How hackers use trusted WhatsApp accounts to spread malware, fraud
The Ministry of Home Affairs, through the Indian Cyber Crime Coordination Centre (I4C), has been actively combating these threats by targeting not only individual malicious files but also the underlying online infrastructure
Investigations are now focused on how legitimate cloud services like Firebase are being misused to host malicious applications and support malware, moving beyond individual malicious files to disrupt the core operational systems of cyber attacks. This includes tackling Windows malware that hijacks WhatsApp Web sessions for spreading further threats and enabling financial fraud, often through 'Boss Scam' or CEO impersonation tactics.
Investigations are now focused on how legitimate cloud services like Firebase are being misused to host malicious applications and support malware, moving beyond individual malicious files to disrupt the core operational systems of cyber attacks. This includes tackling Windows malware that hijacks WhatsApp Web sessions for spreading further threats and enabling financial fraud, often through 'Boss Scam' or CEO impersonation tactics.
Investigations are now focused on how legitimate cloud services like Firebase are being misused to host malicious applications and support malware, moving beyond individual malicious files to disrupt the core operational systems of cyber attacks. This includes tackling Windows malware that hijacks WhatsApp Web sessions for spreading further threats and enabling financial fraud, often through 'Boss Scam' or CEO impersonation tactics.
Most of us are used to opening files sent on WhatsApp without thinking too much about them, especially when they come from someone we know. It could be an account statement, an official-looking document or simply a file forwarded by a colleague. That familiarity is increasingly being exploited by cybercriminals, making malicious files much harder to spot.
The Ministry of Home Affairs has been stepping up its response to the growing malware threat. According to MHA officials, coordinated interventions in a recent WhatsApp-linked malware attack helped safeguard more than 10,000 Indians. I4C also alerted more than 58,000 potential victims over a 30-day period.
The crackdown is also looking beyond individual malicious files and apps to the online infrastructure that can help them operate. In a separate intervention, MHA officials said the Indian Cyber Crime Coordination Centre (I4C) sought Google's intervention against 15 Firebase Realtime Database links.
These links point to online databases that apps can use to store and exchange information in the background. They do not represent 15 infected phones, WhatsApp accounts or victims. Firebase is a legitimate Google service used by developers to build mobile and web applications, including Android apps. Its Realtime Database allows an app to store information online and keep it updated across connected devices.
Cybercriminals, however, can misuse the same infrastructure to support malicious apps. Instead of setting up their own servers, attackers can use legitimate cloud services to communicate with malware or receive information stolen from infected devices.
This is not the first time Firebase infrastructure has surfaced in I4C investigations involving Android malware. In June 2025, I4C flagged three Firebase-hosted domains that were allegedly being used by malware disguised as legitimate banking apps.
The malicious apps allegedly collected SMS messages and sensitive financial information, including credit-card details, and sent the information to Firebase servers being used by the attackers.
The action against the 15 Firebase links does not, by itself, show how each link was being used or whether all of them were connected to Android malware. But it shows how authorities are looking beyond malicious apps and files and also moving against the online infrastructure that can help cyber threats operate.
The recent WhatsApp attack followed a different route. The malware targeted Windows computers and could hijack an active WhatsApp Web session. Once attackers gained access to a genuine WhatsApp account, they could use an identity already trusted by colleagues, friends or employees to spread malicious files further or carry out financial fraud.
I4C had earlier detailed this type of threat in an advisory on what it described as the "Boss Scam" or CEO impersonation fraud. According to the advisory, cybercriminals targeted senior executives and other professionals through email or WhatsApp with malicious ZIP archives disguised as urgent financial or regulatory communications.
Once the malicious file was executed on a Windows computer, the malware could compromise the system and hijack an active WhatsApp Web session.
MHA officials said I4C had also noticed a "sharp rise in complaints" involving such WhatsApp account takeovers on the National Cyber Crime Reporting Portal, with cases following a similar pattern reported from Delhi, Gujarat, Maharashtra and Rajasthan.
