Government Warns WhatsApp Users Against Dangerous File Scam That Can Hijack Accounts
Government Warns WhatsApp Users Against Dangerous File Scam That Can Hijack Accounts
The Indian Cyber Crime Coordination Centre (I4C) has cautioned users against opening suspicious files on WhatsApp, saying cybercriminals are using fake documents to gain control of accounts.
By Vidhi Lalla
Pune: The Indian Cyber Crime Coordination Centre (I4C), under the Union Ministry of Home Affairs, has issued a warning about a new WhatsApp scam in which cybercriminals are sending malicious files disguised as genuine documents to hijack users’ accounts.
According to the advisory, fraudsters are sending files with names such as “View Details,” “Invoice,” or “Document” to make them appear legitimate. However, these files may contain malicious software capable of compromising a user’s WhatsApp account, particularly the WhatsApp Web session.
Officials said users should never download or install files received from unknown numbers, especially if they arrive unexpectedly or create a sense of urgency.
How the scam works
Cybercriminals send a file that appears to be an ordinary document. In many cases, the malicious file is compressed inside a ZIP folder to avoid suspicion.
The warning states that such files often have .exe or .dll extensions. Once installed, the malware attempts to hijack the victim’s WhatsApp Web session, giving attackers unauthorised access to the account.
If successful, fraudsters can misuse the compromised account to send fake messages to the victim’s contacts, impersonate the account owner, and even request money from friends and family.
How to identify suspicious files
Cybersecurity experts recommend checking the file extension before opening any attachment. Files ending in .exe, .dll, or other executable formats should never be installed unless they come from a trusted and verified source.
Users should also be cautious if:
- The sender is unknown or unexpected.
- The message creates urgency or pressure to open the file.
- The attachment claims to be an invoice, document or verification file without prior context.
- The file is sent as a ZIP archive for no apparent reason.
What should you do?
If you receive a suspicious attachment:
- Do not download, open or install it.
- Verify the sender’s identity before opening any unexpected file.
- Delete the message if it appears suspicious.
- Block and report the sender through WhatsApp.
If you have already opened or installed the file:
- Immediately log out of all active WhatsApp Web sessions through WhatsApp settings.
- Run a trusted antivirus or security scan on your device.
- Change important passwords if you suspect unauthorised access.
- Report the incident to the National Cyber Crime Helpline by dialling 1930 or file a complaint through the National Cyber Crime Reporting Portal.
Cybersecurity agencies have repeatedly advised users to remain alert, as scammers increasingly rely on social engineering techniques rather than technical hacking. Attackers often disguise malicious files as routine documents to trick users into installing malware.
Disclaimer: This article is for public awareness based on the latest cybersecurity advisory. Users should always verify the authenticity of files before downloading them and follow official cyber safety guidelines to protect their personal information.



