Who’s the Boss Now: Hijacking WhatsApp Web Sessions for Enterprise Fraud - Cybersecurity Conference

Who’s the Boss Now: Hijacking WhatsApp Web Sessions for Enterprise Fraud

Over the past decade, the abuse of WhatsApp by financially motivated threat actors has undergone a marked evolution. Earlier campaigns (Astaroth, Water Saci, and Mysterious Elephant, etc.) primarily exploited the platform as an initial access and malware delivery vector, distributing banking Trojans, information stealers and remote access malware – no big surprise in the face of rapid adoption of WhatsApp as a business communication platform.

Enter the Boss Scam, an expanding enterprise fraud campaign that has become a significant concern within India’s threat landscape by leveraging carefully orchestrated social engineering over WhatsApp Web. Unlike conventional executive impersonation scams that rely on spoofed phone numbers or newly created messaging accounts, recent Boss Scam variants are delivering weaponized archives through compromised accounts of trusted business partners using phishing lures impersonating regulatory authorities and government agencies. Rather than focusing solely on endpoint compromise, the threat actors behind this campaign are targeting authenticated digital identities, thereby enabling highly convincing business email compromise (BEC)-style fraud.

Victims are tricked into executing files extracted from malicious archives containing DLL side-loaded malware that exfiltrates Chromium browser artifacts, enabling attackers to reconstruct authenticated WhatsApp Web sessions without account credentials or MFA. Using these legitimate sessions, attackers impersonate trusted contacts and send fraudulent payment requests that are difficult to distinguish from legitimate requests, short of physical verification.

The operational maturity of these campaigns is reflected in multiple real-world incidents across India, with publicly reported losses exceeding ₹20 crore (approximately US$2.4 million). Their growing prevalence has also prompted advisories from Indian government agencies, including the Indian Cyber Crime Coordination Centre (I4C) and CERT-In, urging organizations to strengthen financial verification procedures.

In this presentation, we provide a comprehensive end-to-end technical analysis of recent Boss Scam campaigns: the intrusion lifecycle from initial compromise through malware execution, and a demonstration of authenticated WhatsApp Web session reconstruction. We shall also explore how such compromised authenticated WhatApp accounts on Windows may potentially be used as a cross-platform vector to expand the viable threat surface, targeting mobile devices such as Android and iPhone. Finally, we shall propose suitable defensive strategies for this sophisticated threat which requires close monitoring to track its evolution.

Azhagan K M S – K7 Computing Pvt. Ltd.

Azhagan K M S started his career as a Threat Researcher at K7Labs and has two years of experience in cybersecurity. His areas of expertise include Windows threat research, reverse engineering, Digital Forensics and Incident Response. His work focuses on escalation handling, malware analysis, and developing generic and real-time behavioral detections using HIPS. He is also interested in researching emerging threats and evolving attack techniques. He holds a Bachelor of Engineering in Computer Science Engineering and has written and published technical blogs on the K7Labs technical blog.

Priyadharshini – K7 Computing Pvt. Ltd.

Priyadharshini holds a Bachelor’s degree in Computer Science and Engineering from Dhanish Chennai. She works as a Threat Researcher at K7 Computing, with a focus on malware analysis, reverse engineering, Windows digital forensics, and incident response. Her work involves investigating malware behavior, understanding attack techniques, and analyzing threats to support effective detection and response. She has a keen interest in emerging cybersecurity threats and evolving attack methodologies and has contributed technical research and blogs to the K7Labs technical blog.