3 weeks ago
I4C Blocks WhatsApp Account Takeover Campaign, Protecting 10,000 Indians
Bad people on the internet tried to steal WhatsApp accounts from people in India.
They sent fake messages that looked like bank statements or letters from the government.
The messages had a secret file with names like 'Statement of Account.zip' or 'RBI.zip'.
If someone opened the file on a computer, a bad program called a Trojan hid inside and took over their WhatsApp.
The program then used the stolen account to send the same bad file to all the person's friends and groups.
A special group in India called I4C helps stop online crimes, and they found out about the trick.
They blocked the computers that were sending the bad files using a system called the Sahyog Portal.
Because of their work, more than 10,000 people in India were kept safe.
They also sent warnings to more than 58,000 people who might have been tricked.
Experts say people should be careful before opening files that look like bank statements or messages from the tax office.
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs (MHA), blocked a WhatsApp account takeover campaign, protecting more than 10,000 Indians.
I4C geo-blocked command-and-control (C2) servers through the Sahyog Portal to halt the malware campaign.
Victims received malicious compressed (.zip) files such as 'Statement of Account.zip', 'RBI.zip' and 'MCA.zip' disguised as routine account statements or urgent regulatory notices.
Opening the files on a Windows desktop or laptop installed a Trojan that hijacked the victim's active WhatsApp Web session and spread the file to contacts and groups.
Similar incidents were reported in Delhi, Gujarat, Maharashtra and Rajasthan, and I4C has intimated over 58,000 potential victims via SMS in the last 30 days.
- Who
- The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs (MHA), took coordinated action against cyber criminals behind the campaign.
- What
- A WhatsApp account takeover malware campaign was blocked, protecting more than 10,000 Indians from Trojan-based attacks.
- Where
- New Delhi (announcement); similar incidents reported in Delhi, Gujarat, Maharashtra and Rajasthan.
- When
- The Ministry of Home Affairs announced the action on Friday, August 7; I4C had issued a warning advisory on June 22 and intimated over 58,000 potential victims in the last 30 days.
- Why
- To protect citizens from malware that hijacked WhatsApp Web sessions through malicious .zip files disguised as account statements and regulatory communications.
Key facts
- Lead agency
- Indian Cyber Crime Coordination Centre (I4C)
- Coordinating ministry
- Ministry of Home Affairs (MHA)
- Citizens protected
- More than 10,000 Indians
- Potential victims intimated
- Over 58,000 via SMS (header 'I4CMHA-G') in last 30 days
- Attack vector
- Malicious .zip files named 'Statement of Account.zip', 'RBI.zip', 'MCA.zip'
- Malware behaviour
- Trojan hijacks WhatsApp Web sessions on Windows devices; spreads file to contacts and groups
- Countermeasure
- Geo-blocking of command-and-control (C2) servers via Sahyog Portal
- States affected
- Delhi, Gujarat, Maharashtra, Rajasthan
Quotes
Ministry of Home Affairs
Government ministry overseeing internal security
“When the file is extracted and opened on a Windows desktop or laptop, a Trojan is installed which compromises the device and hijacks the victim’s active WhatsApp Web session. In many cases emails are also sent impersonating Income Tax Department.”
freepressjournal.in
“Through these coordinated interventions, more than 10,000 Indians have been protected from this campaign so far. Malwares are being blocked regularly through Sahyog Portal.”
freepressjournal.in










