Researchers at Shandong University disclosed TrojPix, a covert exfiltration technique that steals data from air-gapped computers by subtly manipulating on-screen pixels so attached video cables emit decodable radio-frequency signals. The method is not an initial access vector; it requires malware to already be running on the target system, but it can operate with user-level privileges, without administrator access or hardware modification, and can either imitate a powered-off display or hide transmissions within normal screen content.
In testing, the researchers said TrojPix achieved up to 8.1 Mbps throughput and a maximum range of 208 meters in separate measurements, making it significantly faster than many previously documented air-gap covert channels and potentially capable of transferring large files. The technique reportedly worked across nine monitor brands and 15 video cables, while recommended mitigations focused on physical and preventive controls such as fiber-optic video links, shielding and TEMPEST-style protections, and stronger measures to prevent malware from reaching air-gapped systems in the first place.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers at Shandong University described TrojPix, a covert channel that exfiltrates data from air-gapped computers by subtly modulating on-screen pixels so attached video cables emit decodable radio signals. They reported that the technique requires malware already running on the target, needs no administrator privileges or hardware modifications, and achieved up to 8.1 Mbps in testing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.