Security agencies in Jammu and Kashmir have uncovered a new and concerning operational tactic employed by terrorist organizations and their handlers: the clandestine use of pornography applications and the Tor network for secret communication. This shift away from conventional social media platforms aims to evade surveillance and coordinate activities, officials revealed on Sunday. The move signifies an evolving threat landscape, forcing security forces to adapt their cyber-surveillance strategies to counter these increasingly sophisticated methods.
Information reaching Tahir Rihat suggests that these covert channels are being exploited by terror outfits, with alleged involvement of Pakistan’s intelligence agency, the ISI, to transmit instructions to recruits within Jammu and Kashmir. The strategy involves leveraging real-time chat functionalities embedded within pornography platforms, which are often disguised as tools for users to find local connections. Handlers reportedly use these features to broadcast messages and orchestrate operations, thereby circumventing the scrutiny typically applied to mainstream social media applications.
Security agencies are now scrutinizing a wide array of specialized digital tools that facilitate these communications. Terror handlers are reportedly relying on Tor-based messaging applications, such as Coatex and Conion, to route data through encrypted nodes. This process effectively obscures user identities and makes tracking their digital footprint significantly more challenging. Access to the APK, the file format used for installing mobile applications on Android devices, for applications like Conion is reportedly restricted within India, necessitating the use of illicit download methods.
Further complicating detection efforts, these groups are also utilizing privacy-focused platforms. One such platform, a France-based application, offers end-to-end encrypted messaging without the requirement of a SIM card or phone number, making user attribution exceedingly difficult. Agencies are also monitoring applications originating from Vietnam, alongside anonymous platforms like Moonchat. Moonchat, which reportedly includes PGP-encrypted versions with suspected Chinese origins, bypasses traditional registration processes and is also marketed with features for connecting singles in proximity, mirroring the deceptive nature of other platforms being exploited.
While many of these pornography-related applications are officially banned in India, they are being accessed illegally through the use of Virtual Private Networks (VPNs). VPNs create secure, encrypted connections over the internet by masking Internet Protocol addresses and encrypting online traffic, thereby hindering efforts to track online activities and access sensitive data. Security experts emphasize that platforms utilizing the Tor network present unique tracking challenges. Tor, maintained by the US-based non-profit The Tor Project, is designed for legitimate privacy and anti-censorship efforts. However, its robust anonymity features are increasingly being exploited by clandestine networks, including those involved in terrorism.
The Tor network functions by bouncing encrypted traffic through multiple volunteer-run relay nodes globally, effectively hiding both the origin and destination of the data. This distributed architecture makes it exceptionally difficult for security agencies to map and intercept these off-grid communication channels. Officials have stated that security agencies are continuously adapting their cyber-surveillance frameworks to counter these evolving methods of communication. The rationale behind the ban on these applications, according to officials, is their increasing use by terror groups in the recruitment and radicalization of youth in Jammu and Kashmir.
In a significant departure from their previous reliance on conventional social media, handlers are now reaching out to potential recruits through these less conventional platforms. These applications vary in their security features, with some offering basic encryption while others employ more advanced measures such as end-to-end encryption, self-destructing messages, and the RSA-2048 encryption algorithm. The RSA algorithm processes data on the user’s device without any third-party interference, further enhancing the secrecy of communications. RSA, an American network security and authentication company founded in 1982, provides a foundational key in cryptosystems widely used globally.
This trend indicates a deliberate move by terrorists away from commonly used social media applications like WhatsApp, Facebook Messenger, and Signal, which are more readily monitored by security agencies. Security officials have observed that both handlers and recruits from the Kashmir Valley have been relying on specific applications that can function even under slower 2G or EDGE network speeds. Notably, some of these applications do not require users to provide a phone number or email address during the registration process, adding another layer of anonymity.
These new tactics were brought to light as security forces were already working to combat the use of foreign-generated virtual SIM cards. Developed by companies based outside India, virtual SIM cards enable the generation of phone numbers that can be used on smartphones via specific applications, leaving minimal digital traces. The use of virtual SIM cards was first exposed during the investigation into the 2019 Pulwama terror attack, which resulted in the deaths of 40 CRPF personnel. A detailed investigation by the National Investigation Agency (NIA) revealed that more than 40 virtual SIM cards were utilized by the Jaish-e-Mohammed suicide bomber and his accomplices in that attack, highlighting a persistent and evolving threat.

Tahir Rihat (also known as Tahir Bilal) is an independent journalist, activist, and digital media professional from the Chenab Valley of Jammu and Kashmir, India. He is best known for his work as the Online Editor at The Chenab Times.







Leave a Reply