China, Pakistan and India-Linked Cyber “BOSS Scam” Busted: Over 10,000 Devices Secured, Protecting Indian Citizens from Crores of Rupees in “BOSS Scam” Cyber Fraud

GURU CYBER YODHA
0

The Ahmedabad Cyber Crime Branch has uncovered a sophisticated cyber fraud network involved in the “BOSS Scam”, a growing form of digital fraud in which criminals impersonate CEOs, directors and senior officials to convince employees to transfer money.

According to the official press note, the investigation was conducted through technical analysis and led to the tracing of accused persons in West Bengal. The operation also resulted in the identification of a large network of SIM cards, WhatsApp accounts, OTPs and malware-linked infrastructure. More than 10,000 infected devices were secured, potentially preventing Indian citizens from suffering losses running into crores of rupees.

1. What Is the BOSS Scam?

The BOSS Scam is a form of CEO or executive impersonation fraud. Cybercriminals attempt to make employees believe that they are communicating directly with their company's CEO, director or another senior executive.

The criminals create a sense of urgency by claiming that an immediate financial transaction is required. Employees, particularly those working in finance and accounts departments, are then instructed to transfer money.

The scam becomes more convincing because criminals may use the executive's name and profile photograph on WhatsApp.

2. Malware Is Used as an Entry Point

The investigation found that criminals allegedly impersonated officials of the Reserve Bank of India or other government institutions and sent ZIP files to company executives or employees through WhatsApp or email.

These ZIP files could contain malicious files such as .exe executable files and .dll system library files. When such files are executed on a computer or laptop through WhatsApp Web, criminals can gain control of the WhatsApp Web session.

This makes malicious attachments particularly dangerous for corporate users.

3. WhatsApp Account Hijacking and Impersonation

After gaining control of a WhatsApp Web session, the criminals allegedly save their own mobile number under the name of the CEO or director and use the executive's profile photograph.

The employee may therefore see a familiar name and photograph and assume that the message is genuine.

The criminals then send urgent instructions to the company's Accounts or Finance Department to transfer money. The original number of the CEO or director may be deleted or replaced, making independent verification more difficult.

4. The Complete Criminal Modus Operandi

The investigation describes the criminal process as a chain:

Dummy SIM Card → Mobile Number → OTP → WhatsApp Account → WhatsApp Hijack/Impersonation → CEO/Boss Message → Money Transfer

This demonstrates that cyber fraud often involves multiple supporting layers rather than a single technology.

SIM cards, mobile numbers, OTPs, WhatsApp accounts and malware can collectively form the infrastructure required for a sophisticated cyber fraud operation.

5. Role of Accused Imran Ali Piyada

The press note identifies Imran Ali Piyada, son of Haran Piyada, as one of the accused.

According to the investigation, Imran had a B.A. degree and was working as a Point of Sale (POS) for telecom service providers including Airtel, Jio, Vi and BSNL.

Investigators allege that customer biometric fingerprints and telecom service-provider applications were misused to obtain SIM cards in customers' names. The accused allegedly activated numbers on dummy SIM cards and supplied those numbers to individuals involved in cyber fraud.

The investigation further found that dummy SIM cards were allegedly used for e-commerce and online gaming applications.

According to the press note, over approximately five years, the accused allegedly sold around 21,000 OTPs for e-commerce and online gaming applications at an average price of ₹100, generating more than ₹21 lakh. Around 900 OTPs allegedly used for WhatsApp activation were sold at an average price of ₹250, generating more than ₹2.25 lakh.

6. Role of Accused Injamul

The second accused identified in the press note is Injamul, son of Mujibar Molla.

According to the investigation, Injamul allegedly remained in contact with individuals involved in cyber fraud and assisted with the use of mobile numbers, dummy SIM cards and WhatsApp-based communication systems.

Investigators also found that he allegedly participated in the use of mobile numbers and WhatsApp accounts activated through dummy SIM cards and coordinated with persons involved in cybercrime.

