Security agencies in India have recently identified a concerning shift in the operational tactics employed by terrorist groups and their handlers. Following the exposure of their misuse of online gaming platforms, these groups are now turning to pornography websites and niche encrypted applications for clandestine communication. This development, revealed by officials on Sunday, underscores the evolving strategies of these organizations as they seek to evade surveillance on traditional social media platforms.
New Communication Channels
The covert channels being utilized by these terror outfits, often in collaboration with Pakistan’s intelligence agency, ISI, allow for the transmission of instructions to recruits in Jammu and Kashmir. These pornography platforms, which feature real-time chat tools disguised as dating services, are exploited by handlers to disseminate messages and coordinate activities without drawing attention.
To counter these tactics, security agencies have begun scrutinizing a range of specialized digital tools. Terror handlers are increasingly relying on Tor-based messaging applications such as Coatex and Conion, which route data through encrypted nodes to obscure user identities. Notably, access to the APK for Conion is reportedly restricted within India, presenting additional challenges for monitoring efforts.
In addition to these applications, privacy-focused platforms, including a France-based app that offers end-to-end encrypted messaging without requiring a SIM card or phone number, are also being utilized. This makes it exceedingly difficult to attribute messages to specific users. Agencies are also keeping an eye on Vietnam-based apps and anonymous platforms like Moonchat, which features PGP-encrypted versions believed to have Chinese origins. These applications often bypass traditional registration processes and are used for connecting singles in local areas.
Despite many of these pornography applications being banned in India, they continue to be downloaded illegally via Virtual Private Networks (VPNs). VPNs create secure, encrypted connections over the internet, effectively masking users’ IP addresses and encrypting their online traffic. This makes tracking online activity and accessing data significantly more challenging for security personnel.
Experts in cybersecurity note that platforms utilizing the Tor network present unique tracking difficulties. By routing encrypted traffic through multiple volunteer-run relay nodes globally, these platforms obscure both the origin and destination of the data. While the Tor Project, a US-based non-profit organization, maintains this network for legitimate privacy and anti-censorship purposes, its anonymity features are increasingly being exploited by clandestine networks, including terrorist organizations.
In light of these developments, security agencies are continuously adapting their cyber-surveillance frameworks to map and intercept these off-grid communication channels. Officials have justified the ban on certain applications, citing their growing use by terror groups in recruiting and radicalizing youth in Jammu and Kashmir.
In a notable departure from conventional social media platforms, handlers are now reaching out to potential recruits through these less scrutinized applications, which vary in their security features. While some offer basic encryption, others employ advanced measures such as end-to-end encryption, self-destructing messages, and the RSA-2048 encryption algorithm, which processes data directly on the user’s device without third-party interference.
This trend indicates a significant shift away from widely used social media apps like WhatsApp, Facebook Messenger, and Signal. Security officials have observed that both handlers and recruits from the Valley are relying on specific applications that function effectively even on slower 2G or EDGE network speeds. Remarkably, some of these applications do not require a phone number or email address for registration, further complicating tracking efforts.
The emergence of these new tactics was uncovered as security forces intensified their efforts to combat the use of foreign-generated virtual SIM cards. These cards, developed by overseas companies, enable computers to generate phone numbers for use on smartphones via specific applications, leaving minimal digital traces. This issue first came to light during the investigation into the 2019 Pulwama terror attack, which resulted in the tragic loss of 40 CRPF jawans. The National Investigation Agency’s detailed inquiry revealed that over 40 virtual SIM cards were utilized by the Jaish-e-Mohammed suicide bomber and his accomplices during the attack.