Introduction
India’s transition to a digital economy — UPI payments, online banking, e-commerce, remote work — has been matched step for step by a rise in cybercrime. Phishing links, fraudulent loan apps, romance scams, and the covert planting of Trojan horses and malware on personal or organisational systems are now everyday occurrences rather than rare events. For a victim, the most confusing part is often not the crime itself but what to do next: which law applies, where to complain, and how the process actually works.
This article walks through that process end to end. It explains the substantive law that criminalises the unauthorized insertion of a Trojan or malware program — principally Section 43 and Section 66 of the Information Technology Act, 2000 — and the procedural law that governs how a complaint becomes an FIR, now found in Section 173 of the Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023. It then provides a practical, step-by-step guide to filing a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in), including documentation, jurisdiction, and what happens after submission.
Part I: The Legal Framework — Three Statutes Working Together
Since 1 July 2024, India’s criminal justice architecture rests on three new codes that replaced the colonial-era Indian Penal Code, Code of Criminal Procedure, and Indian Evidence Act:
| Old Law | New Law | Function |
Indian Penal Code, 1860 | Bharatiya Nyaya Sanhita (BNS), 2023 | Defines offences — what is a crime |
| Code of Criminal Procedure, 1973 | Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023 | Defines procedure — how an offence is investigated and tried |
| Indian Evidence Act, 1872 | Bharatiya Sakshya Adhiniyam (BSA), 2023 | Defines proof — what counts as evidence |
Cybercrime sits at the intersection of all four statutes now in force: the IT Act (which remains the special law for computer-related offences), the BNS (which supplies general offences like cheating and forgery when a cyber act also amounts to fraud), the BNSS (which governs how a complaint is registered and investigated), and the BSA (which governs the admissibility of electronic evidence, largely carrying forward the old Section 65B regime under a renumbered provision).
For an offence like the unauthorized insertion of a Trojan or malware program, the substantive charge will almost always be framed under the IT Act, sometimes read with the BNS where the malware was a means to cheat or extort the victim. The *procedure* for reporting it, however, is now governed by the BNSS.
Part II: Unauthorized Insertion of Trojan/Malware — The Substantive Law
Section 43, IT Act, 2000 — The Civil Liability Provision
Before looking at the criminal offence, it helps to start with Section 43, because Section 66 is built directly on top of it. Section 43 lists acts that attract civil liability (damages by way of compensation) when done without the permission of the owner of a computer, computer system, or computer network. Clause (c) is the operative provision for malware:
A person who “introduces or causes to be introduced any computer contaminant or computer virus into any computer, computer system or computer network” is liable to pay damages by way of compensation to the person so affected.
The Explanation to Section 43 defines a “computer contaminant” as any set of computer instructions designed to modify, destroy, record, transmit data, or usurp the normal operation of a computer, computer system, or computer network — a definition broad enough to capture Trojans, worms, ransomware, spyware, and other malware. A “computer virus” is separately defined as any computer instruction, information, data, or program that attaches itself to another program and operates without the knowledge of the user, usually to modify or destroy data.
Section 43 also covers related acts frequently bundled with malware attacks: unauthorized access (clause a), downloading or copying data without permission (clause b), causing disruption (clause d), denial of access (clause e), and, notably, clause (i), which penalises destroying, deleting, or altering information residing in a computer resource, or diminishing its value or utility, or affecting it injuriously by any means.
Section 66, IT Act, 2000 — The Criminal Offence
Section 66 converts the civil wrong in Section 43 into a criminal offence wherever the act is done dishonestly or fraudulently. It reads, in substance:
If any person, dishonestly or fraudulently, does any act referred to in Section 43, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both.
The words “dishonestly” and “fraudulently” are not defined afresh in the IT Act; by settled interpretation they carry the meaning assigned to them under the general penal law — broadly, an intention to cause wrongful gain to oneself or wrongful loss to another (dishonesty), or an intention to deceive with the further object of causing injury (fraud). This is the crucial line that separates an accidental virus infection or a security researcher’s proof-of-concept test from a criminal insertion of malware: the prosecution must show the accused acted with dishonest or fraudulent intent.
Why this matters for a Trojan/malware complaint: A Trojan, by definition, disguises itself as legitimate software to gain a foothold on the victim’s system, after which it may exfiltrate data, log keystrokes, encrypt files for ransom, or open a backdoor for remote control. Planting such a program without the owner’s consent, in order to steal data, extort money, or sabotage a system, squarely satisfies both the Section 43(c) description of a “computer contaminant” and the Section 66 requirement of dishonest or fraudulent intent.
