




More than 10,000 Indians have so far been protected from a malware campaign targeting WhatsApp accounts, following coordinated action by the Indian Cyber Crime Coordination Centre (I4C), the Centre said on Friday.
The Ministry of Home Affairs (MHA) said I4C has detected a sharp increase in complaints on the National Cyber Crime Reporting Portal (NCRP) involving WhatsApp account takeovers.
According to the ministry, the attackers are using malicious files disguised as account statements and official communications allegedly issued by regulatory authorities.



The Centre said I4C has been using the Sahyog Portal to block the command-and-control (C2) servers linked to the malware campaign.
“Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal,” the MHA said.
Similar incidents have been reported from several states, including Delhi, Gujarat, Maharashtra and Rajasthan, the ministry said.
I4C had issued an advisory on June 22, warning people about a growing threat involving impersonation of regulatory and executive authorities to take control of WhatsApp accounts.
The attackers typically send a compressed `.zip` file through WhatsApp, SMS or email. The files are given names such as **“Statement of Account.zip”**, sometimes preceded by a date, or names such as **“RBI.zip”** and **“MCA.zip”**.
The messages are designed to look like routine account statements or urgent notices from regulatory bodies, encouraging recipients to open the attachments without delay.
The MHA said that when the file is extracted and opened on a Windows desktop or laptop, a Trojan gets installed on the device. The malware can then compromise the computer and hijack the victim’s active WhatsApp Web session.
In some cases, the attackers also send emails impersonating the Income Tax Department, the ministry said.
Once an account is compromised, the attackers use it to automatically send the same malicious file to the victim’s WhatsApp contacts and groups. Recipients are often asked to forward the file to their “company finance manager for verification” and open it on a computer.
This allows the malware campaign to spread further, potentially reaching deeper into corporate networks, the ministry warned.
