LIVE DISPATCH
Digital Pathways to Extremism: An Investigative Study of ISIS and Al-Qaeda's Use of Digital Platforms in India Sports, Strategy and Statecraft of Mega Sporting Events as Geoeconomic Instruments: Qatar 2022 to Saudi Arabia 2034 Strategic Autonomy in the Age of Weaponised Interdependence: India’s Geopolitical Dilemma Hardening the Quad: From Strategic Dialogue to Operational Cooperation China’s Grey-Zone Strategy in the Indian Ocean: Implications for India’s Maritime Security The Maghreb of States: Identity, Sovereignty, and the Limits of Non-Interference Europe’s Digital Dependence: Can the EU Achieve Strategic Autonomy? Beyond the Battlefield: Understanding Unconventional Security Challenges in Contemporary Geopolitics Cuba’s Economic Crisis and Strategic Relevance: A Peripheral State in Renewed Great Power Competition Trapped in Deterrence: Nuclear Stability and the Persistence of Conflict in South Asia Loss and Damage Finance: From COP28 Pledges to Policy Architecture Extended Deterrence Under Strain: Credibility, Assurance, and the Stability-Instability Paradox in the Indo-Pacific Beyond Consultation: BIMSTEC's Emerging Role in Regional Intelligence and Security Cooperation Maritime India: Security, Trade, and Great Power Competition Between the Desert and the Savannah: Conflict and the Political Economy of Instability in the Sahel Beyond Ukraine: Understanding Putin's Vision of Russian Power The Politics of Ali Khamenei's Funeral Silicon Sovereignty: How Semiconductors Are Redrawing Global Power Hierarchies Operation Sindoor and the Changing Dynamics of India–Pakistan Security The Negative Impact of US–Iran War on the Pacific Region Generative AI, Labour Sovereignty, and the Geoeconomics of India's Service Economy BRICS Expansion and the Multipolar Moment: Opportunity or Strategic Contradiction? India's AI Diplomacy and the Future of Strategic Technologies Foot-Dragging as Feminism: Iran, South Korea, and the Ungovernable Body Lethal Autonomous Weapons Systems and the Governance Deficit: Challenges to International Humanitarian Law and Accountability Beyond Proximity: Why the UAE Occupies a Growing Place in Iran’s Strategic Calculus Great Power Rivalry and the Crisis of the United Nations Why Fiji Matters: The New Geopolitics of the Indo-Pacific Islands Ten Years After Brexit: Regret, Reform, or Reversal? The Long Shadow of 1953: Understanding the Iran–US Conflict Border Fencing and National security: India’s Strategy along the Bangladesh Border Lingering Effects of the Bush Doctrine on Contemporary US Foreign Policy India’s BRICS 2026 Chairmanship Navigating a tightrope Amidst the Chinese Geopolitical Rise The Control Paradox: How Proxy Warfare Enables Strategic Deniability While Constraining Strategic Control The Return of Unipolarity? U.S Strategic Primacy and the Future of the Global Order Supply Chains and Complicity: The Role of Global Corporations in Forced Labour in Xinjiang The Distant Threat: Is Israel Constructing a Strategic Rival in Pakistan Island Militarisation and Techno-Diplomacy: Turkey’s Eastern Mediterranean Fault Lines Amid India-Greece Alignment India’s Security Scenario: An Assessment of its Continental and Maritime Challenges The Geopolitical Architecture of European Defence: Navigating NATO Synergies, Transatlantic Retrenchment, and the Hybrid Threat Landscape Digital Pathways to Extremism: An Investigative Study of ISIS and Al-Qaeda's Use of Digital Platforms in India Sports, Strategy and Statecraft of Mega Sporting Events as Geoeconomic Instruments: Qatar 2022 to Saudi Arabia 2034 Strategic Autonomy in the Age of Weaponised Interdependence: India’s Geopolitical Dilemma Hardening the Quad: From Strategic Dialogue to Operational Cooperation China’s Grey-Zone Strategy in the Indian Ocean: Implications for India’s Maritime Security The Maghreb of States: Identity, Sovereignty, and the Limits of Non-Interference Europe’s Digital Dependence: Can the EU Achieve Strategic Autonomy? Beyond the Battlefield: Understanding Unconventional Security Challenges in Contemporary Geopolitics Cuba’s Economic Crisis and Strategic Relevance: A Peripheral State in Renewed Great Power Competition Trapped in Deterrence: Nuclear Stability and the Persistence of Conflict in South Asia Loss and Damage Finance: From COP28 Pledges to Policy Architecture Extended Deterrence Under Strain: Credibility, Assurance, and the Stability-Instability Paradox in the Indo-Pacific Beyond Consultation: BIMSTEC's Emerging Role in Regional Intelligence and Security Cooperation Maritime India: Security, Trade, and Great Power Competition Between the Desert and the Savannah: Conflict and the Political Economy of Instability in the Sahel Beyond Ukraine: Understanding Putin's Vision of Russian Power The Politics of Ali Khamenei's Funeral Silicon Sovereignty: How Semiconductors Are Redrawing Global Power Hierarchies Operation Sindoor and the Changing Dynamics of India–Pakistan Security The Negative Impact of US–Iran War on the Pacific Region Generative AI, Labour Sovereignty, and the Geoeconomics of India's Service Economy BRICS Expansion and the Multipolar Moment: Opportunity or Strategic Contradiction? India's AI Diplomacy and the Future of Strategic Technologies Foot-Dragging as Feminism: Iran, South Korea, and the Ungovernable Body Lethal Autonomous Weapons Systems and the Governance Deficit: Challenges to International Humanitarian Law and Accountability Beyond Proximity: Why the UAE Occupies a Growing Place in Iran’s Strategic Calculus Great Power Rivalry and the Crisis of the United Nations Why Fiji Matters: The New Geopolitics of the Indo-Pacific Islands Ten Years After Brexit: Regret, Reform, or Reversal? The Long Shadow of 1953: Understanding the Iran–US Conflict Border Fencing and National security: India’s Strategy along the Bangladesh Border Lingering Effects of the Bush Doctrine on Contemporary US Foreign Policy India’s BRICS 2026 Chairmanship Navigating a tightrope Amidst the Chinese Geopolitical Rise The Control Paradox: How Proxy Warfare Enables Strategic Deniability While Constraining Strategic Control The Return of Unipolarity? U.S Strategic Primacy and the Future of the Global Order Supply Chains and Complicity: The Role of Global Corporations in Forced Labour in Xinjiang The Distant Threat: Is Israel Constructing a Strategic Rival in Pakistan Island Militarisation and Techno-Diplomacy: Turkey’s Eastern Mediterranean Fault Lines Amid India-Greece Alignment India’s Security Scenario: An Assessment of its Continental and Maritime Challenges The Geopolitical Architecture of European Defence: Navigating NATO Synergies, Transatlantic Retrenchment, and the Hybrid Threat Landscape
ADVERTISEMENT
History September 13, 2026 5 Reads

Digital Pathways to Extremism: An Investigative Study of ISIS and Al-Qaeda's Use of Digital Platforms in India

H
By Herumb Choureya
Author • Centre for Security & Strategic Studies
Digital Pathways to Extremism: An Investigative Study of ISIS and Al-Qaeda's Use of Digital Platforms in India
Share Analysis:
EXECUTIVE SUMMARY & STRATEGIC TAKEAWAYS

Digital platforms have increasingly become important spaces for extremist propaganda, ideological influence, recruitment and network-building. Groups such as ISIS and Al-Qaeda have adapted to the changing digital environment by using mainstream social media platforms to attract audiences and encrypted applications to facilitate more private communication. This transition has created new challenges for counterterrorism agencies, particularly in identifying the movement of individuals from open online spaces to restricted digital networks.

This article examines the use of digital platforms by ISIS and Al-Qaeda in India, with particular attention to online radicalisation, propaganda dissemination, recruitment networks and the migration of extremist activity to encrypted platforms. It explores how social media content, anonymous accounts, online handlers, closed groups and cross-platform communication contribute to the development of digital pathways towards extremism. The article also discusses selected investigations and reported networks to assess the relationship between online activity and alleged terrorist facilitation.

ADVERTISEMENT

As the digital environment has become an increasing component of modern-day terrorist activity, social media has also become an increasingly important tool for terrorist organisations such as the Islamic State (IS) and Al-Qaeda (AQ). It is no longer just used as propaganda but also as a means to contact and recruit members of the public, spread their ideology and have initial contact with those who may later be moved into restricted online spaces. In India, we have seen this in a number of recent investigations in which social media activity, particularly on Instagram, preceded contact with handlers, participation in closed groups and in some cases alleged movement towards operational activity.

This is not a new phenomenon. Around a decade ago, there were cases of individuals from Kerala, Maharashtra, and other parts of India who had travelled to the Middle East and Afghanistan to join ISIS/Al-Qaeda. The role of the online platforms to make contact and have influence on the perpetrators was already apparent back then. What has changed is the ecosystem. Repeated platform-level crackdowns and countermeasures have resulted in terrorist actors moving to other encrypted services, closed groups and in some cases to dedicated platforms/channels.

The importance of this change in tactics became clearer during the wave of arrests carried out by the NIA and state ATS units in March and April 2026. Almost 25 individuals found to have been in contact with IS or AQ handlers and operatives. While the circumstances of each case varied, one feature that kept coming up was the social media, particularly Instagram, played a role at the early stages of contact. The arrests therefore provide a useful starting point for examining how online engagement can develop into wider extremist networks.

It is most visible when the individual cases are looked at chronologically. Taken together, the arrests that have been made over this period show that the online contacts were not isolated incidents, but that they were part of wider networks that could span several states or even extend beyond India.

Cases of Arrests

Vijayawada Module

On March 22-23, three youths from Vijayawada were arrested as they had developed contacts with the ISIS activists operating in Hyderabad, Bihar, Karnataka, West Bengal, Delhi and many other parts of India and abroad. The investigators claimed that the accused had planned to carry out terrorist activities in different parts of the country. During interrogation, the accused have admitted that they were attracted towards ISIS and Al-Qaeda propaganda and were following social media groups of ISIS, AQIS and the extremist preachers. They were also found to have posted the content online.

A day later on 25 March, Andhra Pradesh Police arrested three more suspects from Hyderabad, Ballari in Karnataka and Jodhpur in Rajasthan. The accused were identified as Sayeeda Begum, Abdul Salaam and Jishan. Sayeeda was identified by Sharif as the person with whom he had been in touch for a long time.

Jishan had reportedly been associated with the network for around two years. He had also passed an online test before being appointed as an administrator of the BENX Group, a network that had links with IS. Further arrests followed in Bihar, Delhi, Maharashtra and West Bengal on March 26–27. By March 28, police confirmed 12 arrests and announced the busting of the module.

Extremist literature, bomb-making manuals and other radical material were recovered from the accused.1

Other Arrests in April–May 2026

1.On April 4, the Delhi Police Counter Intelligence team arrested an ISIS suspect identified as Rizwan from Kushinagar, Uttar Pradesh. His movements had reportedly been under surveillance for some time. He had earlier been arrested in Mumbai, where anti-national material was recovered.2

2.On April 5, Delhi Police arrested Mosab Ahmed alias Kalam and Mohammad Hamad Kalra from Kalyan and Kurla West in Maharashtra. The two were linked to ISIS and were also reportedly in contact with a Jaish-e-Mohammed handler.3

3.On April 21, the Gujarat ATS arrested two individuals accused of plotting anti-national attacks, spreading radical ideology online and attempting to build a Ghazwa-e-Hind network in India. Investigators recovered bomb-making plans, extremist chats and objectionable literature.4

4.In April, the Uttar Pradesh ATS arrested two men in Bijnor in connection with what officials described as a wider terror-linked network allegedly operated through social media by a Pakistan-linked handler based in West Asia. Earlier, on April 2, the ATS had detained four men from Meerut and Gautam Nagar in connection with the same module. The investigation initially pointed towards a suspected conspiracy to target Lucknow railway station. The two Bijnor suspects were allegedly linked to Aquib, based in West Asia, and Maizal, based in South Africa.5

5.On May 6, the West Kutch-Bhuj SOG arrested a youth identified as Fakirmand Isha Gagda for allegedly spreading ISIS propaganda and ideology through social media.6

The cases also raise the broader question of what draws people into these networks in the first place• Online contact does not arise in a vacuum. It often develops in an environment where grievance, ideology and repeated exposure to extremist material reinforce one another.

Drivers of Radicalisation

Dr. Abhinav Pandya, in his book Radicalisation in India, identifies multiple factors that can contribute to the radicalisation of impressionable individuals. Several of these factors remain relevant both on the ground and in the digital environment.

These include contemporary issues perceived as being directed against the Muslim community in India; the propagation of radical Salafi ideology; and the movement of sections of the youth away from syncretic Sufi-Barelvi customs under the influence of extremist preachers.

