
New Delhi | August 8, 2026
India Disrupts WhatsApp Malware Campaign, More Than 10,000 Users Protected
India’s Ministry of Home Affairs (MHA) announced that a coordinated operation led by the Indian Cyber Crime Coordination Centre (I4C) has protected more than 10,000 people from a large-scale malware campaign that attempted to hijack WhatsApp accounts. The operation included coordinated action to disrupt malicious infrastructure, including geo-blocking command-and-control (C2) servers through the government’s Sahyog Portal.
According to the ministry, the campaign relied on malware disguised as legitimate financial or regulatory documents. Recent complaints received through the National Cyber Crime Reporting Portal (NCRP) indicated a sharp rise in WhatsApp account takeover attempts linked to these malicious files.
How the Malware Campaign Worked
Investigators said cybercriminals distributed compressed ZIP files through WhatsApp, SMS, and email, using filenames designed to appear trustworthy, including examples resembling account statements or documents from financial and regulatory agencies.
The ministry said that once a recipient extracted and opened the ZIP file on a Windows desktop or laptop, a Trojan malware program could be installed. The malware was designed to compromise the device and take control of an active WhatsApp Web session.
Fake Government Documents Used as Lures
Officials warned that attackers also impersonated government agencies by sending fraudulent messages that appeared to come from organizations such as the Income Tax Department, attempting to convince users that the attachments contained urgent official information.
These deceptive messages encouraged victims to open the files immediately, increasing the likelihood of infection.
Infection Spread Through Trusted Contacts
After compromising a WhatsApp account, attackers reportedly used the victim’s account to forward the same infected ZIP file to contacts and WhatsApp groups.
In many cases, recipients were instructed to open the attachment on a computer or share it with a company’s finance department for verification. Authorities warned that this technique could allow malware to spread rapidly through personal and corporate networks.
States Reporting Incidents
According to the Ministry of Home Affairs, cases linked to the campaign have been reported in several states, including:
- Delhi
- Gujarat
- Maharashtra
- Rajasthan
The ministry noted that I4C had previously issued a public advisory warning citizens about similar WhatsApp account takeover attempts involving fake government or regulatory documents.
Safety Advice for Citizens
The government has urged the public to remain vigilant and follow basic cybersecurity practices:
- Do not download or open ZIP files received from unknown or suspicious sources.
- Verify messages claiming to be from banks or government agencies through official communication channels.
- Avoid opening attachments that request urgent action without independent verification.
- Keep operating systems and security software updated.
- Report suspected cyber fraud immediately.
Official Websites & Helpline
National Cyber Crime Reporting Portal
https://www.cybercrime.gov.in
Ministry of Home Affairs
https://www.mha.gov.in
Cyber Crime Helpline
1930
Key Highlights
- I4C helped protect more than 10,000 Indian users from a WhatsApp malware campaign.
- Attackers used fake ZIP files disguised as financial or regulatory documents.
- Malware targeted Windows devices and active WhatsApp Web sessions.
- Multiple states reported incidents.
- Citizens are advised to verify suspicious messages and report cybercrime immediately.
Frequently Asked Questions
How did the malware spread?
Attackers distributed malicious ZIP files through WhatsApp, SMS, and email, disguising them as official documents or account statements.
What happens if the ZIP file is opened?
According to the government, opening the malicious file on a Windows computer may install Trojan malware capable of compromising the device and hijacking an active WhatsApp Web session.
What should users do if they receive a suspicious attachment?
Do not open the file. Verify the sender through official channels and report suspicious activity using the National Cyber Crime Reporting Portal or by calling 1930.










