Over 10,000 Indians shielded from WhatsApp malware takeover: MHA

Share:
Audio Loading voice…
Over 10,000 Indians shielded from WhatsApp malware takeover: MHA

Synopsis

A WhatsApp malware campaign using fake RBI and MCA documents has been silently hijacking Indian accounts and worming into corporate networks — and over 10,000 people were at risk before authorities stepped in. The government's Sahyog Portal is now geo-blocking the servers behind the attack, but the campaign is still active across at least four states.

Key Takeaways

The Ministry of Home Affairs (MHA) confirmed on 7 August that more than 10,000 Indians have been protected from a WhatsApp account takeover campaign.
Attackers send malicious .zip files disguised as regulatory documents ( RBI.zip , MCA.zip , Statement of Account.zip ) via WhatsApp, SMS, and email.
Opening the file on a Windows device installs a Trojan that hijacks the victim's active WhatsApp Web session.
Compromised accounts automatically forward the malware to all contacts, targeting corporate networks through social engineering.
Incidents have been reported across Delhi , Gujarat , Maharashtra , and Rajasthan ; I4C first issued an advisory on 22 June .
The Sahyog Portal is geo-blocking C2 servers on a rolling basis to contain the spread.

The Ministry of Home Affairs (MHA) on 7 August said coordinated action by the Indian Cyber Crime Coordination Centre (I4C) has protected more than 10,000 Indians from an active WhatsApp account takeover campaign that uses malicious files disguised as regulatory documents. Geo-blocking of command-and-control (C2) servers through the Sahyog Portal has been central to containing the threat.

How the Attack Works

Victims receive a compressed .zip file over WhatsApp, SMS, or email bearing names such as Statement of Account.zip — sometimes prefixed with a date, for example 0714 Statement of Account.zip — or labels mimicking regulators such as RBI.zip and MCA.zip. The files are crafted to resemble routine account statements or urgent notices, pressuring recipients to open them immediately.

When the archive is extracted and opened on a Windows desktop or laptop, a Trojan is silently installed. The malware compromises the device and hijacks the victim's active WhatsApp Web session. In several reported cases, emails impersonating the Income Tax Department have also been sent as part of the same campaign.

How the Malware Spreads

Once a WhatsApp account is compromised, it is used to automatically forward the same malicious file to all of the victim's contacts and groups — typically accompanied by a message asking the recipient to forward it to their 'company finance manager for verification' and to open it on a computer. This social engineering layer is designed to push the infection deeper into corporate networks, turning each victim into an unwitting distributor.

States Affected and Prior Warning

The MHA confirmed that incidents following an identical modus operandi have been reported from multiple states, including Delhi, Gujarat, Maharashtra, and Rajasthan. Notably, I4C had issued a public advisory as early as 22 June warning citizens about the emerging threat of regulatory and executive impersonation for WhatsApp account takeovers — indicating authorities had visibility of the campaign weeks before Friday's disclosure.

Government Response and Ongoing Action

The MHA said a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) first flagged the campaign's scale. Through geo-blocking of C2 servers via the Sahyog Portal and coordinated inter-agency interventions, malware variants are being blocked on a rolling basis. 'Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal,' the ministry stated.

Citizens are advised not to open unsolicited compressed files received over any channel, regardless of how official the sender appears. Any suspicious file or account activity should be reported at cybercrime.gov.in or by calling the national helpline 1930.

Point of View

000 people have already been 'protected' raises an uncomfortable question: how many were compromised before the Sahyog Portal caught up? The campaign was active enough for I4C to issue an advisory on 22 June — a full six weeks before Friday's public statement — suggesting the response timeline deserves scrutiny. More structurally, the self-replicating corporate-network angle marks a qualitative shift from consumer-targeted scams to enterprise infiltration, which India's cyber-incident response architecture was not originally designed to handle at scale. The Sahyog Portal's geo-blocking capability is a meaningful tool, but reactive blocking of C2 servers does not address the upstream problem: malware distribution channels on WhatsApp itself remain largely unmoderated.
NationPress
7 Aug 2026

Frequently Asked Questions

What is the WhatsApp malware campaign targeting Indians?
It is a cyberattack campaign in which victims receive malicious .zip files over WhatsApp, SMS, or email disguised as regulatory documents from bodies such as the RBI or MCA. Opening the file on a Windows device installs a Trojan that hijacks the victim's WhatsApp Web session and automatically spreads the malware to their contacts.
How has the Indian government responded to the WhatsApp malware attack?
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has been geo-blocking command-and-control servers through the Sahyog Portal and monitoring complaints on the National Cyber Crime Reporting Portal (NCRP). These interventions have reportedly protected more than 10,000 Indians from the campaign so far.
Which states have been affected by the WhatsApp account takeover campaign?
Incidents following the same modus operandi have been reported from Delhi, Gujarat, Maharashtra, and Rajasthan, according to the MHA. The campaign is believed to be ongoing.
How can I protect myself from this WhatsApp malware?
Do not open unsolicited .zip or compressed files received over WhatsApp, SMS, or email — even if they appear to come from official sources like the RBI or Income Tax Department. Report suspicious files or account activity at cybercrime.gov.in or call the national helpline 1930.
When did authorities first warn about this WhatsApp threat?
I4C issued a public advisory on 22 June warning citizens about regulatory and executive impersonation used for WhatsApp account takeovers — approximately six weeks before the MHA's broader public disclosure on 7 August.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 2 weeks ago
  2. 4 weeks ago
  3. 1 month ago
  4. 1 month ago
  5. 1 month ago
  6. 1 month ago
  7. 1 month ago
  8. 2 months ago
Google Prefer NP
On Google