Connect with us

NEWS

SEBI’s ‘Boss Scam’ Alert Traces Back to a Windows Loophole Nobody Patched

SEBI’s Boss Scam warning names CEO impersonation fraud, but the real gap is a Windows DLL sideloading trick most firms still don’t block by default.

Published

on

India’s markets regulator told every listed company and regulated entity on Friday to stop trusting the boss’s WhatsApp messages at face value. The Securities and Exchange Board of India (SEBI) issued an advisory naming a fraud called the “Boss Scam,” in which criminals impersonate chief executives and managing directors to push finance staff into wiring company money to strangers.

The advisory reads like standard phishing guidance. But the fraud SEBI describes runs, in its most damaging form, through a Windows-specific malware trick that most corporate laptops still don’t block by default, and that gap gets less attention than the phone-verification advice everyone is repeating this week.

SEBI Puts an Official Name on a Fraud Already Draining Accounts

SEBI’s advisory follows an alert from the Indian Cyber Crime Coordination Centre (I4C), the federal unit that tracks organized cybercrime trends across India. The regulator said fraudsters impersonate senior executives and send urgent messages or calls directing finance personnel to transfer money to specified accounts.

Fraudsters are targeting CEO or high ranking official via email or WhatsApp by impersonating them. The communication through email, WhatsApp, Microsoft Teams or other social media platforms with their subordinates or counterparts directs them to carry out instructions resulting in transfer of funds to fraudsters.

SEBI said in its Friday advisory to listed companies and regulated entities. The regulator described two separate methods criminals use. One relies on artificial intelligence, including voice cloning and deepfake video calls, to impersonate executives convincingly. The other installs malware that hijacks a real WhatsApp Web session, which is the more technically involved and, on the evidence so far, the more damaging of the two.

The timeline shows how fast this moved from a niche cybercrime bulletin to a formal market regulation notice.

  1. June 22, 2026: The I4C issues its advisory describing the Boss Scam and its two attack methods to law enforcement and industry contacts.
  2. June 23, 2026: An Ahmedabad real estate businessman receives a fraudulent WhatsApp message impersonating the Reserve Bank of India, an incident later cited by crime branch officers as typical of the pattern.
  3. July 17, 2026: SEBI issues its own advisory to listed companies and SEBI-regulated entities, citing the I4C’s findings directly.

Inside the ZIP File That Turns a Laptop Into a Weapon

The malware route starts with a message that looks like a compliance notice. Fraudsters contact a chief executive or finance officer through email or WhatsApp, often posing as a regulator like the RBI and citing an urgent violation or security update that needs immediate action.

The message carries a compressed ZIP file. Inside it sits a malicious executable (.exe) file paired with a Dynamic Link Library (DLL) file, according to SEBI’s advisory. Once a recipient opens it on a Windows device, the two files work together to compromise the machine and its active WhatsApp Web session.

Stage What Happens
Lure A message impersonating a regulator or a senior executive arrives by email or WhatsApp, citing an urgent compliance issue.
Delivery The message includes a compressed ZIP archive containing a malicious .exe file bundled with a .dll file.
Execution Opening the file on a Windows device triggers what investigators describe as a Trojan dropper, which installs itself quietly on the system.
Exploitation The malware hijacks the device’s active WhatsApp Web session tokens, letting fraudsters send convincing payment instructions from the victim’s real account to finance staff.

Investigators quoted by ThePrint described the mechanism in blunt terms: when the executive extracts and runs the file on a Windows desktop or laptop, a Trojan dropper activates, establishes a foothold, and captures the live WhatsApp Web session. In some cases, once attackers have full control of a device, they quietly edit the contact list so their own number appears under the CEO’s name, adding a second layer of deception for any future message.

Why Does a WhatsApp Scam Need a Windows Vulnerability?

The WhatsApp deception only works because attackers first take over a Windows device. The exe-plus-dll pairing lets the malware borrow a legitimate, trusted program’s identity to load its malicious payload, a technique researchers call DLL sideloading. That trick helps it slip past basic file-scanning defenses that look for obviously suspicious executables rather than a familiar program quietly loading an unfamiliar file.

Microsoft already publishes a defense built for exactly this behavior. Its Defender documentation describes rules designed to target risky software behavior on Windows devices, the kind of executable-plus-DLL combination this fraud depends on, and Microsoft recommends turning the standard protection rules on without extensive testing. One specific rule in that set is built to block executable content from email or webmail, covering exactly the .exe, .dll and .zip file combination SEBI describes. But that rule’s protection scope is email and webmail clients specifically. It does not extend to files delivered and opened through WhatsApp Web or a desktop messaging app, which is precisely the channel this fraud uses. A company that has switched the rule on for its inboxes can still be wide open the moment the same file lands through a chat window instead.

