NG Solution Team
Cybersecurity

Indian Railways Cybersecurity Alert After WhatsApp Web Malware

The Indian Railways has issued a cybersecurity advisory to all zonal railways and other key railway organisations after a script-based cyber incident was reported in Central Railway on August 11 this year. Authorities warned that messaging applications, particularly WhatsApp Web, can be exploited to deliver malicious files and potentially compromise computers connected to railway networks.

According to a root-cause analysis cited by the authorities, the incident occurred when a user received a malicious “E-statement.vbs” file in a WhatsApp group. The file was downloaded onto the user’s computer through the WhatsApp Web application and was subsequently opened by double-clicking it.

“The incident has prompted the Railway Board to direct its units to strengthen endpoint protection and user awareness against malware campaigns exploiting messaging platforms. It is also consistent with a CERT-In warning about a wider campaign in which malicious VBScript files are distributed through WhatsApp, including through compromised accounts to make the messages appear trustworthy,” said the railway official.

Indian Railways cybersecurity measures

Railway units have been asked to ensure that all endpoints connected to railway networks are covered by cyber-security solutions, including ITSM and Endpoint Detection and Response (EDR). Employees have been advised to avoid opening files with extensions such as .vbs, .vbe, .exe, .bat, .cmd, .js and .ps1 unless their authenticity and necessity have been independently verified.

Staff were also told to exercise caution when opening unexpected attachments, even when they appear to come from known contacts. They should verify the identity of the sender before opening suspicious files or clicking links, and keep operating systems, browsers and messaging applications updated.

Related posts

Is CISA warning about three actively exploited SharePoint vulnerabilities?

James Smith

Security Alert: Intelligence Warns of Coordinated Attacks Near Jos

James Smith

Is Anthropic’s Claude Code a security risk due to a backdoor?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy