Terrorist groups aiming to harm India are increasingly moving their recruitment, radicalization, and funding activities online. They’re using tools like encrypted messaging apps, VPNs, fake social media profiles, and cryptocurrency to avoid detection by authorities.
Based on my research, and according to recent reports from ETV Bharat citing senior security officials, there’s been a new wave of concern following the latest nationwide raids and arrests conducted by the National Investigation Agency (NIA).
Show
The ‘Three-App Model’ Emerging From NIA Probes
Recent investigations by the NIA, including searches at twenty locations in July and subsequent arrests, have uncovered a concerning pattern of terrorist recruitment. Officials say recruiters are targeting young people online, starting with public platforms like Instagram. They then move these individuals to secure messaging apps like Telegram for radicalization and planning attacks. Finally, recruits are directed to cryptocurrency channels to receive funding.
According to the report, people being recruited into extremist groups are slowly introduced through private Telegram chats. They start with basic ideological ideas, which become increasingly extreme over time. Eventually, some are told to create false online profiles, find weapons, and even travel to countries like Pakistan or Afghanistan for training from individuals connected to the group.
Similar tactics have appeared in Tamil Nadu, Vijayawada, and Mangaluru, with suspects reportedly using apps like WhatsApp, Telegram, and Viber, alongside cryptocurrency systems, to connect with and radicalize new members. Authorities also say terrorist groups are now utilizing AI tools, complex online networks, and servers hosted in other countries to avoid detection by investigators.
Post-Pahalgam Surge and the Push Toward Anonymity
Following the terrorist attack in Pahalgam and India’s subsequent Operation Sindoor, groups operating from across the border have increased their efforts to recruit young people online. According to a senior security official, they are using tools like virtual private networks (VPNs) to do so. These VPNs, along with encrypted communication and fake social media accounts, allow handlers to conceal their identities, take advantage of legal loopholes, and spread extremist material more easily while avoiding detection.
In the past, people became radicalized mainly by attending meetings and exclusive training sessions. Now, officials report this process has moved overwhelmingly online. Extremist groups are using secure messaging apps and VPNs to secretly plan illegal activities, like recruiting new members.
Crypto Emerges as the Preferred Funding Rail
Over the past year, Indian agencies have been particularly focused on the financial aspects of terrorist activities. A counter-terrorism strategy released in February 2026 by the Ministry of Home Affairs, called PRAHAAR, highlighted a growing trend: terrorist groups are using cryptocurrency to move money in ways that avoid typical anti-money laundering and identity verification procedures.
Recent events have highlighted this concern. In March 2026, authorities in Uttar Pradesh, India arrested a 19-year-old dental student from Moradabad who was suspected of operating an online network connected to ISIS and using cryptocurrency. Investigators believe he communicated with people in Pakistan, Afghanistan, and Turkey through encrypted apps like Session and Discord.
Last month, authorities in Gujarat shut down a cryptocurrency network used to fund terrorism, worth approximately $27 million (Rs 226 crore). Investigators found that the network moved money using cryptocurrencies like USDT and Monero through cities including Ahmedabad, Mumbai, and Karnal.
Investigators in Jaipur, Rajasthan are looking into whether members of a Jaish-e-Mohammed cell received money using cryptocurrency. They’re also investigating communication between the accused and operatives in Pakistan via WhatsApp and secure messaging apps. Meanwhile, a blockchain analysis company called TRM Labs has identified hundreds of transactions – ranging from $100 to $15,000 – connected to ISKP, most of which were sent through Tether on the Tron network.
NIA’s Cyber Counter-Terror Upgrade
To stay ahead of evolving threats, India’s National Investigation Agency (NIA) has strengthened its ability to fight cyber terrorism. Its Anti-Cyber Terrorism Division (ACTD) now focuses on monitoring the dark web, tracking secure messaging apps, gathering information about cyber threats, and conducting digital forensics – all while working closely with other intelligence agencies like the Intelligence Bureau and R&AW. Local police forces, who are usually first to respond to incidents, have also received specialized training to improve their skills in this area.
According to officials, the agency keeps an updated list of encrypted apps used by terrorist organizations. They utilize tools created by DRDO – like analyzing metadata, IP detail records, and the NETRA system for monitoring internet traffic – to track down potentially dangerous online activity.
As part of my research, I’ve been following the government’s efforts to counter online extremism. The Ministry of Electronics and Information Technology (MeitY) has already removed over 9,845 web addresses that hosted radical content, and they’re constantly monitoring the internet to find and take down more extremist propaganda. Separately, the Financial Intelligence Unit is now asking cryptocurrency exchanges to increase their scrutiny of transactions coming from border areas. They’re particularly focused on private wallets and direct transfers between users, as these can sometimes avoid the usual checks and balances.
In July, the National Investigation Agency (NIA) conducted raids at 20 locations across about ten states – including Uttar Pradesh, Andhra Pradesh, Maharashtra, and Delhi – as part of a case involving online radicalization. The case, originally started by police in Vijayawada (case number RC-01/2026/NIA/VSKP), uncovered materials connected to the banned groups AQIS and ISIS. So far, eleven adults and one minor have been arrested in connection with the investigation.
Recent disclosures to the crypto industry in India confirm a trend that authorities have been signaling for the past year through initiatives like PRAHAAR, enforcement actions by the ED, and FIU-IND circulars. Meeting requirements for Know Your Customer (KYC) checks, tracking high-risk wallets, and cooperating with law enforcement investigations are now standard expectations, rather than things that set companies apart.
2026-07-22 15:18