‘Boss Scam’ Alert: Fraudsters Target Victims in Delhi, Gujarat, Maharashtra, and Rajasthan

The CSR Journal Magazine

The recent surge in reports concerning the ‘Boss Scam’ has raised alarms across states including Delhi, Gujarat, Maharashtra, and Rajasthan. This scam involves malicious files that are disguised as official correspondence, such as account statements or regulatory notifications, being sent to professionals via WhatsApp, SMS, or email. The Indian Cybercrime Coordination Centre (I4C) has issued a warning regarding this issue, highlighting the tactics used by fraudsters to exploit their victims.

Typically, these malicious communications contain compressed files labelled with names such as “Statement of Account.zip” or “RBI.zip”. Unsuspecting individuals who download and open these files are at risk of having their WhatsApp accounts compromised. Once the account is hacked, it can be used to send similar files to the contacts of the victim, further propagating the scam.

The I4C has identified that the fraudsters then impersonate senior executives through their compromised accounts. They instruct finance personnel to execute urgent transactions to bank accounts controlled by the scammers, thereby facilitating financial theft. This method not only endangers corporate finances but also damages the credibility of affected individuals.

Government Response and Warnings

In response to this alarming trend, the I4C published an advisory on June 22, warning about the dangers of regulatory and executive impersonation linked to WhatsApp account takeovers. This advisory aims to inform citizens and corporate entities of the necessary precautions to mitigate the risks associated with this form of cyber fraud.

The advisory specifies that the malicious files gain access to the victim’s device and can install a Trojan that compromises the WhatsApp Web session. This allows the hacker to initiate fraudulent communication under the guise of the victim, often urging immediate action regarding fund transfers or compliance with fictitious regulatory requirements.

The I4C’s technical analysis indicates that the campaign involves well-organised networks operating on an international scale. The sophisticated nature of the malware allows it to evade detection and propagate effectively through advanced techniques such as DLL Sideloading. As a result, the investigation is concurrently being conducted with various law enforcement and tech agencies to track the origin and tactics of these cybercriminals.

Protective Measures for Individuals and Corporates

The I4C has also shared technical indicators associated with the malware with security agencies and antivirus companies, enabling enhanced detection and prevention strategies. As of now, over 10,000 individuals have reportedly been protected from potential threats through these efforts, which includes regular malware blocking via a dedicated portal.

In addition, the MHA’s cybercrime unit has been proactive in notifying potential victims through SMS, achieving significant outreach over the past month. The I4C continues to encourage citizens to stay alert to communications from the header ‘I4CMHA-G’, urging them to follow up on any safety advice provided.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store –  https://apps.apple.com/in/app/newspin/id6746449540 

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos