1 week ago
NIA Chargesheet Alleges ISI Role in Pahalgam Cyber Network
India’s National Investigation Agency is investigating the Pahalgam attack.
A report says its chargesheet describes a digital network allegedly supported by Pakistan’s intelligence agency, the ISI.
The network is said to help terrorist groups communicate and spread messages online.
The Resistance Front first reportedly claimed the attack on social media.
Later, after the United Nations Security Council condemned the killings, it reportedly posted messages denying responsibility.
Investigators say automated Telegram bots helped spread both claims and denials.
They also allege that online handlers communicated with people in India.
According to the report, these digital activities may have supported real-world terrorist operations.
An NIA chargesheet allegedly describes an ISI-supported “cyber jihad” network linked to the Pahalgam attack.
The Resistance Front reportedly claimed responsibility within 2.5 hours, then circulated a denial after a UN Security Council condemnation.
The alleged network used servers, encrypted VPNs, virtual SIMs, VoIP lines and Telegram bots to support terror-linked communications.
Investigators reportedly identified coordinated online activity involving Kashmir-focused and Khalistani social-media handles.
Sources allege the network connected Pakistan-based handlers with over-ground workers for radicalisation, surveillance, weapon drops and IED logistics.
- Who
- The National Investigation Agency, Pakistan’s Inter-Services Intelligence, the Resistance Front, Pakistan-based handlers and alleged local over-ground workers are identified in the report.
- What
- An NIA chargesheet allegedly details an ISI-supported digital network used for terror communications, propaganda, online radicalisation and operational support linked to the Pahalgam attack.
- Where
- The alleged network involved Pakistan-based infrastructure and operatives, with links to India, including Jammu and Kashmir and Punjab; the attack occurred in Pahalgam.
- When
- The Resistance Front reportedly claimed responsibility within 2.5 hours of the attack; the reported digital rollback occurred on April 25, 2025, after a UN Security Council condemnation.
- Why
- According to the report, the network allegedly helped terror groups maintain command-and-control, manage public narratives, reach potential recruits and support operations in India.
Investigators’ account
Resistance Front’s reported denial
Responsibility for the attack
Investigators’ account
Investigators reportedly view the initial Resistance Front claim as part of a coordinated terror-linked digital operation.
Resistance Front’s reported denial
The Resistance Front reportedly later denied responsibility and alleged that Indian agencies had planted unauthorised posts.
Purpose of online activity
Investigators’ account
The NIA investigation, as described in the report, alleges that the digital network supported propaganda, radicalisation, command-and-control and real-world operations.
Resistance Front’s reported denial
The reported denial-cum-false-flag narrative attributed the online responsibility claims to unauthorised activity rather than the group itself.
Role of Pakistan-based infrastructure
Investigators’ account
Sources cited in the report allege that ISI-linked infrastructure and handlers helped conceal origins and maintain links with operatives in India.
Resistance Front’s reported denial
The article does not provide a response from Pakistan’s government or the ISI contesting these allegations.
Key facts
- Investigating agency
- National Investigation Agency
- Alleged facilitator
- Pakistan’s Inter-Services Intelligence
- Group cited
- The Resistance Front
- Initial claim
- The Resistance Front reportedly claimed responsibility within 2.5 hours of the attack.
- Reported rollback
- A denial-cum-false-flag narrative was reportedly circulated on April 25, 2025, after a UN Security Council statement condemning the killings.
- Digital tools cited
- Dedicated servers, encrypted VPN gateways, virtual SIMs, VoIP lines, Telegram bots, encryption tools and spam engines.
- Alleged operational links
- The network allegedly connected Pakistan-based handlers with over-ground workers across Punjab and Jammu and Kashmir.











