Over 10,000 Indians shielded from WhatsApp malware takeover: MHA
Synopsis
Key Takeaways
The Ministry of Home Affairs (MHA) on 7 August said coordinated action by the Indian Cyber Crime Coordination Centre (I4C) has protected more than 10,000 Indians from an active WhatsApp account takeover campaign that uses malicious files disguised as regulatory documents. Geo-blocking of command-and-control (C2) servers through the Sahyog Portal has been central to containing the threat.
How the Attack Works
Victims receive a compressed .zip file over WhatsApp, SMS, or email bearing names such as Statement of Account.zip — sometimes prefixed with a date, for example 0714 Statement of Account.zip — or labels mimicking regulators such as RBI.zip and MCA.zip. The files are crafted to resemble routine account statements or urgent notices, pressuring recipients to open them immediately.
When the archive is extracted and opened on a Windows desktop or laptop, a Trojan is silently installed. The malware compromises the device and hijacks the victim's active WhatsApp Web session. In several reported cases, emails impersonating the Income Tax Department have also been sent as part of the same campaign.
How the Malware Spreads
Once a WhatsApp account is compromised, it is used to automatically forward the same malicious file to all of the victim's contacts and groups — typically accompanied by a message asking the recipient to forward it to their 'company finance manager for verification' and to open it on a computer. This social engineering layer is designed to push the infection deeper into corporate networks, turning each victim into an unwitting distributor.
States Affected and Prior Warning
The MHA confirmed that incidents following an identical modus operandi have been reported from multiple states, including Delhi, Gujarat, Maharashtra, and Rajasthan. Notably, I4C had issued a public advisory as early as 22 June warning citizens about the emerging threat of regulatory and executive impersonation for WhatsApp account takeovers — indicating authorities had visibility of the campaign weeks before Friday's disclosure.
Government Response and Ongoing Action
The MHA said a sharp rise in complaints on the National Cyber Crime Reporting Portal (NCRP) first flagged the campaign's scale. Through geo-blocking of C2 servers via the Sahyog Portal and coordinated inter-agency interventions, malware variants are being blocked on a rolling basis. 'Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal,' the ministry stated.
Citizens are advised not to open unsolicited compressed files received over any channel, regardless of how official the sender appears. Any suspicious file or account activity should be reported at cybercrime.gov.in or by calling the national helpline 1930.