°C
Air:
GOLD73,245 0.25%
SILVER84,520 0.29%
USD83.25 0.12%
EUR90.45 0.08%
GBP105.6 0.15%
WhatsApp Malware Warning: Fake Documents Used by Hackers to Target Finance Professionals
Cyber Security

WhatsApp Malware Warning: Fake Documents Used by Hackers to Target Finance Professionals

0 views
Text Size:

The government warning said chartered accountants, company directors, chief financial officers and corporate finance teams were among the main targets.

Cybersecurity company Quick Heal Technologies has issued a warning about an ongoing WhatsApp-based malware campaign that is targeting finance teams, senior executives, chartered accountants and individual business users. According to the company, attackers are distributing malicious files through compromised WhatsApp accounts, often disguising the files as ordinary business documents to make recipients more likely to open them.

The campaign is particularly concerning for professionals who regularly receive financial statements, invoices, regulatory documents and other business-related files through messaging platforms. Quick Heal said the activity has evolved since August 2026, with attackers changing the types of files used in the campaign and adopting additional techniques to bypass antivirus protection and maintain access to compromised devices.

One of the important characteristics of the campaign is that attackers can misuse a compromised WhatsApp account to send malicious files to the account owner's existing contacts. This creates an additional layer of trust because the recipient may recognise the sender's name or phone number. In such cases, users may be less suspicious of an attachment than they would be if it came from an unknown number. Quick Heal has highlighted this method as one of the reasons the campaign can spread among professional and business networks.

The malicious files are designed to appear like legitimate documents. India's Indian Cyber Crime Coordination Centre has separately warned about a related WhatsApp account takeover campaign in which criminals used files disguised as Statement of Account, RBI and Ministry of Corporate Affairs documents. The government warning said chartered accountants, company directors, chief financial officers and corporate finance teams were among the main targets.

The threat is not limited to the initial victim. According to the government warning, once a professional's WhatsApp account is compromised, criminals may use the account to send messages to colleagues and finance employees. This can potentially be used to impersonate senior executives and issue fraudulent payment instructions. The Indian Cyber Crime Coordination Centre has described this broader pattern as the Boss Scam.

The method relies heavily on social engineering. Instead of sending an obviously suspicious message, attackers may attempt to make the document appear relevant to the recipient's work. A finance employee, for example, may regularly receive account statements or payment-related documents. A message containing a similarly named file can therefore appear credible at first glance.

Quick Heal said the campaign has appeared in multiple file disguises and that attackers have continued to change their techniques. The company's research indicates that the threat actors are attempting to adapt their methods in response to security controls. This means users should not assume that a file is safe simply because it uses a familiar-looking filename or arrives through an existing WhatsApp conversation.

The warning is especially relevant for businesses where employees exchange documents through personal or corporate messaging accounts. Finance departments frequently handle sensitive information and may also have access to payment systems. If a senior employee's messaging account is compromised, attackers may attempt to exploit the trust between executives and staff members.

The Indian government has also reported that cybercriminals are using malicious files distributed through WhatsApp, SMS and email as part of the campaign. The Indian Cyber Crime Coordination Centre said it had observed a rise in complaints involving the takeover of WhatsApp accounts of professionals and businesspeople. The government also said threat signals had been shared with CERT-In, Microsoft and Indian antivirus and threat-intelligence companies.

For ordinary WhatsApp users, the latest warning highlights the importance of treating unexpected attachments with caution. A document should not automatically be considered safe merely because it was sent by a known contact. If a message is unusual, appears urgent or contains an unexpected file, users should verify the information with the sender through another trusted communication method before opening the attachment.

Businesses can also reduce risk by establishing clear internal procedures for financial instructions. Employees should be encouraged to independently verify requests involving payments, changes to bank details or urgent transfers. A WhatsApp message alone should not be treated as sufficient authorisation for a high-value financial transaction.

Another important precaution is keeping operating systems, applications and security software updated. Security updates can address known vulnerabilities and improve protection against malicious files. Organisations should also consider restricting the installation of unknown software and monitoring devices that access corporate systems.

Users should also be careful when downloading compressed files or executable content from messaging applications. A file that appears to be a document may contain malicious components. If the file type or message does not match what the recipient normally receives from the sender, it is safer to stop and verify it before proceeding.

The campaign also demonstrates why account security remains important. Users should enable available security features such as two-step verification and regularly review linked devices on WhatsApp. If an unfamiliar device or session is detected, it should be removed immediately and the account should be secured.

If a user believes a device has been infected, the person should avoid continuing to use the compromised device for sensitive financial activity until it has been checked. Organisations should follow their internal incident-response procedures and seek assistance from qualified cybersecurity professionals where necessary.

Financial professionals should be particularly cautious because the consequences of an account takeover can extend beyond the affected device. Attackers may use access to impersonate executives, communicate with employees and attempt to influence financial decisions. The government has specifically warned that compromised accounts can be misused to instruct finance staff to transfer money to accounts controlled by fraudsters.

The growing use of trusted communication channels in cyberattacks also means that traditional assumptions about phishing need to change. Users often associate phishing with messages from unknown senders. However, compromised accounts can allow attackers to approach victims through conversations that already exist. This makes verification particularly important when a message requests sensitive information, software installation or financial action.

The latest Quick Heal warning does not mean that every document received through WhatsApp is malicious. Instead, it highlights an ongoing campaign in which criminals are deliberately using familiar communication channels and realistic document themes to increase the chances of infection. Users should therefore assess the context of an unexpected message before opening its attachment.

For companies, cybersecurity awareness should extend beyond the IT department. Finance employees, accountants, executives and administrative staff who regularly exchange documents can become targets because their accounts may provide access to valuable information or trusted business relationships. Regular employee awareness training and clear verification procedures can help reduce the likelihood of successful social-engineering attacks.

The warning also reinforces the need for organisations to separate communication from financial authorisation wherever possible. A payment request received through a messaging platform should be independently confirmed using established company procedures. This additional verification step can help prevent attackers from exploiting compromised accounts to create a sense of urgency.

Overall, the WhatsApp malware campaign highlights how cybercriminals are adapting familiar social communication tools for malicious purposes. Quick Heal has reported that attackers continue to modify their techniques, while India's cybercrime authorities have separately warned about malicious files being used in WhatsApp account takeover and financial fraud campaigns.

Users can reduce their exposure by avoiding unexpected attachments, verifying suspicious messages with the sender, keeping devices updated, enabling account security features and following safe procedures for financial transactions. For finance teams and senior executives, these precautions are particularly important because a compromised account can potentially be used to target an entire professional network.

Cybersecurity company Quick Heal Technologies has issued a warning about an ongoing WhatsApp-based malware campaign that is targeting finance teams, senior executives, chartered accountants and individual business users.