惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
雷峰网
雷峰网
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
V
V2EX
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
Vercel News
Vercel News
美团技术团队
人人都是产品经理
人人都是产品经理
The Cloudflare Blog

Latest InfoTech News, IT, Information Technology News | The HinduBusinessLine

Google debuts standalone Gemini App for Apple’s MacOS India’s electronics imports cross $116 billion in FY26, exports trail Labour Ministry to look into POSH compliance by IT services firms, says employees union Is TCS harassment case tip of the iceberg? Entry-level smartphones get costlier as memory shortage persists Indians most nervous about AI despite highest skill penetration EdgeCortix secures Axiro, MPower investment to accelerate AI chip innovation Infosys partners Carlos Alcaraz as global brand ambassador Wipro buys select Alpha Net Group contracts for $70.8 Mn AMS expands Pune GCC, strengthens India’s role in global talent operations Memory chip crunch and Iran war lead phone market decline, IDC says UST, Evaaya jointly launch UST Nimbus to help empower GCCs with new capabilities No layoffs, says Zoho: 300 mentioned in social media post were interns Nvidia’s New AI models spark rally in quantum computing stocks OpenAI unveils GPT-5.4-Cyber a week after rival's announcement of AI model IMF urges nations to stay at frontier of mounting AI risks How your CCTV becomes a hacker’s spy Vehant Technologies eyes 20% topline from export in 3 years Cabinet Secretary emphasizes AI development and civil-military cooperation Amazon to acquire Globalstar for $11.57 billion to boost satellite internet Kaar Tech eyes data analytics acquisition as it positions itself as an AI-led enterprise OS enabler India’s quantum mission to complete 2,000 km network by 2027 Andhra Pradesh launches India’s first quantum reference facility in Amaravati Wegovy-maker Novo Nordisk partners with OpenAI to fasten drug development SPNI acquires TV and digital rights for Indian Football League Qlik partners with ServiceNow to enhance AI-driven enterprise workflows Anthropic hires Trump-linked lobbying firm Ballard Partners OpenAI's $852 billion valuation faces investor scrutiny amid strategy shift Sify data centre arm IPO on track and will be timed with market conditions, says CFO Tata Group asks TCS COO to investigate Nashik sexual harassment case
Home Ministry’s cyber security agency cautions against ‘B...
BL New Delhi Bureau · 2026-06-22 · via Latest InfoTech News, IT, Information Technology News | The HinduBusinessLine
Cybercriminals are targeting high-ranking officials and executives

Cybercriminals are targeting high-ranking officials and executives

Home Ministry’s Indian Cyber Crime Coordination Centre (I4C) on Monday cautioned against ‘Boss Scam’, a new trend in cybercrime. This is being done in the guise of a regulator or even impersonating a CEO (Chief Executive Officer).

“Cybercriminals are targeting high-ranking officials and executives by delivering malicious archives via email or WhatsApp under the guise of urgent regulatory compliance. Once executed, the malware compromises the executive’s Windows device and active web WhatsApp sessions, enabling the fraudsters to message subordinate employees and orchestrate fraudulent financial transfers,” the Centre said in an advisory.

Regulatory violation

Explaining the modus operandi, the advisory said cybercriminals contact a CEO or a high-ranking official via email or WhatsApp, impersonating regulators such as the Reserve Bank of India (RBI). The communication falsely claims regulatory violation or mandates an urgent security improvement, demanding a response within a very short timeframe. “The message contains a compressed .zip archive. Inside this archive is a malicious executable (.exe) accompanied by a Dynamic Link Library (.dll) file,” it said.

As seen in multiple cases, the CEO forwards the message to finance officer. When the executive extracts and executes the file on a Windows desktop or laptop, a Trojan dropper is initiated. The malware establishes a persistent foothold, compromises the system, and hijacks the active web WhatsApp session tokens.

“Armed with access to the executive’s real WhatsApp account, the fraudster contacts accounts or finance employees, instructing them to make immediate payments to specified mule bank accounts,” it said while adding that sometimes the scamsters also pose as CEO and use a secondary number to instruct employees into transferring funds.

To diffuse the cyberattack, I4C advised finance departments of the companies to verify the request of any urgent financial transactions or account changes based solely on a WhatsApp text or email.

Unverified sources

Verification through a direct voice call or in-person confirmation may be done. “Do not install executables received from unknown or unverified sources. Regulators like the RBI will never distribute mandatory software updates or security fixes via WhatsApp attachments,” it said.

Further, system administrators should enforce strict software restriction policies (SRP) configurations to block the execution of unknown ‘.exe and .dll’ files originating from the user profile directories. Regularly audit authorised devices within one’s mobile WhatsApp application (Settings>Linked Devices) and proactively log out of any web WhatsApp sessions that are no longer actively monitored.

“Ensure Windows endpoints are equipped with up-to-date solutions that detect malwares,” it said, while adding that any such incidence should be reported on phone number 1930. Alternatively same can be mailed to www.cybercrime.gov.in.

Published on June 22, 2026