← Back to Tech & Science

Indian Authorities Block Over 10,000 WhatsApp Takeovers Linked to Malware Campaign

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

NEW DELHI — Indian authorities have successfully intercepted a large-scale cyberattack that sought to hijack more than 10,000 WhatsApp accounts using malware disguised as official government documents. The coordinated operation was executed by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs on August 7, 2026.

The attack vector involved malicious files distributed to citizens that appeared to be legitimate regulatory notices or legal orders from state agencies. Once opened, these documents installed Trojan software designed to compromise device security and seize control of WhatsApp sessions. The malware allowed attackers to access private messages, financial data, and personal contacts stored within the messaging application.

The I4C identified the threat pattern through network monitoring that detected unusual traffic signatures associated with session hijacking attempts. Upon confirming the nature of the files, authorities moved quickly to block distribution channels and neutralize the malicious code before it could infect a wider segment of the population. The intervention prevented what officials described as a significant breach of citizen privacy and potential financial fraud.

The campaign targeted users across multiple states in India, exploiting public trust in government communications. Attackers leveraged the urgency often associated with regulatory documents to compel victims into opening infected attachments without scrutiny. Once executed, the Trojan software established backdoor access that allowed remote operators to log into WhatsApp accounts from external devices, effectively locking out legitimate owners.

Security experts note that this method represents an evolution in social engineering tactics used by cybercriminal groups operating within and outside India. By impersonating regulatory bodies, attackers bypassed standard user skepticism toward unsolicited messages. The sophistication of the malware suggests a well-resourced operation capable of generating convincing forgeries to mimic official letterheads and digital signatures.

While the immediate threat has been contained through the blocking action, questions remain regarding the origin of the attack group and whether similar campaigns are active in other sectors. Authorities have not yet identified specific individuals or organizations responsible for distributing the malicious files. The Ministry of Home Affairs stated that ongoing investigations aim to trace the infrastructure used to host the fake documents.

Citizens were advised by officials to avoid opening attachments from unknown sources, even if they appear to originate from government entities. Verification through official channels was recommended before interacting with any digital document claiming regulatory status. As of late Friday, no confirmed cases of successful account takeovers resulting in financial loss had been reported following the intervention.

The incident highlights growing vulnerabilities in mobile communication platforms as cyber threats increasingly target everyday users rather than corporate networks. With WhatsApp serving hundreds of millions of Indians for daily communication and business transactions, such attacks pose a direct risk to national digital security infrastructure.

Discussion

0 / 2000