Cognizability, Bail, and Jurisdiction of Section 66 Offences
Under the Schedule to the IT Act (as it interacts with the BNSS classification of offences), an offence under Section 66 is cognizable and bailable. “Cognizable” means the police can register an FIR and begin investigation, including arrest, without prior permission of a magistrate — this is significant because it means a victim does not need to first approach a court; a police station (or the cyber portal, which routes to police machinery) is competent to act directly.
Related and Overlapping IT Act Provisions A Trojan/malware complaint frequently overlaps with these companion provisions, which a complainant should be aware of because the police may invoke more than one section depending on what the malware actually did:
| Section | Offence | Relevance to Malware Cases |
| Section 43 | Civil penalty for damage to computer/data | The base civil provision; also allows compensation claims before the Adjudicating Officer under Section 46 |
| Section 65 | Tampering with computer source documents | Where the malware involved altering or concealing source code |
| Section 66 | Computer-related offences (dishonest/fraudulent acts under S.43) | The primary criminal charge for planting a Trojan/virus |
| Section 66B | Receiving stolen computer resource or communication device | If the accused received data/credentials stolen via the malware |
| Section 66C | Identity theft (fraudulent use of password, digital signature, unique identification) | Where the Trojan harvested login credentials |
| Section 66D | Cheating by personation using computer resource | Where the malware was used to impersonate the victim online |
| Section 66E | Violation of privacy | If the malware captured images/videos without consent |
| Section 66F | Cyber terrorism | Where malware targets critical infrastructure with intent to threaten unity, integrity, or security of India |
| Section 72 | Breach of confidentiality and privacy | Where data accessed through the malware is further disclosed |
The BNS Overlay — Cheating, Extortion, and Forgery
Where the malware was a tool to commit fraud (for instance, ransomware demanding payment, or a banking Trojan that facilitated unauthorized fund transfers), the police typically add relevant BNS provisions alongside the IT Act sections:
Section 318, BNS (corresponding to the old Section 420 IPC) — cheating and dishonestly inducing delivery of property.
Section 308, BNS (corresponding to the old Section 384 IPC) — extortion, relevant to ransomware demands.
Section 336–340, BNS (corresponding to the old forgery provisions) — where fabricated documents or credentials are used.
Section 111, BNS — organised crime, which can be invoked where the malware operation is run by a syndicate, including cyber-enabled organised crime.
This dual charging — IT Act for the technical offence, BNS for the fraud element — is now standard practice and is one of the first things a law student should note when analysing an FIR in a malware case.
Part III: The Procedural Law — Registering the Complaint under Section 173, BNSS
From Section 154 CrPC to Section 173 BNSS
The registration of a First Information Report for a cognizable offence, formerly governed by Section 154 of the CrPC, is now governed by Section 173 of the BNSS, 2023. The structure is worth knowing in detail because it directly shapes how a cybercrime complaint moves from an online submission to a formal FIR.
Section 173(1): Information relating to a cognizable offence may be given to the police orally or by electronic communication, irrespective of the area where the offence was committed. If given orally, it must be reduced to writing and read over to the informant; if given electronically, it is taken on record as an FIR only after the informant signs it within three days. This electronic-communication route is the statutory hook that legitimises e-FIRs, including cybercrime complaints filed online.
Section 173(2): A copy of the recorded information must be given to the informant free of cost.
Section 173(3): For a cognizable offence punishable with imprisonment of three years or more but less than seven years, the officer-in-charge may, with the prior permission of an officer not below the rank of Deputy Superintendent of Police, conduct a preliminary enquiry within 14 days to ascertain whether a prima facie case exists, before proceeding to register and investigate. Since Section 66 of the IT Act carries a maximum punishment of three years, complaints can sometimes fall into this preliminary-enquiry band, so a complainant should not be surprised if the police first verify facts before formal registration — this is not a refusal to act, but a statutorily permitted step.
Section 173(4): If a police officer refuses to record information about a cognizable offence, the aggrieved person may send the substance of the information in writing, by post, to the Superintendent of Police, who must then either investigate the case personally or direct a subordinate officer to do so.