Another factor is the manipulation of users by the use of very motivational, visually attractive and emotionally appealing social media content. The recommendations in algorithms can repeatedly expose users to material that reinforces existing grievances or introduces more extreme views. Perceived injustices and alleged atrocities against Muslims by fringe right-wing elements can also be exploited by extremists. The interpretation of the Quran presented by radical preachers is also part of this process.

Some people are led to believe that the Khilafah is the ideal system of governance and not democracy or any other political system. They also believe that it will bring back the era of the Prophet and his companions. Global conflicts such as Chechnya, Bosnia, Gaza, Syria and Iraq are used as examples again and again to push these ideas of a common grievance as a result of propaganda of the various enemies of the Muslims like the ISI.7

These drivers become particularly important when they intersect with the way extremist material is presented online. The transition from ideological curiosity to sustained engagement is often as much about the format and frequency of exposure as it is the content.

From Engagement to Radicalisation: The Appeal of Extremist Content

Short-form video has become one of the most accessible forms of online content. On Instagram, in particular, Reels allow extremist supporters and operatives to reach large audiences without requiring direct interaction at the initial stage.8

Supporters and operatives of ISIS and AQ, often referred to as munasireen, have used short-form videos featuring extremist nasheeds in the background. The videos can include speeches by militants and preachers on jihad, Khilafah and Sharia, or footage of attacks and ambushes carried out against Western forces.9

Extremist Salafi nasheeds also play an important role in this propaganda mix. The rhythmic and melodic nature of the nasheeds, despite the absence of musical instruments, has the potential to elicit strong emotional responses from the viewer. They can be used to reinforce the group identity of the IS/AQ supporter, inspire their followers and to promote the messages of IS/AQ. In this regard, nasheeds function not just as background audio but as part of the wider propaganda and recruitment tools of IS/AQ.10

In addition, the visual presentation of such content has changed : Instagram Reels are often heavily edited, often using motion effects and other tricks to make the videos more visually appealing. In Indian context, clips of mob lynchings, bulldozer actions, and alleged atrocities by fringe right-wing groups are often intermixed with material that riles people up, disseminates extremist messages, and is all presented in a slick manner. 11

This applies to the BENX case as well. Unlike the account discussed in the investigation, the network described includes multiple accounts, administrators, restricted groups, and supporting infrastructure.

Investigative Findings: The BENX Network

The BENX Group case provides an indication of how a digital network can develop around extremist content. The group had maintained a presence on Instagram for an extended period. More than 40 accounts were reportedly affiliated with the network, many of them using 'benx' in their account names. Some profiles appeared to be based in Pakistan, Afghanistan and Bangladesh.

These accounts posted reels featuring radical nasheeds and extremist preachers. Several reels received more than one lakh views and thousands of likes, indicating a substantial level of engagement and a wider support network.

Apart from accounts carrying the BENX name, other profiles were reportedly operated by the same network and directly posted pro-ISIS content. One backup profile, identified as @1s1s_hafisha, had several thousand followers, while multiple other Main profiles appeared to have been managed by the same administrator.

The group also maintained a GitLab and GitHub repository titled 'DarkNoorAgents'. Based on the material described in the investigation, such repositories may have been used for maintaining propaganda infrastructure, archiving material, collaboration and content management, as well as communication-related functions. The group was also reported to possess cyber-offensive and defensive capabilities.

The network additionally maintained a restricted Instagram channel in which entry was limited to selected individuals. The principal administrator, identified as Drxn.benx and apparently the founder of BENX COM and TEAM DARK NOOR AGENTS, had around 107,000 followers. The scale of this audience is significant, given the nature of the content associated with the account.

Sources have linked Drxn.benx to another alias, 'NOOR-THE VIP HACKER'. Some unverified accounts claim that TEAM DARK NOOR AGENTS was established in 2013 and represented a combination of a Salafi-jihadist framework and a group of cybersecurity specialists. The same sources claim that the team maintained a strategic relationship with ISIS.

The name TEAM DARK NOOR AGENTS had surfaced in early 2024 alongside hacktivist groups such as Mysterious Team Bangladesh, Team Insane Pakistan, Khan Cyber Army, Team 1919 and Team Anon Force. This occurred during claims surrounding the alleged release of two billion Aadhaar cards. The claim was entirely a hoax. Although the breach claim was not directly attributed to Mysterious Team Bangladesh, that group promoted it while Team Insane Pakistan was described as playing a leading role. The episode nevertheless brought attention to the network's reported links with Islamist hacktivist circles.

Drxn.benx's profile claimed that he was based in Kabul, Afghanistan. Other sources and investigative material, however, have suggested that he may have been based in India and used the Afghan location to avoid the attention of Indian agencies. One piece of circumstantial evidence cited in this context is a review under the name 'DRXN BENX' on Acer's website for a purchase made at an Acer store in Lucknow on November 24, 2025.12

The group propagated material featuring Osama bin Laden, Israr Ahmed, Zakir Naik and Anwar al-Awlaki. Investigators also linked the network to handlers based in Pakistan, Afghanistan, Syria and Bangladesh through more than 40 social media accounts. Individuals identified by aliases including Al Hakeem Shukoor, Ninja, Hemorxy, Abu Muharib and Abu Balushi were alleged to have provided guidance on militant training, weapons and the supply of arms.

Some radicalised individuals associated with the wider network were reportedly already studying at Islamic religious institutions abroad, while efforts to recruit additional individuals continued.13

The BENX network is significant not only because of its scale, but because similar patterns appear in other investigations. Across the cases discussed below, online activity increasingly intersects with recruitment, fundraising, closed groups and alleged preparations for violence.

Online Radicalisation Across Recent Cases

The arrests made during this period also illustrate how online engagement can progress towards operational activity. In one Mumbai case, the accused allegedly planned to use remote-controlled toy-car bombs. They had joined Islamist groups referred to as 'Soldiers of Jihad' and 'Mission Khilafat' on social media. Investigators also found alleged links with Abu Huzaifa, an individual affiliated with JeM who reportedly used Telegram and other platforms for recruitment.14

In the Gujarat ATS case involving Murshid and Irfan, 21-year-old Murshid maintained an Instagram profile containing posts referring to 'Sar tan se juda', 'Al Jihad' and 'Jihad fi sabilillah', alongside reels featuring Islamist preachers. He had joined and created multiple radical group chats across Instagram, WhatsApp and Telegram.

Murshid administered a Telegram group named 'Dawlatul Islamiyah e Hind' and an Instagram group named 'Jammu & Kashmir'. Several Pakistani JeM and LeT sympathisers were present in these groups and had been added by Murshid. He had also planned to open a bank account to obtain funds for terrorist activities but was arrested before doing so.15

Irfan was similarly attempting to raise funds and gather resources for bomb-making operations. The ATS reportedly found him in contact with ISIS-linked elements and other individuals holding radical views. The accused were also allegedly discussing the training of recruits in making explosives, sending recruits to camps, contacting foreign terrorist organisations and establishing illegal weapons channels linked to Pakistan and Afghanistan.16

In another case, Uvaid Malik and Jalal Haider alias Sameer were linked to Aquib in West Asia and Maizal in South Africa. Their arrests pointed towards an expanding online recruitment and radicalisation network operating through Instagram and other platforms. During interrogation, the accused allegedly told investigators that the handler was using social media to disseminate radical content, incite anti-national sentiments and encourage violent activity. Police also said that the network was attempting to expand its presence in India through sustained digital engagement.17

The common thread across these cases is the movement from open visibility to controlled access. Once an individual has entered the orbit of extremist content, the next stage can involve a shift away from mainstream platforms towards encrypted services.

Encrypted Platforms as Conduits for Radicalisation, Recruitment and Propaganda

Mainstream social media platforms are open, widely used and subject to local legal frameworks. Companies are therefore more likely to cooperate with law-enforcement agencies and comply with requests for information. This makes such platforms more vulnerable to scrutiny and surveillance from the perspective of terrorist actors.

IS and AQ have consequently expanded their presence across encrypted services such as ElementX, SimpleX/Matrix, Signal, Session, Rocket.Chat and Threema. These platforms offer end-to-end encryption and, in some cases, peer-to-peer communication, including voice and video calls. Telegram remains heavily used, but the possibility of channels and accounts being removed has encouraged the use of alternative encrypted platforms.

A significant part of ISIS's propaganda and recruitment infrastructure now exists on ElementX and SimpleX. Its presence on Telegram is increasingly visible through bots. Digital publications and outlets associated with ISIS, including Al-Azaim, Ansar Electronic Security, Ansar Production, Amaq and Al-Naba, as well as Bengali groups, have also maintained a presence on Element and Matrix-based platforms.few Indian and Sri Lankan nationals are present in these groups alongside Bangladeshi users.

ISIS also maintains its own platform, 'Techhaven'. Although the application is available through the Play Store, it operates through the web and is used for propaganda dissemination, discussion and recruitment. The platform contains more than 500 groups, some of which are official ISIS channels. Indian users are also present, including individuals associated with Tamil Nadu's National Thowheed Jamaat and Malayalam-speaking communities.18

A major challenge for investigators is that these encrypted platforms do not maintain grievance offices or comparable local points of contact in India. This can make it difficult for agencies to trace the origins of users and obtain metadata or IP information through conventional channels.

The broader implication is that radicalisation, which historically could take months or even years, can now occur within weeks or even days. Short-form content, algorithmic amplification and the exploitation of developmental vulnerabilities have compressed the time required to move an individual from passive engagement to deeper ideological involvement.

The movement between these platforms is therefore not necessarily random. It can form part of a broader progression in which mainstream platforms provide reach, while encrypted spaces provide greater insulation for deeper ideological and operational engagement.

The Funnel from Mainstream Platforms to Encrypted Networks

The rise of ISIS and its use of social media for propaganda and recruitment created new pathways to radicalisation, particularly among younger users. The organisation's model of encouraging low-sophistication 'inspired' attacks, often involving vehicles or knives rather than explosives, lowered the barrier to entry for potential attackers, including teenagers. Online radicalisation accelerated this trend by allowing minors to consume extremist content without direct physical contact with established terrorist networks.

The internet, social media algorithms and immersive online environments have therefore changed the manner in which radicalisation can take place. Extremist networks use what can be described as a multi-tiered funnel strategy to identify, groom and radicalise vulnerable users.

The process can begin on algorithm-driven mainstream platforms such as TikTok, Instagram, Facebook and YouTube Shorts. Algorithms designed to maximise engagement and retention can inadvertently expose users who interact with edgy or controversial material to increasingly extreme and emotionally charged content. In the extremist ecosystem, this may include videos glorifying terrorist organisations and operatives and normalising extremist aesthetics through short-form video.

Once a user demonstrates ideological affinity or vulnerability, recruiters can shift the interaction to encrypted platforms such as Signal, Telegram, ElementX, SimpleX or Wire. Within these more insulated environments, users can be exposed to intensive indoctrination, tactical discussions, operational planning and the normalisation of extreme violence.

This platform migration also explains why disruption of a single account or channel rarely amounts to the disruption of an entire network. ISIS's digital ecosystem illustrates the extent to which propaganda and communication can be distributed across multiple services.19

Multiplatform Communication and the Evolving ISIS Ecosystem

In January 2025, the Al-Azaim Media Foundation highlighted the centrality of Telegram to the online ecosystem in issue 43 of Voice of Khurasan. At the same time, ISIS supporters have increasingly explored applications that combine privacy, security and anonymity with broadcasting capabilities.

This development is closely linked to the concept of the Multiplatform Communication Paradigm (MCP). The model involves operating across multiple interconnected platforms to communicate with supporters, promote active proselytism and distribute propaganda. For Salafi-jihadist groups, the objective is not to depend on a single platform but to maintain a distributed digital ecosystem in which the closure of one channel does not necessarily disrupt the wider network.20

The online ecosystem cannot, however, be examined only through the lens of individual recruitment. The same digital spaces can also provide indicators of wider organisational linkages and external influence. This becomes particularly relevant in assessing the reported relationship between the ISI, ISIS and ISKP.

Assessing the ISI–ISIS/ISKP Nexus and Its Activities in the Indian Digital Space

The developments associated with ISKP and its online ecosystem have increasingly drawn attention in the context of India's security environment. In late December 2025, several reports indicated the emergence of ISKP as a potential deniable proxy against India. Intelligence Bureau inputs suggested that plans were already underway to expand the group's footprint in India, with Jammu and Kashmir as a principal focus.21

In early February, an Al-Azaim release criticised the TTP, the Afghan Taliban and Baloch groups, accusing them of apostasy for placing nationalism and territorial interests above religion. It also alleged that these groups were supported and financed by India.22

Around the same period, in December 2025, the ISKP propaganda outlet Sawt-al-Hind, which had been active before 2023 and subsequently became dormant, resurfaced under the modified identity 'sawt-ul-Hind'. The Islamic State's official Bengal outlet, Fursan-al-Tawhid, later stated that it was not officially affiliated with ISKP. Nevertheless, the material appeared on official ISIS propaganda websites under the label 'Production of Supporters'.23

The propaganda was disseminated in Hindi, English, Urdu, Bengali and Malayalam through a Signal group, indicating renewed multilingual outreach towards Indian audiences.

