It begins with a zip file that looks like an RBI notice. It ends with an accountant obeying an instruction that never came from his employer. Cases are now reported from four states.
By Aalimi Nation Investigations Desk | Ahmedabad
AHMEDABAD — The instruction arrived on WhatsApp and it was unambiguous: send Rs 1.5 crore to a garment manufacturer in Kolkata, immediately. The company's accountant did what the message said. It was only afterwards that the firm discovered the sender was not the boss at all, but a hacker operating his account.
The route in had been opened weeks earlier, and by the boss himself. On 23 June 2026, Pravin Nagjibhai Bualiya, who runs a real estate business in Ahmedabad, received a WhatsApp message from an unknown mobile number. The sender identified himself as an officer of the Reserve Bank of India's "risk control" department and said unusual financial activity had been detected in the company's bank account, which could be frozen or suspended. Attached was a zip file.
Bualiya told BBC Gujarati that similar messages had been reaching him for six months. He had ignored them at first, but the links kept coming, and eventually he thought they might genuinely be from the RBI. He forwarded the link to his company's accountant and asked him to find out whether the account had in fact been frozen. The accountant, he said, opened the link on his desktop and downloaded the file.
That single click is the whole attack.
India's Indian Cyber Crime Coordination Centre (I4C) has a name for this pattern. Its advisory of 22 June 2026 — a day before the Ahmedabad message landed — is titled "Regulatory and Executive Impersonation for WhatsApp Account Takeover using Malicious Windows Executables and High Value Financial Fraud." In the reported cases, victims receive a compressed file over WhatsApp, SMS or email with a name designed to look routine or official: "Statement of Account.zip", often carrying a date prefix, or plainly "RBI.zip" and "MCA.zip". Some emails impersonate the Income Tax Department instead.
Inside the archive is a Windows executable paired with a DLL file. Opened on a desktop or laptop, it installs a trojan and hijacks the victim's active WhatsApp Web session. The phone is not what is attacked; the browser session is.
The compromised account then works for the attacker. According to I4C, the malware circulates the same file automatically to the victim's contacts and groups, typically with a request to forward it to the recipient's company finance manager for verification and open it on a computer — pushing the infection deeper into corporate networks with the credibility of a known sender behind it.
I4C's advisory is blunt on one point: regulators such as the RBI never distribute software updates, security fixes or account statements through WhatsApp attachments.
The final stage is social, not technical. With control of a senior executive's genuine WhatsApp account — or by quietly saving an attacker-controlled number under the name "CEO" on a compromised device — the fraudsters message the accounts and finance staff with urgent instructions to transfer funds to mule accounts.
What makes this version dangerous is that the usual warning signs are gone. Earlier CEO-fraud attempts relied on spoofed email domains or lookalike WhatsApp profiles, and staff were trained to spot the misspelt address or the odd sender ID. Here the message comes from the boss's real account, in the boss's real chat thread. There is nothing to misspell.
I4C's National Cybercrime Threat Analytics Unit has said its technical analysis indicates organised networks operating across national borders are behind the campaign. Cases with an identical modus operandi have been reported from Delhi, Gujarat, Maharashtra and Rajasthan, and the agency has recorded a sharp rise in WhatsApp-compromise complaints on the National Cyber Crime Reporting Portal.
Because the malware only executes on Windows machines and the bait is written in the language of compliance, the people most exposed are the ones who handle compliance: chartered accountants, company directors, chief financial officers and finance and accounts staff. The profile of the victim is not the careless user but the conscientious one — the employee who opens a regulator's notice quickly precisely because it is a regulator's notice.
Government intervention has been running in parallel. The Ministry of Home Affairs says coordinated action has protected more than 10,000 citizens from this campaign, with linked malware blocked through the Sahyog portal, and that alerts were sent to over 58,000 potential victims in a 30-day period using the SMS header "I4CMHA-G".
Every documented case turns on a payment instruction that was never verified outside the chat window. I4C's central recommendation to companies is to independently confirm any urgent fund-transfer or account-change request by direct voice call or in person, and to sensitise finance teams specifically. Its technical advice is narrower: do not download, extract or open zip files or executables from unverified sources; review WhatsApp's linked devices and log out of sessions no longer in use; and have system administrators block the execution of unknown .exe and .dll files from user profile directories.
If an account has already been compromised, the advice is to log out of all linked devices at once, warn contacts not to open anything received from the account, and scan the machine with updated anti-malware. Cyber fraud can be reported on helpline 1930 or through the National Cyber Crime Reporting Portal.








