New TrojPix Attack Extracts Data from Air-Gapped Systems via Video Cable Emissions

Researchers at Shandong University have demonstrated a new technique called TrojPix that can exfiltrate data from air-gapped computers. This approach leverages imperceptible on-screen pixel changes to cause the video cable to emit faint radio signals, which a nearby receiver can decode. However, TrojPix requires malware to already be present on the targeted system.
What happened
A new data exfiltration technique named TrojPix has been introduced by researchers from Shandong University. It targets air-gapped systems—computers isolated from any network connections—by manipulating on-screen pixels in a manner imperceptible to the human eye. These pixel changes induce the video cable to emit faint radio frequency signals. When a receiver is placed nearby, it can capture and decode these signals to retrieve sensitive data.
Importantly, TrojPix is not a standalone attack method; it requires the target computer to be infected with malware beforehand. The malware executes the pixel modulation to generate the radio emissions via the video cable for data leakage.
Why it matters
Air-gapped systems are typically used to secure highly sensitive data by physically isolating them from external networks. TrojPix challenges the security assumptions of such setups by showing how data can be covertly leaked without network access, expanding the threat landscape for critical environments.
The method's reliance on subtle electromagnetic emissions makes it particularly stealthy and difficult to detect with conventional network defense tools. This side-channel exfiltration highlights the need for comprehensive security measures that consider unconventional attack vectors, especially for protecting critical infrastructure and classified data.
What security teams should do
Since TrojPix requires existing malware infection on the target, prevention of initial compromise remains critical. Security teams should maintain rigorous endpoint protection, apply strict access controls, and implement robust malware detection capabilities to prevent unauthorized code execution on sensitive machines.
Additionally, organizations operating air-gapped systems may consider monitoring for unusual electromagnetic emissions and physical security controls to limit proximity of unauthorized receivers. Reviewing and limiting physical exposure of cable runs can reduce the feasibility of such side-channel attacks.
Key technical details
TrojPix exploits the video cable that connects a computer to its monitor by manipulating pixel colors on the screen. These changes are modulated at a frequency imperceptible to the user, causing the video cable to emit low-power radio signals.
A nearby receiver device can intercept these signals and decode the data transmitted covertly through this side-channel. Because the attack uses electromagnetic radiation from hardware components, it bypasses traditional network and software-based detection methods. The technique is contingent on prior malware implantation that controls the pixel modulation process.
Affected organizations/products
The technique targets air-gapped computers connected to displays through video cables. No specific organizations or products were identified in the disclosed research.
Source attribution
https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html