Reports also indicated that in September–October 2025, ISKP's Balochistan coordinator Mir Shafiq Mental met Rana Mohammad Ashfaq, a senior LeT figure. The meeting can be seen as evidence of formal coordination between the two groups under ISI patronage.24

In early January, intelligence reports indicated that the ISI had directed the Lashkar-e-Taiba to embed a 12-member fidayeen squad within the ISKP framework. The reported objective was to carry out high-impact attacks in Jammu and Kashmir while attributing them to ISKP, thereby creating plausible deniability and obscuring direct Pakistani involvement.25

The reported ISKP-related developments acquire greater significance when viewed alongside earlier investigations into the Al-Hind ecosystem. The Rameshwaram Cafe investigation, in particular, exposed a network in which older extremist linkages had continued to operate beneath the surface.

The Rameshwaram Cafe Investigation and the Al-Hind Network

Although many of these developments are visible during 2025–26, the network has deeper roots. Following the Rameshwaram Cafe blast on March 1, 2024, the investigation found that the individuals involved had previously been associated with the Islamic State's Al-Hind module and had been absconding since the 2020 busting of that module.

The principal perpetrators, Taaha and Shazib, had links with Mahaboob Pasha and Khaja Moideen, who has been described as the emir of ISIS in South India. Delhi Police later stated that the network was, in reality, an LeT module operating under the appearance of an ISIS module.

According to the chargesheet-related account, Taaha was introduced to Mohammad Shahid Faisal by Shoaib Ahmed Mirza, a former convict in the 2012 Bengaluru LeT conspiracy case. Taaha subsequently introduced Faisal to individuals operating within the IS Al-Hind ecosystem.

The accused were eventually arrested in West Bengal following a nationwide search. Their interrogation opened up a wider terror architecture and indicated that the radicalisation and network involvement extended back several years.

The investigation also brought attention to the individuals who operated behind these networks. Among them, Mohammad Shahid Faisal and Farhatullah Ghori illustrate the connection between older terrorist infrastructures and newer technology-enabled methods of facilitation.26

Mohammad Shahid Faisal and Farhatullah Ghori

The investigation identified an online figure using aliases including 'Colonel', 'Bhai' and 'Ustad/Zakir'. He was later identified as Mohammad Shahid Faisal, the online handler who communicated with Taaha and the wider Thirthahalli module.27

Faisal was not a newly emerged foreign terrorist. He was originally from Bengaluru and had an engineering and technical background. He had been involved in the 2012 Bengaluru LeT conspiracy case and fled to Pakistan in 2013 with the assistance of Farhatullah Ghori, his father-in-law. He subsequently emerged as an important online facilitator. In July 2026, the Ministry of Home Affairs designated Mohammed Shahid Faisal as a terrorist.28

Farhatullah Ghori, also known by aliases including Abu Sufiyan, Sardar Sahib, Faru and Ustadh Farhatullah, left India in 1994 and moved to Riyadh, Saudi Arabia. The Government of India designated him as an individual terrorist in 2020.

While in Saudi Arabia, Ghori was accused of remotely controlling and funding major terror plots executed in India, including the 2002 Akshardham attack. In 2015, the ISI reportedly facilitated his movement from Saudi Arabia to Pakistan, where he formally aligned with JeM and took refuge in Lahore and Rawalpindi.

During his time in Saudi Arabia and later through intermediaries in the UAE, Ghori reportedly established a substantial hawala network for assisting the ISI. He now operates in close coordination with his son-in-law Mohammad Shahid Faisal, who represents the more technology-oriented side of Ghori's operations and handles local execution networks.29

Ghori's newer Al-Hind and Rameshwaram Cafe-linked modules used encrypted digital wallets and decentralised cryptocurrency transfers to finance safe houses and procure bomb-making material. According to findings cited from the NIA chargesheet, Taaha and Shazib received funding through cryptocurrency. The funds were allegedly routed through cryptocurrency and converted into usable money through Telegram-based peer-to-peer mechanisms.

The NIA also found that Taaha and Shoaib obtained Indian SIM cards, bank accounts and identity documents using material sourced through the dark web.30

The significance of Ghori's role is not limited to his earlier operational associations. His re-emergence online demonstrated how an established extremist figure could use digital platforms to re-enter the information and recruitment space.

Farhatullah Ghori's Return to the Digital Space

Ghori re-emerged in 2022 through a series of audio-visual messages distributed across Twitter, Facebook, Instagram and YouTube under the banner 'Sawt-al-Haq'.31 Multiple accounts belonging to supporters and operatives subsequently appeared on Twitter and Facebook, although many of these accounts are now inactive.32

Ghori also launched websites using names including Sawt-al-Haq, Tahreek-e-Qisas and Al-Ummah. He was a close associate of Syed Ahmed Basha, the founder of Al-Ummah. Around 2015, Al-Ummah reformed into the Base Movement, which openly declared allegiance to Al-Qaeda's global ideology.33

The Base Movement carried out a series of low-intensity IED blasts at court complexes in South India under its banner, seeking to establish an Al-Qaeda footprint in the region.

The shift from propaganda to calls for physical action is particularly visible in the railway-sabotage allegations. Here, online messaging was no longer simply ideological; investigators also examined whether it was being used to encourage and facilitate attacks on critical infrastructure.

Railway Sabotage and the Ghori Network

In July 2024, Farhatullah Ghori released a video message calling on followers and sleeper cells to carry out acts of sabotage against railway infrastructure in India. In September 2024, the Home Ministry acknowledged that there had been 18 attempts to derail trains within a period of 55 days.

The frequency of these incidents raised concerns over a wider conspiracy. The central government subsequently directed the NIA to investigate more than 24 such incidents reported during 2023–24.

The NIA found that Ghori was radicalising youth in Delhi, Mumbai, Karnataka, Maharashtra, Uttar Pradesh and Bihar and conspiring with them to carry out attacks. Central investigative sources initially described several incidents as lone-wolf attempts targeting railway infrastructure.

Investigators also found evidence that sleeper cells were being activated and provided online guidance on how to target trains, including instructions relating to objects that could be placed on tracks and methods of detonation. Agencies subsequently suspected the involvement of ISKP and the ISI.

