Terrorist organisations targeting India are shifting the core of their recruitment, radicalisation and financing operations into the digital layer, relying on encrypted messengers, virtual private networks, anonymous social accounts and cryptocurrency to stay a step ahead of investigators.
That assessment, from senior security officials cited by ETV Bharat, comes after a fresh round of National Investigation Agency (NIA) raids and arrests across the country.
The ‘Three-App Model’ Emerging From NIA Probes
A series of NIA searches at 20 locations in July, along with recent arrests, has revealed what officials describe as a three-app pipeline of terror. In the pattern investigators are mapping, vulnerable youths are first approached on open platforms such as Instagram, then moved into encrypted spaces such as Telegram for ideological grooming and operational planning, and finally onboarded to cryptocurrency channels for funding.
Recruits are gradually added to closed Telegram groups, exposed to graded ideological material, and later handed violent extremist content, the report said. Some are then instructed to build fake identities, source weapons and, in a few instances, travel to Pakistan or Afghanistan for training under foreign handlers.
This pattern resurfaced in cases in Tamil Nadu, Vijayawada and Mangaluru, where the accused are alleged to have used WhatsApp, Telegram and Viber along with crypto rails to communicate with and radicalise recruits. Officials added that terror groups are also tapping AI-enabled tools, multi-layer virtual networks and foreign-hosted infrastructure to stay outside investigators’ reach.
Post-Pahalgam Surge and the Push Toward Anonymity
“It has come to notice that after the Pahalgam terror attack and India’s response through Operation Sindoor, terrorist organisations across the border have stepped up recruitment of youths using virtual private networks,” a senior security establishment official told the source. VPNs, encrypted channels and burner social accounts, the official said, let handlers hide identities, exploit jurisdictional gaps and push extremist content with a wider reach and a lower risk of detection.
Historically, radicalisation happened through physical gatherings and closed ideological sessions. Officials say that model has now largely migrated online, with end-to-end encrypted apps and VPNs used to plan illicit activity including recruitment into extremist networks.
Crypto Emerges as the Preferred Funding Rail
The financial leg of the pipeline is the piece that has drawn the sharpest attention from Indian agencies over the past year. The Ministry of Home Affairs’ PRAHAAR counter-terrorism strategy, released in February 2026, flagged that terror outfits are increasingly moving money through crypto wallets that skip standard AML and KYC checks.
That warning has been reinforced by a run of recent cases. In March 2026, Uttar Pradesh ATS arrested a 19-year-old dental student from Moradabad for allegedly running an ISIS-linked digital module and dealing in cryptocurrency with contacts in Pakistan, Afghanistan and Turkey using encrypted apps such as Session and Discord.
In May, the Gujarat Cyber Centre of Excellence dismantled a Rs 226 crore crypto-terror financing network, with investigators tracing suspicious flows through USDT and privacy coin Monero across Ahmedabad, Mumbai and Karnal.
In the Jaish-e-Mohammed sleeper cell case in Jaipur, Rajasthan ATS is examining whether the accused received funds via cryptocurrency while staying in touch with Pakistan-based operatives on WhatsApp and other encrypted platforms. Blockchain analytics firm TRM Labs has separately tracked hundreds of ISKP-linked transactions ranging from $100 to $15,000, most routed through Tether on the Tron network.
NIA’s Cyber Counter-Terror Upgrade
To keep pace, the NIA has expanded its cyber counter-terror stack. Its Anti-Cyber Terrorism Division (ACTD) now anchors dark web monitoring, tracking of encrypted channels, cyber threat intelligence and digital forensic work, in close coordination with the Intelligence Bureau and R&AW. State police forces, often the first responders on the ground, have been put through specialised capacity-building programmes.
Officials say the agency also maintains a running database of encrypted apps exploited by terror groups and uses DRDO-developed tools including metadata analysis, IP Detail Record (IPDR) analysis and the NETRA network traffic platform to trace suspicious digital footprints.
On the takedown side, MeitY has already blocked more than 9,845 URLs carrying radical content, with continuous cyber patrolling identifying extremist propaganda for removal. Alongside, the Financial Intelligence Unit has been asking exchanges to tighten monitoring of transactions originating from sensitive border regions, particularly private wallets and peer-to-peer transfers that bypass centralised oversight.
The July NIA action itself, at 20 locations across roughly ten states including Uttar Pradesh, Andhra Pradesh, Maharashtra, Delhi, Bihar, Rajasthan, Karnataka, Gujarat, Telangana and West Bengal, was tied to an online radicalisation case (RC-01/2026/NIA/VSKP) originally registered by Vijayawada Police, where investigators recovered material linked to banned outfits AQIS and ISIS. Eleven accused and one juvenile have been arrested in that probe so far.
For the crypto industry in India, the signal from the disclosures is consistent with what agencies have been messaging through PRAHAAR, ED enforcement and FIU-IND circulars over the past year. Compliance around KYC, on-chain monitoring for high-risk wallets and cooperation with law enforcement on trace requests is fast becoming a baseline expectation, not a differentiator.
Also Read: India’s ED Probes $35M (₹337 crore) Crypto Scam Run by Self-Styled ‘Key Opinion Leaders’
