🛡️ Security & DefenceMAINS · GS3.18 · GS3.19

The 'Statement of Account.zip' that hijacks your WhatsApp

I4C has warned that a self-propagating Trojan disguised as bank statements and RBI notices is taking over the WhatsApp accounts of finance professionals, which are then used to order fraudulent transfers in the boss's name.

What happened

For Prelims

For UPSC: A precise, quotable cyber-security case. Use it for social engineering versus technical exploitation, public-private threat intelligence sharing, cross-border organised cybercrime, and why institutional verification protocols beat awareness campaigns.
What it is NOT: This is not a breach of WhatsApp's encryption — the malware hijacks an already-authenticated WhatsApp Web session on a compromised Windows computer.

For Mains

Syllabus: GS3.18 · GS3.19 · Linkage L1

Anchor
The attack does not break the platform; it borrows the trust already inside it.
Substantiation (data)
Over 58,000 potential victims intimated in thirty days through the SMS header I4CMHA-G, and more than 10,000 protected by geo-blocking C2 servers via the Sahyog portal.
Exemplification
A 'Statement of Account.zip' opened by a finance executive turns their own WhatsApp into the distribution channel and their identity into the payment instruction.
Problematisation
Attribution stops at the border: the networks operate across jurisdictions while the loss is booked in an Indian company's accounts.
Way-forward
Mandate out-of-band verification for fund transfers, restrict WhatsApp Web on finance workstations, and route takedowns through Sahyog at machine speed.
Position
Cyber resilience in a firm is an accounting control before it is an IT control.
Deploys into: Cyber security + organised crime (GS3.18, GS3.19) · social engineering and CEO fraud, public-private threat intelligence, and cross-border attribution.
Ministry of Home Affairs · 2026-08-07 · PRID 2295889 · PIB source ↗
Related: Security & Defence · this week's cards · Cybercrime & financial fraud