The 'Statement of Account.zip' that hijacks your WhatsApp
I4C has warned that a self-propagating Trojan disguised as bank statements and RBI notices is taking over the WhatsApp accounts of finance professionals, which are then used to order fraudulent transfers in the boss's name.
What happened
- I4C flagged a rise in WhatsApp account takeovers reported from Delhi, Gujarat, Maharashtra and Rajasthan.
- The lure is a .zip named 'Statement of Account', 'RBI' or 'MCA', containing a Windows .exe and a .dll.
- Opening it installs a Trojan that hijacks the active WhatsApp Web session and re-sends itself to all contacts.
- In the 'Boss Scam' stage, a senior executive's account instructs finance staff to remit funds to mule accounts.
- I4C intimated over 58,000 potential victims via 'I4CMHA-G' and protected over 10,000 by geo-blocking C2 servers through Sahyog.
For Prelims
- I4C: the Indian Cyber Crime Coordination Centre, under the Ministry of Home Affairs.
- NCRP: the National Cyber Crime Reporting Portal, where such complaints are filed.
- NCTAU: the National Cybercrime Threat Analytics Unit of I4C, which did the technical attribution.
- CERT-In: the national computer emergency response team, with which threat signals were shared.
- DLL sideloading: a technique that makes a legitimate program load a malicious library, used here to evade detection.
- C2 server: the command-and-control server a Trojan reports to; these were geo-blocked through the Sahyog portal.
- Mule account: a third party's bank account used to receive and move fraud proceeds.
- Prior advisory: issued 22 June 2026 on regulatory and executive impersonation for WhatsApp account takeover.
For UPSC: A precise, quotable cyber-security case. Use it for social engineering versus technical exploitation, public-private threat intelligence sharing, cross-border organised cybercrime, and why institutional verification protocols beat awareness campaigns.
What it is NOT: This is not a breach of WhatsApp's encryption — the malware hijacks an already-authenticated WhatsApp Web session on a compromised Windows computer.
For Mains
Syllabus: GS3.18 · GS3.19 · Linkage L1
Anchor
The attack does not break the platform; it borrows the trust already inside it.
Substantiation (data)
Over 58,000 potential victims intimated in thirty days through the SMS header I4CMHA-G, and more than 10,000 protected by geo-blocking C2 servers via the Sahyog portal.
Exemplification
A 'Statement of Account.zip' opened by a finance executive turns their own WhatsApp into the distribution channel and their identity into the payment instruction.
Problematisation
Attribution stops at the border: the networks operate across jurisdictions while the loss is booked in an Indian company's accounts.
Way-forward
Mandate out-of-band verification for fund transfers, restrict WhatsApp Web on finance workstations, and route takedowns through Sahyog at machine speed.
Position
Cyber resilience in a firm is an accounting control before it is an IT control.
Deploys into: Cyber security + organised crime (GS3.18, GS3.19) · social engineering and CEO fraud, public-private threat intelligence, and cross-border attribution.
Ministry of Home Affairs · 2026-08-07 · PRID 2295889 · PIB source ↗