CSA Uncovers WhatsApp Web Scam Targeting Bank and MoMo Users

The Cyber Security Authority (CSA) has uncovered a sophisticated cyber attack in Ghana where criminals are exploiting WhatsApp Web to steal sensitive financial information, including banking credentials and mobile money one‑time passwords (OTPs). According to the CSA, the scheme primarily targets Windows computer users through malicious ZIP files disguised as legitimate documents such as invoices or work files. Once downloaded and extracted, the files install the Astaroth malware, an advanced information‑stealing virus that operates undetected.
After installation, Astaroth secretly connects to WhatsApp Web, harvests the victim’s contact list, and automatically sends similar malicious files to all contacts, enabling rapid spread without the user’s knowledge. In the background, the malware conducts extensive data‑harvesting operations, stealing login details, OTPs, browser cookies, and recording keystrokes. This stolen data allows attackers to gain unauthorized access to bank accounts, compromise mobile money wallets, and carry out fraudulent transactions.
The CSA explained that the attack relies heavily on social engineering, with threat actors sending convincing messages to trick victims into opening the infected files. By disguising the malware as everyday documents, criminals increase the likelihood of users unknowingly installing the virus. Once active, the malware not only spreads itself but also provides cybercriminals with a steady stream of sensitive information.
Authorities have urged the public to exercise extreme caution when opening files received via messaging platforms, even if they appear to come from trusted contacts. Users are advised to avoid downloading suspicious attachments, keep devices updated with the latest security patches, and install reliable antivirus software. The CSA also recommends reporting any unusual account activity immediately to prevent further damage.
This discovery highlights the growing threat of cybercrime in Ghana, particularly as mobile money and online banking become more widespread. By targeting widely used platforms like WhatsApp, attackers exploit everyday communication tools to infiltrate personal and financial systems. The CSA’s warning serves as a reminder that vigilance and digital hygiene are essential to safeguarding against increasingly sophisticated cyber threats.



