Boss Scam Alert: WhatsApp Hijacking Malware Targets Finance Professionals
A new “Boss Scam” campaign is targeting finance professionals, company executives and corporate employees by hijacking active WhatsApp Web sessions. Attackers are reportedly sending malicious ZIP files disguised as RBI, MCA or account-statement documents through WhatsApp, SMS and email.


Once opened on a Windows PC, the malware can compromise the system and take control of the victim’s WhatsApp Web session. Attackers then use the hijacked account to spread the same malicious files to contacts and impersonate senior executives, sending urgent requests for fraudulent fund transfers.
Organizations should avoid opening unknown ZIP files or executables, block unauthorized .exe and .dll execution, monitor endpoint activity and regularly review WhatsApp Linked Devices. Finance teams should independently verify urgent payment requests through a trusted communication channel. Net Protector helps strengthen endpoint and malware protection against evolving cyber threats.
Stay Ahead of WhatsApp Threats with NPAV Endpoint Security