7. Investigation of 4,500 SIM Cards

One of the most significant findings came from approximately 4,500 SIM cards found in mobile devices during the investigation.

The Cyber Crime Cell analyzed these SIM-related details and identified 251 complaints registered on the National Cyber Crime Reporting Portal (NCRP).

These complaints were filed by applicants from 26 different states of India, demonstrating the geographical reach of the digital infrastructure under investigation.

The complaints included:

  • 194 Online Financial Fraud cases
  • 3 BOSS Scam cases
  • 29 Online and Social Media Related Crime cases
  • 8 Other Cyber Crime cases
  • 5 Sexually Explicit Act cases
  • 4 Hacking/Damage to Computer System cases
  • 7 Sexually Obscene or Sexually Abusive Content cases
  • 1 CSEAM-related case

8. Cybercrime as a Service

The case also highlights the growing threat of Cybercrime as a Service (CaaS).

According to the press note, online platforms and messaging services such as WhatsApp are being misused to openly share groups and links for buying and selling OTPs.

This allows criminals to obtain ready-to-use digital resources required for cybercrime. Such services effectively make cybercrime resources available to other criminals without requiring them to independently develop the entire infrastructure.

9. Multi-Country Cyber Infrastructure

Technical and network analysis conducted by the Indian Cyber Crime Coordination Centre (I4C) and Ahmedabad Cyber Crime Branch revealed suspected links to international cyber infrastructure.

The press note states that the malware was suspected to have been developed by cybercriminals associated with China and was being used to target Indian citizens through a call centre located in Islamabad, Pakistan.

It further states that bank accounts involved in the cyber fraud were accessed through a China-based VPN service.

The investigation indicated infrastructure associated with China, India, Pakistan and Hong Kong, allegedly used to conceal identities and actual locations.

10. More Than 10,000 Devices Secured

A major achievement of the investigation was the securing of more than 10,000 infected devices.

According to the press note, the coordinated action helped protect Indian citizens from potential cyber fraud losses amounting to crores of rupees.

The malware identified through the Sahyog Portal is also being regularly blocked, helping strengthen preventive action against the identified threat.

11. Property Seized

During the investigation, authorities seized:

  • 7 mobile phones
    • 3 Android mobile phones
    • 4 keypad mobile phones
  • SIM cards associated with the devices
  • 1 Airtel router

The total estimated value of the seized property was ₹19,500.

12. Key Cybersecurity Lessons for Businesses

The BOSS Scam investigation provides several important lessons for organisations:

  1. Do not open unexpected ZIP files or executable attachments received through WhatsApp or email.
  2. Never rely only on a profile photograph or displayed name to verify a senior executive's identity.
  3. Verify urgent payment instructions using a separate communication channel.
  4. Companies should establish multi-level approval procedures for financial transfers.
  5. Employees should receive regular training on CEO impersonation, malware and WhatsApp-based fraud.
  6. Organisations should maintain updated endpoint protection and monitor suspicious files.
  7. SIM cards, mobile numbers and OTPs should be treated as critical elements of cyber security.
  8. Finance departments should be particularly cautious when a request involves urgency, secrecy or unusual payment instructions.

Conclusion

The Ahmedabad Cyber Crime Branch's BOSS Scam investigation highlights the increasingly organised nature of cybercrime. What may appear to be a simple WhatsApp message can be supported by a complex ecosystem involving malware, dummy SIM cards, OTPs, WhatsApp accounts, impersonation and international cyber infrastructure.

The identification of 251 NCRP complaints across 26 states, analysis of approximately 4,500 SIM cards, and securing of more than 10,000 infected devices demonstrate the scale of the investigation.

For businesses and employees, the most important lesson is simple: always independently verify urgent financial instructions before transferring money. A familiar name, photograph or WhatsApp account should never be considered sufficient proof of identity.

Post a Comment

0 Comments
Post a Comment (0)
To Top