Zero FIR and e-FIR: Why They Matter for Cybercrime
Two features of Section 173 are especially significant for cyber offences, where the victim, the accused, and the affected server may all be in different states:
- Zero FIR: The words “irrespective of the area where the offence is committed” mean a victim can walk into ‘any’ police station in India and have the complaint registered, regardless of territorial jurisdiction. It is logged with a “0” serial number and then transferred to the police station that does have jurisdiction, which re-registers it as a regular, numbered FIR. This directly addresses the classic jurisdictional problem in cybercrime, where the victim may be in Delhi, the server in another country, and the money mule’s bank account in a third state.
- e-FIR / e-Zero FIR: Since May 2025, the Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs, has integrated the National Cyber Crime Reporting Portal with the Crime and Criminal Tracking Network and Systems (CCTNS) and state e-FIR systems. Under this e-Zero FIR initiative, complaints of financial cyber fraud involving losses above ₹10 lakh, filed through the portal or the 1930 helpline, are automatically converted into a Zero FIR** at a dedicated e-Crime Police Station, without the complainant needing to first visit a police station. The complainant is then required to visit the concerned cybercrime police station within three days to have the Zero FIR converted into a regular FIR, consistent with the three-day signature requirement in Section 173(1).
For malware-specific complaints that do not involve a direct monetary loss above this threshold (for example, a Trojan planted to spy on a device rather than to steal money), the complaint is still validly filed on the portal, but it goes through the ordinary route: the complaint is forwarded to the jurisdictional cyber cell or police station for registration and investigation, rather than being auto-converted into a Zero FIR.
Part IV: Step-by-Step Guide to Filing a Complaint on the National Cyber Crime Reporting Portal
The National Cyber Crime Reporting Portal (cybercrime.gov.in) is the Government of India’s centralised platform, operated under the aegis of the I4C, for reporting all categories of cybercrime, including malware and Trojan-related offences.
Step 1: Decide the Category of Complaint
The portal has two broad complaint categories:
Report Cyber Crime related to Women/Child — for content involving child sexual abuse material or crimes against women (this category allows anonymous reporting).
Report Other Cyber Crimes — this is the category for financial fraud, hacking, malware/Trojan insertion, identity theft, and similar offences.
For a Trojan/malware complaint, select “Report Other Cyber Crimes.”
Step 2: Register or Log In
– Click on “File a Complaint,” accept the terms and conditions, and either log in or register using a valid mobile number and email ID.
– An OTP is sent to the registered mobile number for verification.
Step 3: Choose the Sub-Category of the Offence
The portal prompts the complainant to select the specific type of incident — for a malware/Trojan case, relevant sub-categories typically include “Hacking/Damage to computer, computer system, etc.,” “Malware Attack,” “Ransomware,” or “Data Breach/Theft,” depending on how the malware manifested.
Step 4: Enter Incident Details
This is the most important step for building a strong complaint. The complainant should provide:
– Date and approximate time the malware/Trojan were discovered or suspected to have been introduced.
– Description of the incident in plain, factual language — how the infection was noticed (unusual pop-ups, unauthorized transactions, files encrypted, device slowing down, unknown processes running, unfamiliar login alerts).
– Suspected source of the infection, if known (a phishing email, a cracked software download, an infected USB drive, a malicious link/attachment).
– Financial loss, if any, with exact amounts, transaction IDs, and the bank/payment app involved.
– Device and system details— make, model, operating system, IP address if known, and whether the device is personal or belongs to an organisation.
Step 5: Upload Supporting Evidence
The portal allows attachment of evidence, which strengthens the complaint considerably. Useful materials include:
– Screenshots of suspicious pop-ups, error messages, ransom notes, or unauthorized access alerts.
– Antivirus/anti-malware scan reports identifying the Trojan or malware signature.
– Bank statements or transaction records if there was financial loss.
– Copies of the phishing email or message suspected to be the infection vector, with full headers if possible.
– A preserved copy (not a modified one) of the suspicious file, where safe to retain.
Practical tip: Do not “clean” or reformat the infected device before filing the complaint and, ideally, before a forensic examination, since this can destroy evidence needed to trace the offender.
Step 6: Submit and Note the Acknowledgment Number
On submission, the portal generates a complaint/acknowledgment number. This number is essential — it is used to track the status of the complaint on the portal and should be retained (screenshot or printout) for all future correspondence with the police or cyber cell.
