Over 10,000 Indians safeguarded from WhatsApp malware attack: Govt
New Delhi, Aug 7
The Centre on Friday said that coordinated action by the Indian Cyber Crime Coordination Centre, including geo-blocking of command-and-control servers through the Sahyog Portal, has protected more than 10,000 Indians from a WhatsApp account takeover campaign.
In a statement, the Ministry of Home Affairs (MHA) said I4C has observed a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) regarding the takeover of WhatsApp accounts through malicious files disguised as account statements and communications purportedly issued by regulatory authorities.
"Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal," the ministry said.
According to the MHA, incidents following an identical modus operandi have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan. I4C had earlier issued an advisory on June 22 warning citizens about the emerging threat involving regulatory and executive impersonation for WhatsApp account takeovers.
"In the reported incidents, victims receive a compressed (.zip) file over WhatsApp, SMS or e-mail bearing names such as Statement of Account.zip (often prefixed with a date, e.g. 0714 Statement of Account.zip) or RBI.zip, MCA.zip," it explained.
These messages are crafted to resemble routine account statements or urgent notices from regulators, prompting recipients to open the files immediately.
"When the file is extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device and hijacks the victim's active WhatsApp Web session. In many case emails are also sent impersonating Income Tax Department," the ministry mentioned.
"The compromised WhatsApp account is thereafter misused to automatically circulate the same malicious file to all the contacts and groups of the victim, typically with a request to forward the file to the recipient's "company finance manager for verification" and to open it on a computer, thereby extending the chain of infection deeper into corporate networks," it added.
— IANS
Reader Comments
My uncle in Jaipur almost fell for this exact scam last week! Someone sent him a "RBI statement.zip" file on WhatsApp and he was about to open it when I stopped him. These fraudsters are getting smarter daily. Happy to see I4C taking proactive steps. Still, most people don't even know about the Sahyog portal... please spread more awareness!
Good initiative but a bit late. My cousin in Pune lost his entire business contact list to this attack in May. He was working on a Windows laptop and opened what he thought was an Income Tax notice. Within hours, his clients were receiving malware links from his account. The damage was massive. The govt should work with WhatsApp directly to create stricter verification for such files.
Great job by our cyber cell! 💪 Just hoping they also start tracking these international servers more aggressively. The scammers are mostly operating from outside India and that's why they get away so easily. Also, everyone should enable Two-Step Verification on WhatsApp right now — it takes just 2 minutes and saves a lifetime of headache. Cyber aware India, strong India! 🇮🇳
Nice to see the system working, but let's be honest — 10,000 is a drop in the ocean. We have 500 million+ WhatsApp users in India. The fact that I4C only issued its first advisory on June 22 when such scams were running since early 2024 shows our response time is still slow. Need more proactive digital literacy campaigns, especially for senior citizens who are the biggest targets.
My respect for our cyber police has
We welcome thoughtful discussions from our readers. Please keep comments respectful and on-topic.