A campaign dubbed Boss Scam is targeting Indian enterprises by hijacking senior executives’ WhatsApp Web sessions and using the real accounts to send fraudulent payment requests. Attackers reportedly lure victims with urgent compliance-themed messages, including notices impersonating regulators such as the Reserve Bank of India, and deliver malicious ZIP archives that executives are tricked into forwarding to finance staff. Indian authorities said the scheme has led to rapid transfers to mule accounts, with some cases involving losses of up to Rs. 2,45,00,000.
The ZIP files contain a legitimate signed executable paired with a malicious DLL that abuses DLL sideloading on Windows. Once executed, the malware can establish persistence, search Chromium-based browsers for active WhatsApp Web sessions, and steal cookies, authentication tokens, IndexedDB data, saved credentials, and encryption material; some reports say the data is archived with tar.exe and exfiltrated over TCP to clone the victim’s session. The attackers then impersonate executives or trusted employees to request wire transfers, spread additional malicious messages, or steal corporate information, and may fall back to saving an attacker-controlled number under the executive’s name if the hijacked session is cut off.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Indian Cyber Crime Coordination Centre (I4C) warned about a 'Boss Scam' campaign targeting business leaders' WhatsApp Web sessions to enable impersonation, fraudulent transfer requests, and broader organizational compromise. The warning described attackers using phishing emails or WhatsApp messages with ZIP archives that deploy DLL sideloading malware on Windows systems.
Indian authorities cited documented cases in which attackers used hijacked executive WhatsApp sessions to send fraudulent wire-transfer instructions, with transfers of up to Rs. 2,45,00,000 sent to mule accounts within minutes. The campaign relied on regulatory-themed social engineering and malware that stole WhatsApp Web session tokens from compromised Windows devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.