Step 7: Follow Up and Convert to a Formal FIR
– If the complaint qualifies under the e-Zero FIR mechanism (financial fraud above ₹10 lakh), it is automatically registered as a Zero FIR, and the complainant must visit the designated cybercrime police station within three days to complete the Section 173(1) signature formality.
– For other complaints, including most malware/Trojan cases without large financial loss, the complaint is forwarded to the jurisdictional Cyber Crime Cell or local police station, which registers it as an FIR under Section 173 BNSS if the facts disclose a cognizable offence, and proceeds to investigate.
– If the police decline to register the FIR, the complainant has the statutory recourse under Section 173(4), BNSS, of writing to the Superintendent of Police with the substance of the complaint.
Step 8: Alternative — The 1930 Helpline
For urgent financial fraud (unauthorized transactions, UPI fraud facilitated by a banking Trojan), the complainant should also call the national cybercrime helpline, 1930, immediately. Speed matters here: many banks and payment gateways can freeze or reverse a fraudulent transaction only within a short window, and the 1930 helpline is integrated with banks and payment intermediaries for exactly this purpose.
Part V: Illustrative Judicial Guidance
While Indian case law specifically on Trojan/malware insertion under Section 66 is still developing, a few decisions are essential background for understanding how courts have approached related IT Act provisions:
– Shreya Singhal v. Union of India (2015)— the Supreme Court struck down Section 66A of the IT Act (which had criminalised “offensive” online messages) as unconstitutionally vague and violative of free speech. This is important precisely because Section 66A is no longer good law; any complaint or academic answer referencing online offences must be careful not to invoke a repealed provision, and should rely on Sections 66, 66C, 66D, or the BNS provisions instead.
– Syed Asifuddin and Ors. v. State of Andhra Pradesh (2005) — the Andhra Pradesh High Court dealt with tampering of computer source code (mobile handset ESN/SID reprogramming) under Section 65 of the IT Act, illustrating how courts have interpreted “computer source documents” broadly enough to cover embedded device code, a principle of interpretive relevance to malware that alters system-level code.
Students should treat this area as a fast-developing one: with the BNS/BNSS now in force and the e-Zero FIR mechanism only recently operational, reported decisions applying these provisions together are still emerging, and the safest approach in an exam answer is to state the applicable sections precisely and note that case law is evolving.
Part VI: Practical Checklist for a Complainant
- Do not shut down or reformat the affected device before evidence is preserved.
- Screenshot everything — error messages, ransom notes, unauthorized transaction alerts.
- Run a reputable antivirus/anti-malware scan and save the report.
- File on cybercrime.gov.in under “Report Other Cyber Crimes,” selecting the malware/hacking sub-category.
Call 1930 immediately if there is an ongoing or recent financial transaction linked to the attack.
Note the acknowledgment number and follow up with the jurisdictional cyber cell within three days if directed.
Retain all correspondence with the bank, payment app, or service provider regarding the incident.
If the police decline to act, write to the Superintendent of Police under Section 173(4) BNSS.
Part VII: Frequently Asked Questions
- Is planting a Trojan or virus on someone’s computer a criminal offence, or only a civil wrong?
Both. Section 43 of the IT Act makes it a civil wrong attracting compensation. It becomes a criminal offence under Section 66 the moment it is done “dishonestly or fraudulently” — imprisonment up to three years, fine up to five lakh rupees, or both.
- Do I need to find out who committed the offence before filing a complaint?
No. The complainant only needs to report the facts of the incident. Identifying the accused is the job of the investigating agency, using IP logs, device forensics, and bank/payment trails.
- Can I file a complaint if the malware came from outside India?
Yes. The offence is registered based on where the victim or the affected computer resource is located; cross-border origin does not bar registration, though it may affect the speed and mechanics of investigation (e.g., mutual legal assistance requests).
- What if the local police station refuses to register my complaint, saying it isn’t their jurisdiction?
This refusal is not valid. Section 173(1), BNSS expressly allows an FIR to be registered “irrespective of the area where the offence is committed” (Zero FIR). If refused, the complainant can write to the Superintendent of Police under Section 173(4), BNSS.
- Is the National Cyber Crime Reporting Portal only for financial fraud?
No. It covers all categories of cybercrime, including hacking, malware/ransomware attacks, identity theft, online harassment, and crimes against women and children, under its two broad complaint categories.
- What is the difference between a Zero FIR and an e-FIR?
A Zero FIR is about jurisdiction — it can be filed at any police station regardless of where the offence occurred. An e-FIR is about mode — it is filed electronically instead of in person. A single complaint, such as one filed on the cyber portal, can be both at once.
