to hack professional accounts and manipulate corporate finance departments into transferring substantial sums of money to fraudulent mule accounts.

How the 'Boss Scam' Works: Dangerous .ZIP Files Disguised as Official Statements

According to comprehensive technical findings from the National Cybercrime Threat Analytics Unit (NCTAU), the scam typically begins when a target receives an innocuous-looking compressed archive file. Common titles utilized by scammers include "Statement of Account.zip" (often appended with a specific date), "RBI.zip", or "MCA.zip".

When an unwary victim clicks or downloads the malicious file on their computer or mobile device:

  • Instant Account Compromise: The victim's WhatsApp or communication account is immediately hijacked by malware.

  • Automated Propagation: The compromised account automatically broadcasts the same malicious ZIP file to all contacts and professional groups within the user's network.

  • Corporate Chain Infection: Messages instruct recipients to forward the file to the company's finance manager for urgent verification, deepening the malware's grip on the corporate network.

Impersonating Senior Executives to Direct Unauthorized Money Transfers

In the advanced stages of this targeted attack—classically identified as CEO fraud or a "boss scam"—the criminals leverage complete access to the hacked WhatsApp account. Alternatively, they secretly rename a hacker's contact number as the company's "CEO" or managing director inside the compromised device. Masquerading as top leadership, the fraudsters send urgent directives to junior accountants, administrative staff, or finance managers demanding immediate, confidential money transfers to designated mule bank accounts under the guise of urgent corporate transactions or secret mergers.

I4C Investigation, International Links, and Preventive Measures

Technical analysis conducted by the I4C's specialized wing has uncovered that this massive cyber fraud operation is being orchestrated by an organized network operating from foreign soil. In response, law enforcement and investigative agencies have ramped up collaborative probes. Furthermore, critical malware threat indicators and technical signatures have been officially shared with the Indian Computer Emergency Response Team (CERT-In), Microsoft Defender, and leading domestic anti-virus providers such as Quick Heal, K7 Computing, and Net Protector to ensure real-time detection and blocking of malicious files.

Authorities report that proactive measures have successfully protected over 10,000 Indian citizens from falling victim to financial losses. Continuous blocking mechanisms are live across digital collaboration portals, and official safety warnings are actively being dispatched to citizens nationwide via the dedicated "I4CMHA-G" SMS header.

Latest Posts