New J&K Terror Tactic: Pakistan-Based Groups and ISI Using Porn Sites and Encrypted Apps to Contact Recruits
Security agencies in Jammu and Kashmir have uncovered a fresh method being used by terror outfits and Pakistan’s Inter-Services Intelligence (ISI) to reach recruits while staying outside the usual surveillance net. Officials said on Sunday that handlers are now using live-chat tools on pornography websites and a range of niche encrypted applications to pass instructions, coordinate activity and contact youths in the Valley.
The finding comes after agencies earlier exposed the misuse of online gaming platforms by the same networks. Together, the two tactics point to a clear shift: terror handlers are moving away from widely used messaging apps such as WhatsApp, Facebook Messenger and Signal, where monitoring has become more established, and towards platforms that attract less routine scrutiny.
Chat tools hidden in plain sight
According to officials, some pornography websites offer real-time chat features that are presented as a way for users to find dates or people nearby. Handlers are allegedly using those chats to send messages and organise activity while trying to remain outside conventional monitoring. Several of the sites and related apps are banned in India. They are still being accessed through virtual private networks (VPNs), which mask IP addresses and encrypt traffic, making online activity harder to trace.
Officials said the encrypted messaging features on these platforms have also been used in efforts to recruit and radicalise youths in Jammu and Kashmir. The appeal for handlers is practical. The platforms look ordinary to a casual observer, they are not the first places investigators search, and they offer a mix of anonymity and easy access once a VPN is in place.
Tor apps and other hard-to-trace tools
Agencies are also examining a set of specialised digital applications. Among them are Tor-based messaging platforms such as Coatex and Conion. These apps route data through encrypted nodes so that a user’s identity and location are more difficult to establish. Access to the Conion APK — the Android file used to install the app — is reportedly restricted in India.
Tor, short for The Onion Router, is free open-source software maintained by the US-based non-profit The Tor Project. It was built for privacy and to resist censorship. Encrypted traffic is bounced through multiple volunteer-run relay nodes around the world, which hides both the origin and the destination of the data. Security experts said that same design now creates serious tracking problems when it is used by clandestine networks, including terror groups.
Handlers are also using privacy-focused messengers. One France-based application offers end-to-end encrypted messaging without a SIM card or phone number, which makes user attribution more difficult. Vietnam-based applications are under watch as well. So is Moonchat, an anonymous platform that has several versions used for finding singles nearby. Some of those versions use PGP encryption, are suspected to have Chinese origins, and allow registration without the usual phone number or email address.
Officials said the apps in use offer different levels of protection. Some provide only basic encryption. Others offer end-to-end encryption, disappearing or self-destructing messages, and RSA-2048-based protection that processes data on the user’s own device without a third party in the middle. A further practical detail matters in the Valley: some of these applications still work on slower 2G or EDGE networks, and some do not require a phone number or email to register.
Virtual SIM cards and an older lesson
The new findings sit alongside another long-running problem: foreign-generated virtual SIM cards. Companies based outside India produce software that can generate phone numbers for use on smartphones through dedicated apps, often leaving a thin digital trail. Officials said agencies have stepped up efforts against this method as they map the latest communication channels.
The technique is not new. It was first laid out in detail during the National Investigation Agency probe into the 2019 Pulwama attack, in which 40 CRPF personnel were killed. Investigators found that more than 40 virtual SIM cards had been used by the Jaish-e-Mohammed suicide bomber and his accomplices. The latest reports suggest handlers are combining older tools such as virtual SIMs with newer, less visible chat environments.
Why the shift happened
The pattern described by officials is one of adaptation. Once mainstream social media and popular encrypted messengers came under closer watch, networks looked for quieter corners of the internet. Gaming platforms were one such corner. Pornography sites with dating-style chat rooms were another. Tor-based and no-SIM messengers added a further layer of concealment.
That does not mean the older platforms have vanished from the picture. It means handlers are mixing channels and choosing the ones that are hardest to attribute. A recruit may be approached in a chat that looks like a dating conversation, then moved onto an app that needs no phone number, then given instructions that disappear after they are read. VPN use sits underneath much of this activity, especially where the relevant apps are blocked in India.
Officials also noted that handlers appear to test platforms with different security levels rather than relying on a single tool. That variety itself is a problem for investigators. A network that hops between a banned porn app, a Tor messenger and a France-based no-SIM service does not leave a single, clean trail.
How agencies say they are responding
Security agencies said they are adapting cyber-surveillance systems to map and intercept these off-grid channels. The work includes watching specific applications, tracking illegal downloads through VPNs, and linking the new chat methods to the existing campaign against virtual SIMs. Officials argued that bans on some of the applications were justified because the same encrypted features were being used to recruit and radicalise youths in Jammu and Kashmir.
The challenge is technical as much as it is operational. Traffic that travels through Tor relays is designed to hide its path. Apps that do not ask for a SIM or email leave fewer account records. Chats that sit inside entertainment or dating-style sites are easy to dismiss as ordinary traffic until a pattern of contact with known handlers appears. Agencies therefore have to combine technical monitoring with older methods: human intelligence, device seizures, and the reconstruction of networks after arrests.
What the tactic reveals
The reports do not claim that pornography sites have replaced every other channel. They describe a widening toolkit. Terror outfits and ISI-linked handlers are using whatever digital space still offers a mix of reach, deniability and weak routine monitoring. For recruits in the Valley, that can mean first contact in a place that looks nothing like a militant forum.
The same reports also show the limits of treating this as a purely technological contest. Bans and APK restrictions slow some users down. They do not stop those who already know how to use a VPN. Tor was not built for terrorism, yet its anonymity features are being exploited. Virtual SIMs were a problem in 2019 and remain one in 2026. Each time one path is squeezed, another is tested.
What agencies have described this week is therefore less a single new app than a habit: keep moving to the next unwatched corner. Pornography sites with live chat, Tor messengers such as Coatex and Conion, no-SIM encrypted apps, Moonchat variants, and foreign virtual SIMs now sit in that category. The task for security agencies is to treat those corners as part of the same network rather than as isolated oddities, and to keep updating their own systems as the list of tools grows.