New WhatsApp scam embeds malware in photos, victim loses Rs 2 lakh

In a surprising twist to cybercrime tactics, hackers are now hiding malware in image files on WhatsApp. A case in Jabalpur highlights the growing threat of file-based attacks targeting user data and bank accounts.

By  Storyboard18| May 26, 2025 1:23 PM
When this feature rolls out, users who don’t have your number will see your username instead, helping minimize unwanted contact and data exposure.

A new and alarming trend dubbed the "WhatsApp image scam" is now gaining traction, exploiting unsuspecting users by embedding malicious code within innocent-looking image files, according to a media report.

Unlike traditional scams that rely on phishing links or OTP fraud, this new scheme utilizes a technique known as steganography - a method of concealing malware within image files. When the image is opened, the malware installs itself on the user's device without raising suspicion, quietly stealing sensitive data like passwords, banking credentials, and one-time password (OTPs).

A recent case in Jabalpur, Madhya Pradesh has drawn national attention to this threat. A man reportedly lost close to ₹2 lakh after opening an image sent from an unknown WhatsApp number.

Investigations revealed that the image contained malware, which infiltrated his device and executed unauthorized financial transactions, all without alerting the victim.

Cybersecurity experts warn that such file-based attacks are more dangerous than traditional scams, as they leave little trace and can bypass standard mobile security measures.

The Department of Telecommunications (DoT) has since issued a public advisory, urging users not to download media files from unfamiliar WhatsApp contacts.

To guard against such threats, experts recommend:

- Avoiding downloads from unknown sources on WhatsApp

- Enabling two-factor authentication on all accounts

- Keeping phones and apps updated with the latest security patches

- Using reputable antivirus software on mobile devices

WhatsApp is reportedly expected to introduce enhanced security tools to scan for malicious media in future updates.

First Published onMay 26, 2025 1:22 PM

SPOTLIGHT

Brand MakersDil Ka Jod Hai, Tootega Nahin

"The raucous, almost deafening, cuss words from the heartland that Piyush Pandey used with gay abandon turned things upside down in the old world order."

Read More

The new face of the browser: Who’s building AI-first browsers, what they do and how they could upend advertising

From OpenAI’s ChatGPT-powered Atlas to Microsoft’s Copilot-enabled Edge, a new generation of AI-first browsers is transforming how people search, surf and interact online — and reshaping the future of digital advertising.