A Rs 1.5 Crore Lesson From Ahmedabad

The mechanics turned real for an Ahmedabad businessman named Pravin, whose case Ahmedabad Crime Branch officers described to ThePrint. On June 23, around 11 a.m., he received a WhatsApp message from an unknown number.

“This is a notification from the Reserve Bank of India,” the message read, warning of risk-control action and unusual transactions tied to his company’s bank account, and threatening to restrict or suspend it. Pravin’s accountant later opened the accompanying file on a work computer, and fraudsters gained access through the compromised WhatsApp Web session that followed. The company lost roughly Rs 1.5 crore (about $180,000 at typical exchange rates) before the fraud was caught.

Officers in Mumbai and Ahmedabad’s crime branches say the pattern repeats across cases: an urgent regulatory-sounding message, a ZIP file, a finance department that trusts a name it recognizes on the screen.

SEBI Tells Finance Teams to Pick Up the Phone

Set against a technical attack chain, SEBI’s own prescription for companies is mostly procedural rather than technical. The regulator’s advisory lists a handful of concrete steps.

  • Independently verify any payment request received through WhatsApp, email or social media by calling the concerned senior official directly.
  • Never transfer funds solely on the basis of instructions received through social media platforms.
  • Avoid installing executable files without first confirming the sender’s identity, even when the file appears to come from someone familiar.
  • Log out of WhatsApp Web sessions that are not actively in use.
  • Report any suspected fraud immediately through the national cybercrime helpline, 1930, or the Cyber Crime portal.

The advice to log out of inactive sessions is worth a second look. WhatsApp’s own help documentation says the platform will automatically disconnect linked devices after 30 days of inactivity, a built-in safeguard that does nothing for an active fraud unfolding within hours. Manual vigilance, not the platform’s own timeout, is what actually closes the window while an attack is underway.

An Old Fraud Wearing New Software

This is not entirely new in shape. Business Email Compromise (BEC), where criminals impersonate executives over email to redirect payments, has cost companies globally for over a decade. Dr Sanjay Katkar, joint managing director at Quick Heal Technologies, an Indian cybersecurity firm, said the advisory shows how cybercriminals increasingly lean on exploiting trust and human behavior rather than pure technical holes, according to Business Standard.

A Fortinet spokesperson quoted by the same outlet described the Boss Scam as a variant of BEC distinguished by how directly it exploits organizational hierarchy and manufactured urgency. What’s changed is the toolkit: AI-generated voices and video calls on one side, and a Windows malware chain that hijacks a genuinely trusted messaging account on the other, each removing a different kind of doubt an employee might otherwise have.

The national cybercrime helpline stays the same either way: 1930, or a report filed through the government’s portal. Neither number rewrites a Windows security setting, and until more companies flip on the technical controls sitting unused in their own endpoint software, the fastest fix will keep being a phone call.

Frequently Asked Questions

What does UPSI have to do with the Boss Scam?

Fraudsters sometimes tell victims not to disclose a payment, falsely claiming it involves Unpublished Price Sensitive Information (UPSI), market-moving corporate information that hasn’t been made public. Citing UPSI discourages an employee from checking the instruction with a colleague, which is exactly the kind of second opinion that would normally catch the fraud.

What is a mule bank account?

A mule account is a bank account used to receive and quickly move fraudulently obtained funds, often opened using a stolen or borrowed identity or a shell entity. Once stolen money lands there, it typically gets split and moved again within hours, making it much harder for investigators to trace or recover.

Why doesn’t antivirus software catch this malware automatically?

DLL sideloading works by having a legitimate, trusted program load the malicious file rather than running an unfamiliar executable directly, which is what most basic antivirus tools are tuned to flag. That’s why security researchers who have examined the Boss Scam campaign describe it as built for stealth as much as speed.

Are deepfake voice and video calls hard to detect in these scams?

Cybersecurity experts who have reviewed the campaign say visual or voice-based verification alone is no longer enough to confirm someone’s identity, given how convincing AI-generated voice cloning and video calls have become. That’s part of why SEBI’s advisory pushes companies toward independent phone verification through a known number rather than trusting the call or video itself.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending