WhatsApp Malware Scam in India: How to Stay Safe
Learn how the latest WhatsApp malware scam in India uses malicious ZIP files to hijack accounts and target businesses. Discover key prevention tips.

A message from your colleague. A file labelled “RBI.” An urgent request from your CEO.
It looks routine. It feels familiar. But that simple message could be the beginning of a serious cyberattack.
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs (MHA), has reported a sharp rise in complaints involving WhatsApp account takeovers of professionals and businesspersons. Similar incidents have been reported across Delhi, Gujarat, Maharashtra and Rajasthan.
This growing WhatsApp malware scam in India combines malicious files, social engineering and account hijacking to target individuals and businesses.
How Does the WhatsApp Malware Scam Work?
The attack typically starts with a message received through WhatsApp, SMS or email.
Victims may receive a malicious ZIP file with names such as:
“Statement of Account.zip”
“0714 Statement of Account.zip”
“RBI.zip”
“MCA.zip”
The accompanying message is designed to look legitimate. It may appear to be an account statement, regulatory notice or urgent compliance communication from the Reserve Bank of India (RBI), Ministry of Corporate Affairs (MCA) or Income Tax Department.
The objective is to create urgency and convince the recipient to open the attachment without verifying it.
What Happens When You Open a Malicious ZIP File?
The ZIP archive may contain a malicious Windows executable (.exe) along with a Dynamic Link Library (.dll) file.
When these files are extracted and executed on a Windows computer, they can install a Trojan malware that compromises the device.
The malware can then hijack an active WhatsApp Web session, potentially allowing attackers to take control of the victim's WhatsApp account.
This is where an individual infection can turn into a wider cybersecurity threat for businesses.
How a WhatsApp Account Takeover Spreads the Attack
After compromising a WhatsApp account, attackers can use the genuine account to send the same malicious file to the victim's contacts and groups.
The message may ask recipients to forward the file to their company finance manager for verification or open it on a computer.
Because the message comes from someone they know, recipients may be less likely to suspect a scam.
The attack can therefore spread like this:
Malicious ZIP file → Malware infection → WhatsApp account takeover → Trusted contacts targeted → Further infections
For businesses, this creates additional risks to employee devices, corporate networks, sensitive information and financial systems.
WhatsApp Malware Can Lead to CEO Fraud
The danger doesn't stop with account takeover.
Attackers can use compromised WhatsApp accounts to carry out CEO fraud, executive impersonation or Boss Scams.
A fraudster may impersonate a senior executive and contact finance or accounts employees with an urgent request to transfer money to a mule bank account.
The message could be as simple as:
“Please process this payment immediately.”
Because the request appears to come from a trusted executive, employees may act without following normal verification procedures.
This is why protecting businesses from WhatsApp scams and cyber fraud requires more than antivirus software. Strong payment controls, identity verification and employee awareness are equally important.
Why Is This WhatsApp Cyberattack Difficult to Detect?
The biggest weapon in this attack is trust.
The sender may be someone you know.
The attachment may look like a normal business document.
The message may appear to come from a government authority.
The request may seem to come from your CEO.
The campaign also reportedly uses DLL sideloading, a technique that can help malicious software execute while attempting to avoid detection.
This makes the attack a combination of malware, social engineering, phishing and WhatsApp account takeover.
How to Prevent WhatsApp Malware Attacks
Individuals and organisations can reduce their risk with a few important security practices.
1. Don't Open Unexpected ZIP Files
Never download, extract or execute .zip, .exe or .dll files received from unknown or unverified sources.
2. Verify Government and Regulatory Messages
Don't assume an attachment is legitimate because it mentions RBI, MCA or the Income Tax Department. Verify the communication through official channels before taking action.
3. Check WhatsApp Linked Devices
Regularly review WhatsApp → Settings → Linked Devices and log out of devices or sessions you don't recognise.
4. Strengthen Windows Endpoint Security
Businesses should restrict the execution of unknown .exe and .dll files and keep antivirus, anti-malware and endpoint security solutions updated.
5. Verify Urgent Payment Requests
Finance teams should independently verify unusual payment instructions, even when they appear to come from a CEO, director or other senior executive.
6. Conduct Cybersecurity Awareness Training
Employees should be trained to identify phishing attacks, malicious attachments, social engineering and impersonation scams.
What to Do If Your WhatsApp Account Is Hacked
If you suspect a WhatsApp account takeover, act immediately:
Log out of all unknown linked devices.
Warn your contacts not to open suspicious files sent from your account.
Scan the affected computer using updated security software.
Inform your IT or cybersecurity team.
Report suspected cyber fraud through 1930 or the National Cyber Crime Reporting Portal.
Quick action can help prevent the attack from spreading further.
Protect Your Business Before Attackers Find the Weak Spot
The latest WhatsApp malware scam in India is a reminder that cyberattacks don't always begin with sophisticated hacking.
Sometimes, they begin with a file that looks completely harmless.
A “Statement of Account.”
An “RBI Notice.”
An urgent message from your CEO.
Pause. Verify. Then open.
For businesses, proactive security testing can help identify vulnerabilities before attackers exploit them.
WhiteKnight helps organisations strengthen their security posture through proactive cybersecurity assessments and security testing, helping businesses identify weaknesses before they become entry points for attackers.
And WhatsApp malware isn't the only cyber threat organisations in India need to watch.
With Independence Day approaching, the country's threat landscape is also seeing increased hacktivist activity and targeted cyberattacks.
Read our related blog, Hacktivist Attacks on India: Independence Day 2026, to understand the emerging threat landscape and what organisations should be watching for.
Cyber threats evolve. Your security strategy should evolve with them.
Stay alert. Stay safe.