- How is a complaint automatically converted into a Zero FIR?
Under the e-Zero FIR initiative launched by the I4C in May 2025, complaints of financial cyber fraud involving losses above ₹10 lakh, filed via the portal or the 1930 helpline, are auto-converted into a Zero FIR at a dedicated e-Crime Police Station. The complainant must then visit the concerned police station within three days to sign and convert it into a regular FIR, per the Section 173(1) signature requirement.
- Is Section 66A of the IT Act still applicable to malware or objectionable online content cases?
No. Section 66A was struck down as unconstitutional in Shreya Singhal v. Union of India (2015) and cannot be invoked. Relevant offences must be charged under Sections 66, 66C, 66D, or corresponding BNS provisions instead.
- Can I claim monetary compensation separately from the criminal case?
Yes. Section 46 of the IT Act allows a complainant to approach the Adjudicating Officer for compensation for damage caused under Section 43, independent of any criminal proceedings under Section 66.
- What should I do immediately if I suspect a banking Trojan caused an unauthorized transaction?
Call the 1930 cybercrime helpline immediately and file a complaint on cybercrime.gov.in without delay — banks and payment intermediaries can often freeze or reverse funds only within a short window after the fraudulent transaction.
References and Citations
Information Technology Act, 2000, ss. 43, 46, 65, 66, 66B–66F, 72.
Bharatiya Nyaya Sanhita, 2023, ss. 111, 308, 318, 336–340.
Bharatiya Nagarik Suraksha Sanhita, 2023, s. 173.
Bharatiya Sakshya Adhiniyam, 2023 (electronic evidence provisions, successor to s. 65B, Indian Evidence Act, 1872).
Shreya Singhal v. Union of India, (2015) 5 SCC 1.
Syed Asifuddin and Ors. v. State of Andhra Pradesh, 2005 CriLJ 4314 (AP HC).
National Cyber Crime Reporting Portal — https://www.cybercrime.gov.in
National Cybercrime Helpline — 1930 (Indian Cyber Crime Coordination Centre, Ministry of Home Affairs).
Cyber Law Consulting, “How to file a Zero FIR and eFIR under the New Criminal Law (BNSS-2023)” — https://www.cyberlawconsulting.com/sop_zero_efir_new_criminal_law.php
EBC Webstore Blog, “Zero FIR & e-FIR Under BNSS Section 173: Everything You Need to Know” — https://blog.ebcwebstore.com/zero-fir-e-fir-bnss-section-173/
KSANDK, “Zero FIR and e-FIR Under BNSS: How to File a Police Complaint” — https://ksandk.com/constitutional/how-to-file-a-police-complaint-in-india/
Lexology (Shardul Amarchand Mangaldas & Co.), “Fighting cyber crimes,” originally published in The Hindu Business Line, 26 May 2025 — https://www.lexology.com/library/detail.aspx?g=32d22768-4fc7-4d5f-b373-42ee97893a83
Anantam IAS, “e-Zero FIR Initiative: Online Zero FIR and BNSS Section 173” — https://anantamias.com/e-zero-fir-initiative/
Conclusion
The unauthorized insertion of a Trojan or malware program is squarely a criminal offence under Indian law — civilly actionable under Section 43 and criminally punishable under Section 66 of the Information Technology Act, 2000, with imprisonment up to three years, a fine up to five lakh rupees, or both, wherever dishonest or fraudulent intent can be shown. Where the malware is used as a vehicle for fraud, extortion, or impersonation, the Bharatiya Nyaya Sanhita, 2023 supplies additional, often more severely punished, offences. Procedurally, Section 173 of the Bharatiya Nagarik Suraksha Sanhita, 2023 — reinforced by the Zero FIR and e-FIR mechanisms, and now the e-Zero FIR initiative for large financial frauds — has made it considerably easier for a victim to report a cybercrime from anywhere in India, without being turned away on grounds of territorial jurisdiction. The National Cyber Crime Reporting Portal is the practical gateway that ties this substantive and procedural law together, converting a citizen’s complaint into a trackable, investigable case. For both practitioners and students, the essential discipline is the same: identify the technical act (what the malware actually did), match it to the correct IT Act provision, layer on the relevant BNS offence where fraud is present, and follow the Section 173 BNSS procedure to ensure the complaint is properly registered and pursued.