A sophisticated new cyber fraud known as the 'Boss Scam' is targeting corporate finance teams by impersonating senior executives via hijacked WhatsApp and email accounts.

  • Criminals impersonate CEOs and CFOs to trick employees into unauthorized fund transfers.
  • Malware-laden ZIP files are used to infect computers and seize control of WhatsApp Web sessions.
  • Techniques like 'DLL Sideloading' allow malware to bypass traditional security checks.
  • Authorities including I4C and SEBI have issued high-level alerts for corporate entities.

A sophisticated new cyber threat, dubbed the 'Boss Scam' or CEO impersonation fraud, is sending shockwaves through the corporate world. In this highly coordinated attack, cybercriminals impersonate top-tier executives such as CEOs, CFOs, and senior management to manipulate finance department employees into transferring massive sums of money from company accounts to fraudulent destinations.

The attack vector typically begins with a deceptively routine communication. Employees may receive emails or WhatsApp messages containing attachments named 'Statement of Account.zip', 'RBI.zip', or 'MCA.zip'. These files are designed to mimic official regulatory or banking documents, creating a sense of legitimacy and urgency that compels the recipient to act quickly.

The Mechanics of the Hijack

Once a victim extracts and opens these malicious ZIP files, a sophisticated malware is activated. This malware utilizes a technique known as 'DLL Sideloading', which allows the malicious code to run through a legitimate application, effectively evading standard security software. The most alarming capability of this malware is its ability to take complete control of an active WhatsApp Web session on a user's desktop or laptop.

By hijacking trusted communication channels, criminals are weaponizing the professional hierarchy against the very employees meant to protect it.

Why This Matters

BozokMedia analysis shows that this is not a simple phishing attempt but a highly organized social engineering campaign. By gaining access to an executive's WhatsApp, attackers can leverage existing trust. When a 'CEO' sends an urgent request for a fund transfer via a known chat window, the psychological barrier to questioning the order is significantly lowered, making the fraud incredibly successful.

The Indian Cyber Crime Coordination Centre (I4C) and the Securities and Exchange Board of India (SEBI) have both flagged this rising trend. Investigations suggest that these attacks are being orchestrated by organized criminal networks, some of which may be operating across international borders, targeting major business hubs in Delhi, Gujarat, Maharashtra, and Rajasthan.

FeatureTraditional PhishingThe Boss Scam
Primary TargetGeneral UsersCorporate Finance/Accounts Teams
MethodFake Links/EmailsWhatsApp Web Hijacking & Malware
Psychological TriggerFear/GreedAuthority/Urgency
Did You Know?: The 'Boss Scam' can create a 'chain of infection' where one compromised employee inadvertently spreads the malware to the entire finance team.

Frequently Asked Questions

1. How can I identify a 'Boss Scam' message?
Be wary of any urgent request for money or sensitive data, even if it comes from a known contact. Always verify through a separate, trusted channel like a direct phone call.

2. What should a company do if they suspect a breach?
Immediately disconnect infected devices from the network, change all administrative credentials, and report the incident to the National Cyber Crime Reporting Portal (NCRP).