The ISKP module had earlier been implicated in the March 7, 2017 bombing of the Bhopal–Ujjain passenger train. The incident was described at the time as the first ISIS attack in India. Following the bombing, Madhya Pradesh and Uttar Pradesh Police arrested eight terrorists in a joint operation. One member was later killed in an encounter in Lucknow, while others were arrested from Kanpur and Etawah. Investigators also identified several suspects who remained absconding.

In 2024, agencies suggested that Kanpur could have served as a base for Ghori's new module, which was considered significant because many of the railway-related incidents had occurred in Uttar Pradesh.34

The railway-related investigations also brought renewed attention to the wider digital ecosystem through which Ghori-linked and ISI-linked propaganda was circulated. These channels indicate an attempt to sustain a broader information environment rather than rely on a single outlet.

Digital Propaganda Channels Linked to Ghori and the ISI

To radicalise impressionable Youth, ISI-linked actors and Ghori's operatives created Telegram channels and accounts across Facebook, Instagram, Twitter, BitChute, MEGA, Bluesky , Dailymotion and the Internet Archive.35

Among the Telegram channels identified were Pasban Movement of India, Darsgah Urdu, Darsgah Hind, Students of Hind, Tahreek al Hind, Knowyourduty and Hindostan News, among others.36

The content across these channels was not always identical, but substantial overlap was visible. Some Al-Qaeda sympathisers and TTP and IMP supporters from Afghanistan and Pakistan were also present in these groups. Other associated subgroups circulated links to terrorist channels and extremist material.37

SIMI and Indian Mujahideen leaflets and literature, ISIS explosive-making manuals, and propaganda releases of JeM and LeT were reportedly circulated through the main channels. Writings by Safdar Nagori and videos featuring various SIMI leaders were also shared.38

Taken together, these activities suggested an attempt by the ISI to present the network as a home-grown movement and, to an extent, revive the ecosystem for organisations such as Indian Mujahideen and SIMI. ISIS manuals, particularly guidebooks produced by Al-Hadeed Media of ISKP, were also extensively circulated.39

As agencies began monitoring these groups and channels, several disappeared or shifted towards Element and Signal. Some Facebook pages and Instagram handles were also withheld or banned in India by the central government.

During 2024–25, a coordinated campaign by the ISI involved multiple accounts posting radical propaganda. Links to group chats and channels across Telegram, Signal and Element were circulated through many of the Telegram channels by ISI linked actors.(Some group names cannot be publicly named).4

During the investigation into the 2025 Red Fort blast, investigators reportedly found that the perpetrators had been part of a Telegram group named 'Farzandan Darul Uloom Deoband'. Links to join this group had already been circulated across different Telegram circles named above, by the ISI and continued to circulate even after the channel was banned in India.41

A significant development is that several of these groups, particularly those linked to Farhatullah Ghori, have shifted to ElementX, where ISIS propaganda is reportedly being circulated extensively. Some ISIS operatives, primarily from Bangladesh, are also reportedly present in these groups.

Alongside links to Ghori's propaganda channels, links to Bengal-based Islamic State groups have increasingly been circulated. This development has been cited as another indicator of possible coordination between the ISI and ISKP.42

Around June 2026, advertisements reportedly appeared on Instagram and Facebook promoting Sawt-al-Haq propaganda. The profiles running these advertisements appeared to have been created or activated only recently. The reported method involved acquiring pre-existing profiles based in the United States and Europe and subsequently using them to distribute radical content.43

While the ISIS ecosystem has received considerable attention because of its strong presence on visual and encrypted platforms, Al-Qaeda's digital strategy follows a somewhat different pattern. Its infrastructure places greater emphasis on dedicated websites, forums and region-specific publications.

Al-Qaeda's Digital Infrastructure and Cyber Activities

Al-Qaeda's digital infrastructure differs in important respects from that of ISIS. While ISIS has maintained a particularly visible presence on Instagram, AQ has been less active there. ISIS does not maintain a dedicated website focused exclusively on the Indian subcontinent, whereas AQ has maintained region-specific websites for propaganda dissemination.44

AQ-linked groups based in Bangladesh have also used Pinterest, a platform widely used by younger audiences for sharing visually oriented content. AQ maintains a significant presence on Facebook as well.

AQ also operates dedicated web forums. One such forum is associated with its Bengal province and has a predominantly Bangladeshi user base. The forum carries magazines and daily news updates and allows members to communicate, discuss issues and post content.

The forum also contains dedicated sections dealing with different regions and domains, including information security. Tutorials relating to Kali Linux have also reportedly been uploaded there, indicating that parts of the ecosystem extend beyond conventional propaganda and into technical knowledge sharing.45

AQ also maintains a presence across many of the encrypted platforms used by ISIS. Like ISIS's Techhaven, AQ has its own encrypted platform, 'gnews', apparently developed by AQ itself.

One notable security feature is the manner in which registrations are handled. AQ does not keep registration open continuously; instead, registration windows reportedly open at specific times, reducing the opportunity for agencies to infiltrate the platform.46

Another platform used by AQ is Chirpwire, which resembles Twitter/X but operates at a comparatively slower pace. TTP, TRF and other organisations are also present on the platform, although AQ users reportedly constitute the largest segment.47

These differences become clearer when the activities of Al-Qaeda in the Indian subcontinent are examined alongside recent developments. AQIS has maintained a distinct regional propaganda architecture while also using many of the same mainstream and encrypted platforms.

AQIS Activity and the Red Fort Blast

A few months before the 2025 Red Fort blast, which was alleged to have been carried out by AGuH and JeM, several profiles linked to AGuH became active and began posting radical propaganda produced by AQIS's Al-Hurr media outlet. One of the profiles was identified as 'Doctor Sahab', apparently associated with an individual from the Faridabad module.48

AQIS maintains a presence across ElementX, Signal, Threema, Rocket Chat, Telegram and Facebook. It has also used these platforms to disseminate its magazine As-Sahab, which focuses primarily on the Indian subcontinent. On Facebook, many followers of AQ-linked pages are reportedly based in Pakistan.49

AQIS also maintains a dedicated website. Around a week before the Red Fort blast, an article titled 'The Time is Approaching....' was published under a section titled 'Kashmir – doorway to Ghazwa-e-Hind'. The timing of the publication, when viewed alongside the subsequent attack and related developments, warrants attention.50

In early May, reports also indicated that AQIS and the Base Movement, the successor network associated with Al-Ummah, had several operatives across India. These individuals had reportedly maintained a low profile for years. The recent increase in online activity being detected by intelligence agencies suggests that some of these networks may be preparing to become operational again.51

Conclusion

The cases discussed in this study show that ISIS and Al-Qaeda in India go well beyond propaganda. Social media can be the initial point of contact, while encrypted and less visible platforms can provide a space to continue communicating away from the public eye. The movement between these spaces has become an important feature of extremist activity allowing networks to maintain a public presence, while recruiting and communicating in more restricted environments.

