Researchers at Shandong University have unveiled a novel data exfiltration technique named TrojPix, capable of leaking sensitive information from air-gapped systems by manipulating video cable emissions. The attack exploits imperceptible pixel modulation to encode data into the electromagnetic radiation emitted by video cables, achieving a peak throughput of 8.1 Mbps and a range of up to 208 meters in controlled tests. This represents a significant advancement over previous covert channels, which typically operate at bits or kilobits per second, enabling the transfer of a 100 MB file in under two minutes.
TrojPix requires prior malware installation on the target system but does not need administrator privileges or hardware modifications. The malware can draw to the screen, allowing two primary transmission methods: simulating a powered-off display to keep the screen dark during transmission, or embedding the signal within normal on-screen content. The technique has been validated across nine monitor brands and fifteen video cables, demonstrating broad compatibility.
While the concept of exploiting compromising emanations (TEMPEST) is decades old, TrojPix builds on recent work like TEMPEST-LoRa (CCS 2025), which achieved lower throughput and range. However, these emission-based attacks remain largely theoretical in real-world scenarios, as actual air-gap breaches (e.g., Stuxnet, Agent.BTZ) have relied on physical media like USB drives. Countermeasures include using fiber-optic video cables, shielding facilities to TEMPEST standards, and preventing malware infections. The attack underscores the need for physical security measures alongside traditional cyber defenses.
CVEs: CVE-2026-55200, CVE-2026-46817
Malware: TrojPix, PIXHELL, Stuxnet, Agent.BTZ
Companies: Shandong University
Original source: thehackernews.com