WhatsApp Web Hacking Scam via Malicious Files — How to Identify & Stay Safe

INDIA — By BharatSecure Threat Intelligence Team ·

Severity: Medium | View Full Scam Details

🛡️ Want to check if you've received this scam?

Check This Scam on BharatSecure →

WhatsApp Web Hacking Scam via Malicious Files: How Indian Users Are Losing Money in 2026

Fraudsters are targeting Indian WhatsApp users with malicious files that silently hijack their accounts — and the results can be financially devastating.

What Is the WhatsApp Web Hacking Scam via Malicious Files?

In this scam, fraudsters trick you into opening a file — often disguised as a PDF, APK, image, or document — through WhatsApp. Once opened, the file either installs spyware on your device or harvests your WhatsApp Web session data, allowing the attacker to access your account from a remote browser without your knowledge. You stay logged in on your phone, completely unaware that someone else is reading your messages, impersonating you to your contacts, and potentially draining money through UPI requests.

This scam is not limited to any one type of user. Homemakers, business owners, students, and senior citizens have all reported falling victim. According to complaint trends tracked on India's National Cybercrime Reporting Portal (cybercrime.gov.in), WhatsApp-based fraud is one of the most frequently reported categories. CERT-In has repeatedly warned the public about malicious files spread through messaging platforms as part of its broader advisories on social engineering threats.

What makes this particularly dangerous is how trusted the delivery channel feels. The file often appears to come from a known contact whose account has already been compromised — so you have no obvious reason to be suspicious.

How This Scam Works — Step by Step

  1. You receive a file on WhatsApp — typically from a contact whose account has been compromised, or occasionally from an unknown number. The file may look like a wedding invitation (a PDF named "SharmaParivar_Wedding.pdf"), a job offer letter, a government document, or a "prize certificate."

  2. You open the file. On Android devices, if you have enabled "Install from Unknown Sources," an APK file can silently install malware. Even non-APK files can exploit vulnerabilities in PDF readers or media processors on unpatched devices.

  3. Your WhatsApp session is cloned or monitored. The malware captures your WhatsApp Web QR authentication token or forwards your messages to a remote server. In some reported cases, it generates a new linked device on your WhatsApp account without your consent.

  4. The fraudster impersonates you. Using your account, they message your contacts claiming an emergency — "I'm stuck at the hospital, please send ₹5,000 urgently on this UPI ID." Contacts trust the message because it appears to come from you.

  5. Money is transferred. Your contacts, believing they are helping you, send money to a UPI ID controlled by the fraudster. By the time anyone realises the deception, multiple transfers may have occurred.

  6. Your account may be locked out. In more aggressive cases, the fraudster re-registers WhatsApp on a new device using your number via a SIM swap, locking you out entirely.

Real Warning Signs to Watch For

What Happens to Victims

The immediate financial loss typically ranges from a few thousand to several lakh rupees, depending on how many contacts are deceived. UPI transactions are near-instant and extremely difficult to reverse — once your contacts send money to the fraudster's account, recovery is not guaranteed even if a police complaint is filed promptly. Victims have reported losses of ₹20,000 to ₹2,00,000 in documented complaint patterns on cybercrime.gov.in.

Beyond money, the emotional toll is significant. Victims feel deep embarrassment that their account was used to defraud friends and family. If the fraudster also accessed personal chats, Aadhaar card images, or bank documents shared over WhatsApp, there is a real risk of identity fraud — including fraudulent loan applications using your KYC details.

What RBI and CERT-In Say

CERT-In (cert-in.org.in) has issued multiple advisories warning users not to open files or click links received from unknown or unverified sources on messaging platforms. Their general framework advises keeping devices patched, avoiding APK downloads outside the official Play Store, and reviewing linked device permissions regularly.

The Indian Cybercrime Coordination Centre (I4C), which operates under the Ministry of Home Affairs, runs the 1930 cybercrime helpline specifically for financial fraud. RBI's consumer protection guidelines make clear that banks are not automatically liable for losses caused by customer-side malware — meaning your bank may not refund you if malware on your own device facilitated the fraud. This makes prevention critical.

How to Protect Yourself

  1. Never open unexpected files on WhatsApp — even from known contacts. Call them first to confirm they actually sent it.
  2. Disable "Install from Unknown Sources" on your Android device (Settings → Security).
  3. Regularly check WhatsApp Linked Devices (three-dot menu → Linked Devices) and log out of any session you don't recognise.
  4. Enable two-step verification on WhatsApp (Settings → Account → Two-step verification). This adds a PIN that blocks re-registration of your number.
  5. Never store Aadhaar, PAN, or bank documents as photos in WhatsApp — if your account is compromised, these become instantly accessible.
  6. Keep your Android/iOS operating system and WhatsApp app updated to patch known vulnerabilities.
  7. Warn your contacts immediately if you suspect your account has been compromised, so they don't send money in response to fraudulent requests.

What to Do If You've Been Targeted

Frequently Asked Questions

Can this scam happen on iPhones, or only on Android? While Android devices are at higher risk due to APK sideloading, iPhone users are not immune. Malicious PDFs and media files can exploit unpatched vulnerabilities on iOS too. Keeping your device updated is the single most important protection regardless of platform.

If my contact lost money because my account was hacked, am I legally responsible? This is a situation where you should consult a lawyer for specific guidance. Generally, if you were a victim of fraud rather than a willing participant, you are not criminally liable — but you should file a police complaint promptly to document that your account was compromised without your consent.

Will WhatsApp's end-to-end encryption protect me from this scam? No. End-to-end encryption protects messages in transit between devices. Once a fraudster links their device to your account or installs malware that reads your screen, encryption does not help — they see exactly what you see, in plain text.


Stay safe online — verify any suspicious message or file at BharatSecure.app before you open it, and report cybercrime immediately on the 1930 helpline.

Disclaimer: This article describes a pattern of fraud reported in public sources for public-safety awareness. It is not legal, financial, or medical advice. To request correction or removal of any content, write to hello@bharatsecure.app.

Related Scams in Our Database

Verify Any Suspicious Message

Check any suspicious message, link, or call for free at bharatsecure.app.