Our investigations also show how these networks have adapted to repeated disruption. The BENX case demonstrates how networks use multiple social-media accounts, restricted groups and supporting digital infrastructure. Investigations into the Al-Hind network and the activities of Farhatullah Ghori show how networks with older operational roots have embraced encrypted communications, cryptocurrencies and online recruitment. The distinction between propaganda, recruitment and facilitation is becoming harder to maintain.

recently some reports are came out which revealed that the shift is continuing beyond the platforms that are normally used for communication by the terror outfits. The security agencies have found the handlers of terrorist recruits using pornography sites with chat functions,niche encrypted apps, anonymous platforms and virtual SIMs to communicate with the recruits in Jammu and Kashmir. Some of these don’t require a conventional phone number or email address while others use encrypted or anonymous communication system. The significance of the development is not so much in the particular platform as much in the fact that the terror outfits are happy to shift to less conventional digital spaces when the established ones become easier to monitor.

Such a change in the nature of digital networks also makes it possible for recruits to no longer remain in one platform or communication service throughout the process. Contact can begin in an open environment, then move to a private group and eventually to a platform designed to hide the identity of its users. The same network can thus leave traces in several services without any one account providing a clear picture of its activity.

The recent reports on JeM and AQIS too show the importance of looking beyond specific organisations. The intelligence-based reporting on the two groups has pointed to attempts by them to expand their network in India, with JeM trying to rebuild its capabilities in Jammu and Kashmir and AQIS trying to strengthen its ideological and recruitment network elsewhere. The reported attempt by ISI-linked outfits to use different organisations and fronts too shows how attribution too can become part of the problem. For investigators, as much importance is attached to who is behind an account or module or an attack as the activity itself.52

The cases examined in this paper show that ISIS and Al-Qaeda have developed different yet adaptable digital ecosystems in India. ISIS has emphasised visual propaganda, mainstream social media and encrypted communication on multiple platforms. Al-Qaeda has relied on its dedicated websites, forums and regional publications. Both have shown that disrupting one platform does not necessarily mean the disappearance of the network behind it.

This is where the virtual and physical aspects of the threat begin to overlap. A group does not have to have a large physical presence before it can develop an audience, identify sympathisers and make contact with potential recruits. Conversely an existing physical network can use the digital world to extend its reach without having to be visible in every place it has contacts.

For Indian security agencies, identifying the digital pathways is as important as the identification of individual accounts. This is because we can see movement from one platform to the other, contact with handlers outside India, repeated use of anonymous or encrypted services and the same material being spread across different online spaces.

This study has shown that the online presence of ISIS and Al-Qaeda in India is neither static nor limited to social media. Their network have shown an ability to adapt to platform restrictions, shift communication channels, maintain contact with individuals in India, and combine online activity with existing organisational structures. Recent cases also show that the next stage of this activity may be harder to identify because communication is increasingly moving into spaces, such as gaming platforms that were not originally designed as terrorist platforms.

For counter-terrorism agencies, the challenge goes beyond removal of extremist content or mere identification of the propagandist. We need to understand the pathway by which individuals are exposed to extremist content and recruited and brought into private communication, and the role of the digital domain in this process. We need to understand how these networks move through this space in order to detect emerging modules before an online connection becomes an operational one.

References:

1. The New Indian Express, “NIA Traces Online Terror Radicalisation Network from Vijayawada to Six States,” June 28, 2026,https://www.newindianexpress.com/cities/vijayawada/2026/Jun/28/nia-traces-online-terror-radicalisation-network-from-vijayawada-to-six-states(See also National Investigation Agency, “RC-01/2026/NIA/VSKP,”https://nia.gov.in/rc-012026niavskp)

2. The Hindu, “UP Man Held by Delhi Police on Suspicion of Terror Links,”https://www.thehindu.com/news/cities/Delhi/up-man-held-by-delhi-police-on-suspicion-of-terror-links/article70826042.ece

3. Economic Times, “Delhi Police Arrest Two for Links with ISIS and Jaish-e-Mohammad,”https://economictimes.indiatimes.com/news/india/delhi-police-arrest-two-for-links-with-isis-and-jaish-e-mohammad/articleshow/130043132.cms’from=mdr

4. The New Indian Express, “Gujarat ATS Arrests Two for Allegedly Plotting Anti-National Attacks,” April 21, 2026,https://www.newindianexpress.com/india/2026/Apr/21/gujarat-ats-arrests-two-for-allegedly-plotting-anti-national-attacks (See also Dainik Bhaskar, “Gujarat ISIS Recruitment Plot: Two Arrested,”https://www.bhaskar.com/g/national/news/gujarat-isis-recruitment-plot-two-arrested-137751942.html)

5. India Today, “Uttar Pradesh ATS Arrests Terror Suspects, Pakistan Handler, Social Media,” April 11, 2026,https://www.indiatoday.in/india/story/uttar-pradesh-ats-arrests-terror-suspects-pakistan-handler-social-media-2894779-2026-04-11

6. The Hindu, “Man Held in Gujarat’s Kutch for Promoting ISIS Ideology on Social Media,”https://www.thehindu.com/news/national/gujarat/man-held-in-gujarats-kutch-for-promoting-isis-ideology-on-social-media/article70931641.ece

7. Dr. Abhinav Pandya, Radicalisation in India.

8. based on author’s own investigation

9. based on author’s own investigation.

10. Global Network on Extremism and Technology, “Extremist Nasheeds, Emerging Subcultures and the Cultivation of Radical Online Communities in Southeast Asia,”https://gnet-research.org/2026/02/25/extremist-nasheeds-emerging-subcultures-and-the-cultivation-of-radical-online-communities-in-southeast-asia/

11. based on author’s own investigation.

12. based on author’s own investigation.

13. based on author’s own investigation.

14. The Daily Pioneer, “Delhi Police, Maharashtra ATS Foil ISIS-Linked IED Toy Car,”https://dailypioneer.com/news/delhi-police-maharashtra-ats-foil-isis-linked-ied-toy-car

15. based on author’s own investigation.

