In short
A high-trust authority or executive identity is used to get the victim to run or open a malicious item The objective is typically to take over WhatsApp/account access and enable high-value financial fraud.
What it is
The communication appears to come from a regulator or senior executive and creates pressure to comply. The victim is then pushed to open/run a malicious Windows executable or follow account-access instructions.
How it starts
A high-trust authority or executive identity is used to get the victim to run or open a malicious item.
What they tell you
The communication appears to come from a regulator or senior executive and creates pressure to comply
What they want you to do
Open/run a malicious Windows executable or follow account-access instructions
How you lose money
take over WhatsApp/account access and enable high-value financial fraud
What happens next
After the first successful step, the fraudster may demand more money/information, deepen account or device access, or disappear.
Warning signs
authority | urgency | trust | malicious executable | account takeover | impersonation
Where this is documented
India — officially documented by an Indian authority/regulator
How to avoid it
Verify the claim using the agency's official website or published helpline; do not transfer money or share OTP/PIN because of an unsolicited threat.
If it already happened
Contact the bank/payment provider immediately if money moved; report financial cyber fraud promptly via 1930 and cybercrime.gov.in; preserve messages, transaction IDs, phone numbers and URLs.