How malware spread through trusted WhatsApp accounts
The malicious files were designed to blend into an ordinary workday. MHA officials said they were circulated with names such as "Statement of Account", "RBI" and "MCA", making them appear to be financial statements or documents connected with regulators and government institutions.
The real damage could begin when the archive was downloaded on a Windows desktop or laptop, extracted, and the executable file inside it was run. I4C said such ZIP archives could contain a malicious executable (.exe) file along with a Dynamic Link Library (.dll) file.
Running the executable could trigger malware, compromise the Windows system and hijack an active WhatsApp Web session.
That gave attackers access to something particularly valuable: a genuine WhatsApp identity that other people already trusted.
Once an account was compromised, attackers could use it to send malicious files or messages to the victim's contacts and groups. Instead of receiving a suspicious attachment from an unknown number, the next potential victim could receive it from somebody they knew.
The threat could also move from malware infection to financial fraud. In the CEO impersonation cases described by I4C, attackers who gained access to a senior executive's genuine WhatsApp account could contact employees in the finance or accounts department.
What appeared to be an urgent instruction from the boss could actually be a fraudster asking an employee to transfer money to a mule bank account.
I4C has also documented another variation in which attackers manipulate contact information after compromising a device and use an attacker-controlled number saved under the name of a senior executive to send fraudulent payment instructions.
The threat was therefore not confined to one infected computer. Malware, account takeover and impersonation could work together, allowing attackers to use a trusted digital identity to reach more people and, in some cases, target a company's finances.
How the attack was handled
Containing such attacks requires authorities to look beyond individual compromised accounts and identify the servers and other online systems helping the malware operate.
According to the MHA, I4C's response to the WhatsApp-linked malware included action against command-and-control, or C2, servers. These are online systems through which attackers can communicate with compromised computers and control malicious activity remotely.
The ministry said servers associated with the malware were geo-blocked through the Sahyog Portal. Sahyog is a government mechanism designed to speed up coordination between authorised agencies, technology companies and other online intermediaries when information, data or communication links are being used for unlawful activity.
The MHA says Sahyog was launched to expedite notices under Section 79(3)(b) of the Information Technology Act and facilitate the removal or disabling of access to information, data or communication links being used to commit unlawful acts.
According to MHA officials, the coordinated interventions helped safeguard more than 10,000 Indians. Technical information linked to the malware was also shared with CERT-In, Microsoft and Indian cybersecurity firms including Quick Heal, K7 Computing and Net Protector to help detect and block malicious files associated with the attack.
I4C also alerted more than 58,000 potential victims over a 30-day period through SMS messages sent under the header "I4CMHA-G", according to MHA officials.
The response therefore worked at several points in the attack: identifying systems supporting the malware, moving to disrupt them, sharing information that could help security software detect malicious files and warning people who may already have been exposed.
The action involving Firebase infrastructure reflects another part of the same wider challenge. Malware does not always depend on websites or servers that obviously belong to criminals. Attackers can misuse legitimate online services that ordinary apps and businesses rely on every day, making what happens behind an infected device much harder for a user to see.
Cybersecurity researchers have documented examples of Android malware using Firebase infrastructure. SurxRAT, an Android remote-access Trojan documented by security researchers in 2026, was found to use Firebase-backed infrastructure to communicate with its operators. Researchers said the malware was capable of surveillance, stealing information and remotely controlling infected devices.
The Windows malware involved in the recent WhatsApp attack and Android malware exploiting Firebase are not the same threat. But both point to a broader shift in the way cybercriminals operate. Instead of relying only on suspicious websites, unknown numbers or obviously malicious software, attackers are increasingly finding ways to exploit legitimate platforms and services that millions of people use every day.
That also changes how such threats have to be tackled. Warning users remains important, but by the time a malicious file reaches a phone or computer, much of the infrastructure behind the attack may already be in place. Identifying and disrupting the servers, databases and communication channels that allow malware to operate can stop an attack at an earlier stage.
The recent actions by I4C show that the fight against malware is increasingly moving behind the screen, targeting not only what users see and click on, but also the digital infrastructure that keeps these attacks running.