The Uttar Pradesh Anti-Terrorist Squad is examining a digital network of around 100 people as it widens its investigation into an alleged Al Qaeda in the Indian Subcontinent-linked online module.
The probe centres on 19-year-old Maqsood Ali, a Siddharthnagar native arrested in Coimbatore on September 14 with assistance from the Tamil Nadu ATS. Investigators allege that he maintained foreign contacts, participated in multiple online groups and developed a communication application called “Captain M Network.”
According to fresh reporting on the investigation, ATS teams are now scrutinising around 100 people from Uttar Pradesh and neighbouring states who were allegedly connected with Maqsood through social media or other online platforms.
Of these, the agency has reportedly identified five to six people whose roles require closer examination. Contact with an accused person by itself does not establish involvement in any offence, and investigators are assessing each individual separately.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Phone data becomes central to the wider investigation
Investigators have focused heavily on digital material recovered from Maqsood’s mobile phone and other devices.
ATS officials allege that some recovered chats involved information linked to bomb-making. Investigators are trying to establish who supplied the material, why it was sought and whether there was any plan to use it.
The agency has not publicly established a final target for the alleged module or disclosed a complete operational plan.
That makes forensic examination particularly important. Investigators can use device records, timestamps, account information and communication histories to reconstruct who communicated with whom and when.
ATS had earlier alleged that Maqsood operated two WhatsApp accounts and was associated with groups called “UU Entry Gate”, “United Ummah”, “Gazwa-e-Hind”, “Team Black Hat” and “Lashkar-e-Mehndi”.
Some of those groups allegedly contained Pakistani phone numbers and individuals described by investigators as Pakistani hackers. ATS also claimed that extremist material and discussions around secure communication tools circulated through parts of the network.
‘Captain M Network’ app under technical examination
A major focus is the application investigators say Maqsood built himself.
ATS has described “Captain M Network” as a secure application through which Maqsood, another arrested accused identified as Mohammad Nabeel, and other individuals allegedly remained connected. The app reportedly carried the motto “One Platform, One Motive — Unity, Plan and Action.”
Investigators say Maqsood taught himself Python, Java, coding and hacking-related skills using online resources including YouTube, Instagram, Telegram and WhatsApp groups.
Separate reporting says he was also learning artificial intelligence online. However, publicly available ATS accounts establish more clearly that online resources were used to develop his technical skills; exactly how AI tools were used in building the application has not yet been independently detailed.
The ATS is now examining the app’s architecture, associated accounts and communication records.
Investigators will need to determine whether it functioned simply as a privately developed messaging tool or whether it was deliberately designed to hide communications connected with the alleged module.
What digital forensics can reveal
Digital forensics is the process of extracting and examining information from phones, computers and online accounts in a way that can later be used as evidence.
Deleting a chat does not always mean every trace disappears. Investigators may still recover account identifiers, timestamps, cached information, cloud records or data from another participant’s device.
In this case, the ATS is reportedly matching app data against WhatsApp contacts, foreign numbers and other online accounts.
That process could help investigators distinguish casual online connections from people who may have participated in organised activity.
The case began after UP ATS arrested Mohammad Nabeel, an Azamgarh resident, on September 12. Investigators said information gathered during that probe led them to Maqsood in Coimbatore two days later.
The ATS registered the case under Sections 152 and 61(2) of the Bharatiya Nyaya Sanhita as well as Sections 18 and 38 of the Unlawful Activities (Prevention) Act. The provisions relate, among other things, to conspiracy and alleged association or activity connected with a terrorist organisation.
The investigation remains at an early stage. The alleged purpose of the wider network, the significance of the foreign contacts and the roles of the five-to-six people under closer scrutiny have not yet been finally established.
For investigators, the next stage will depend heavily on what forensic analysis of the seized devices and online accounts actually proves.
What this means for you: Online groups and private apps can leave extensive digital trails even when communications are deleted or moved between platforms. Users should also remember that being present in a group or contact list does not by itself establish criminal involvement; investigators must establish each person’s actual conduct and intent.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics