From Terror Camps to Tor and Now Porn Sites: Inside the New Playbook of Cross-Border Radicalisation
Introduction
For years, the story of terror recruitment in Jammu & Kashmir followed a familiar arc: physical infiltration across the Line of Control, local Over Ground Workers (OGWs) acting as couriers, and recruitment pitches on mainstream apps like WhatsApp and Facebook Messenger. Indian security agencies built entire surveillance architectures around that arc. Now, officials say, the architecture is being outflanked in a way few anticipated: through pornography and dating platforms.
The New Front: Chat Rooms Nobody Is Watching
According to officials cited in recent reporting, Pakistan-based terror handlers working in coordination with Pakistan's ISI have begun exploiting the real-time chat features built into pornography and dating websites to reach recruits in Jammu & Kashmir. These pornography platforms feature real-time chat tools that operate under the guise of helping users find dates nearby, and handlers are exploiting that feature to broadcast messages and coordinate activities. It's a strikingly mundane pivot for an organisation engaged in violent extremism, but that is precisely the point that nobody expects a counter-terror dragnet to be watching a dating chatbox.
Officials say the tactic is designed to evade the surveillance that has become standard on conventional social media platforms, allowing handlers to convey instructions to recruits while staying off the radar of established monitoring tools. WhatsApp, Signal and Facebook Messenger have all, in various ways, become known quantities to Indian intelligence subject to legal intercepts, metadata analysis and years of institutional familiarity. A chat window buried inside an adult content site is not.
Tor, Encrypted Nodes, and Apps Built to Disappear
Other than porn sites, investigators have also flagged a cluster of niche, privacy-first messaging apps that route traffic through Tor-based, encrypted nodes to mask user identity. Security agencies have placed a wide array of specialised digital tools under scrutiny, with terror handlers relying on Tor-based messaging applications like Coatex and Conion to route data through encrypted nodes and obscure user identities. Access to at least one of these apps' installation files is reportedly already restricted within India, though enforcement against sideloaded Android packages remains an uphill battle.
What makes these platforms attractive to handlers isn't unique code so much as the design philosophy behind privacy-first messaging generally. Some of these apps offer only basic encryption, while others go further with end-to-end encryption, self-destructing messages, and strong on-device encryption algorithms that keep data processing off any third-party server. Several reportedly allow account creation without a phone number or SIM verification, stripping away one of the most basic identity anchors that Indian telecom-linked surveillance depends on.
There's also an operational, almost logistical, reason for the shift: connectivity. Officials note that some of these applications provide end-to-end encryption, self-destructing messages and registration without a phone number or email, making it difficult for security agencies to trace users, even as terror networks also shift away from commonly used platforms. In the hilly, forested and often poorly connected terrain of Jammu's border districts, apps engineered to function on weak 2G or EDGE networks have an obvious tactical advantage over data-hungry mainstream platforms.
VPNs, Banned Apps, and a Cat-and-Mouse Game
Virtual Private Networks add another layer of obfuscation, letting operatives access apps banned in India and mask the geographic origin of their traffic. This isn't new tradecraft, but its pairing with adult-content chat infrastructure and Tor-routed messaging represents a genuinely novel combination in the Kashmir context, according to the officials describing the pattern to reporters.
The broader trend line, officials say, is a steady migration away from platforms Indian agencies have learned to monitor. Terror networks are increasingly moving away from mainstream, commonly used platforms in favour of more obscure alternatives, forcing intelligence agencies into a perpetual game of catch-up: each time a monitoring capability matures against one platform, handlers migrate to the next.
This is not the first time investigators have flagged this cat-and-mouse dynamic. Reporting on a recent case in Jammu's Bathindi area described a 19-year-old allegedly radicalised through the encrypted app. Session the same platform reportedly linked to suspects in a Delhi bomb plot investigation after months of contact with Pakistan-based handlers. Investigators in that case noted that terror organisations have increasingly turned to multi-layered encrypted messaging services specifically to evade monitoring by intelligence agencies.
The Virtual SIM Problem
Alongside app-layer evasion, foreign-issued virtual SIM cards remain a persistent headache for investigators. The most cited example remains the 2019 Pulwama attack investigation, in which agencies reportedly traced more than 40 virtual SIM cards to the Jaish-e-Mohammed suicide bomber and his network numbers that could be provisioned and abandoned without ever touching an Indian telecom's KYC system. That case became something of a template for how virtual and foreign-registered numbers can be used to build communication chains that are extremely difficult to map after the fact, since there is no physical SIM, no retail purchase record, and often no domestic carrier data trail at all.
More recent J&K cases echo the same pattern in a different form. Police investigating a cross-border radicalisation network noted that intelligence agencies now suspect unauthorised SIM card distribution is being used by terrorists to communicate with handlers across the border, part of a broader push to choke off the logistical and communication backbone that keeps sleeper modules alive even when direct physical contact with a local handler is minimal or non-existent.
How Agencies Are Responding
To their credit, security agencies aren't standing still. Officials say cyber-surveillance frameworks are actively being redesigned to map and intercept these "off-grid" communication channels, a phrase that itself signals how far outside traditional monitoring territory this recruitment method has moved. Agencies say they continue to adapt their cyber-surveillance frameworks specifically to map and intercept these off-grid communication channels. That has included moving to restrict access to specific APKs, tightening scrutiny of virtual number providers, and, as seen in recent CIK (Counter Intelligence Kashmir) operations, proactively disrupting online propaganda networks before recruitment pitches can mature into operational plots. One recent CIK operation, for instance, intercepted attempts to recruit two teenage boys who were allegedly being fed terror content in the direction of a Pakistan-based handler, underlining how young the target pool for these campaigns has become.
Conclusion
What this episode really illustrates isn't a single clever trick but a structural truth about counter-terror surveillance: it is inherently reactive. Every time agencies build competence around a platform, handlers find a low-attention, high-friction-to-monitor alternative: first fringe messaging apps, then Tor-routed clients, and now the sprawling, largely unregulated back-end of adult content platforms, which few people would ever think to associate with national security. It's a reminder that the fight against radicalisation online is no longer confined to obviously "extremist" corners of the internet; it can hide in plain sight, inside the most ordinary-looking corners of the web.
Sources
- New J-K terror tactic: Pornography apps, Tor network used for secret messaging — The Tribune
- New J&K terror tactic: Handlers turn to porn sites, encrypted apps to contact recruits — Deccan Herald
- Terrorists using porn website, encrypted apps for chats with recruits — Organiser
- New J&K Terror Tactic: Pornography Apps, Tor Network Used For Secret Messaging — Kashmir Dot Com
- From WhatsApp to Porn Sites: Terror Groups Adopt New Digital Tactic in J&K — Jammu Kashmir Now
- Jammu teenager's arrest exposes cross-border radicalisation network — The Tribune
- After OGW network, J&K cops target communication channel of terrorists — The Tribune
- CIK busts online radical network, foils recruitment of two minors — The Tribune