16. The New Indian Express, “Gujarat ATS Arrests Two for Allegedly Plotting Anti-National Attacks,” April 21, 2026,https://www.newindianexpress.com/india/2026/Apr/21/gujarat-ats-arrests-two-for-allegedly-plotting-anti-national-attacks

17. India Today, “Uttar Pradesh ATS Arrests Terror Suspects, Pakistan Handler, Social Media,” April 11, 2026,https://www.indiatoday.in/india/story/uttar-pradesh-ats-arrests-terror-suspects-pakistan-handler-social-media-2894779-2026-04-11

18. based on Author’s own investigation.

19. Institute for Economics & Peace, Global Terrorism Index 2026,https://www.visionofhumanity.org/wp-content/uploads/2026/03/Global-Terrorism-Index-2026-Report.pdf

20. Global Network on Extremism and Technology, “Remaining and Expanding: IS Munasirin and the Pro-Islamic State Ecosystem on SimpleX Chat,” August 7, 2025,https://gnet-research.org/2025/08/07/remaining-and-expanding-is-munasirin-and-the-pro-islamic-state-ecosystem-on-simplex-chat/

21. IANS, “ISKP Emerges as Pakistan’s New Deniable Proxy against India,” December 31, 2025,https://ianslive.in/iskp-emerges-as-pakistans-new-deniable-proxy-against-india--20251231112414

22. based on Author’s own investigation.

23. based on author’s own investigation.

24. IANS, “ISKP and LeT Backed by ISI Targeting Balochis and Taliban, Planning to Revive Militancy in Kashmir: Intel Sources,” October 7, 2025,https://ianslive.in/iskp-and-let-backed-by-isi-targeting-balochis-and-taliban-planning-to-revive-militancy-in-kashmir-intel-sources--20251007150307

25. Zee News, “J&K Security Alert: LeT-ISKP Hybrid Fedayeen Squad, ISI Report,”https://zeenews.india.com/india/jk-security-alert-let-iskp-hybrid-fedayeen-squad-isi-report-3012056.html

26. National Investigation Agency, press release, September 9, 2024,https://nia.gov.in/sites/default/files/Document/1811_1_PR09092024.pdf

See also National Investigation Agency, press release, https://nia.gov.in/sites/default/files/Document/1716_1_Pr.pdf

Indian Express, “Missing Suspect in Terror Conspiracy Case Emerges as Online Handler in Rameshwaram Cafe Blast Plot,” https://indianexpress.com/article/cities/bangalore/missing-suspect-terror-conspiracy-case-emerges-online-handler-rameshwaram-cafe-blast-plot-9434632/

27. Indian Express, “Missing Suspect in Terror Conspiracy Case Emerges as Online Handler in Rameshwaram Cafe Blast Plot,”https://indianexpress.com/article/cities/bangalore/missing-suspect-terror-conspiracy-case-emerges-online-handler-rameshwaram-cafe-blast-plot-9434632/

28. Indian Express, “Mohammed Shahid Faisal: MHA Designated Terrorist under UAPA,”https://indianexpress.com/article/cities/bangalore/mohammed-shahid-faisal-mha-designated-terrorist-uapa-bengaluru-10774329/

See also The Hindu, “Bengaluru Engineer Who Has Been on NIA Most Wanted List Since 2012 Emerges as Handler of Three Terror Modules in Karnataka,” https://www.thehindu.com/news/national/karnataka/bengaluru-engineer-who-has-been-on-nia-most-wanted-list-since-2012-emerges-as-handler-of-three-terror-modules-in-karnataka/article68622812.ece

29. Firstpost, “Hyderabad Islamist Farhatullah Ghori Declared Terrorist by Home Ministry, Works for LeT, JeM,”https://www.firstpost.com/india/hyderabad-islamist-farhatullah-ghori-declared-terrorist-by-home-ministry-works-for-let-jem-11376861.html

See also Times of India, “Hyderabad Fugitive Mohammed Farhatullah Ghori Linked to Jaish, LeT under Intelligence Scanner,” https://timesofindia.indiatimes.com/city/hyderabad/hyderabad-fugitive-mohammed-farhatullah-ghori-linked-to-jaish-let-under-intelligence-scanner/articleshow/98573501.cms

Ministry of Home Affairs, notification, October 28, 2020, https://origin1504-mha.nic.in/sites/default/files/Notifciation18individualterrorist_28102020_0.pdf

30. National Investigation Agency, press release, September 9, 2024,https://nia.gov.in/sites/default/files/Document/1811_1_PR09092024.pdf

31. The Jamestown Foundation, “The Elusive Indian Ideologue Farhatullah Ghauri Resurfaces to Call for Jihad in India,”https://jamestown.org/the-elusive-indian-ideologue-farhatullah-ghauri-resurfaces-to-call-for-jihad-in-india/

32. based on Author’s own investigation.

33. based on author’s own investigation.

34. Dainik Bhaskar, https://dainik.bhaskar.com/c7NNeXCi0Mb’ref=MTkwNzAzMDA4NjgyOTU1OTgwOA%3D%3D

35. based on author’s own investigation.

36. based on author’s own investigation.

37. based on author’s own investigation.

38. based on author’s own investigation.

39. based on author’s own investigation.

40. based on author’s own investigation.

41. based on author’s own investigation.

42. based on author’s own investigation.

43. based on author’s own investigation.

44. based on author’s own investigation.

45. based on author’s own investigation.

46. based on author’s own investigation.

47. based on author’s own investigation.

48. based on author’s own investigation.

49. based on author’s own investigation.

50. based on author’s own investigation.

51. IANS, “Intelligence Agencies Warn AQIS Could Use Mali Attacks to Regroup in India,” May 11, 2026,https://ianslive.in/intelligence-agencies-warn-aqis-could-use-mali-attacks-to-regroup-in-india--20260511111337

52. The Hans India, “JeM, AQIS Join Hands to Engineer Mass Unrest across India,”https://www.thehansindia.com/news/cities/new-delhi/jem-aqis-join-hands-to-engineer-mass-unrest-across-india-1113457

(The views expressed are those of the author and do not represent the views of CESCUBE)

Image Source: AI Generated

Herumb Choureya
About Herumb Choureya →

Herumb Choreya is a Cybersecurity Undergraduate at the National Forensic Sciences University with a focused primary interest in OSINT/Intelligence and National Security. Over the past 2 years, he has independently engaged in tracking and analyzing extremist/terrorist network behaviour within Indian cyberspace.

ADVERTISEMENT

Related Strategic Analysis