news.mlab.sh
Back to the feed
threat-intel

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

Medium
Summary

Researchers at Shandong University have developed a new technique called TrojPix that allows data to be exfiltrated from air-gapped systems by subtly modulating pixels on a screen and transmitting them as a radio signal. This method bypasses traditional network defenses and requires only malware already present on the target machine. While not a method of initial intrusion, it provides a significant avenue for data exfiltration once an attacker has gained access.

TrojPix utilizes imperceptible pixel modulation to transmit data over a radio frequency, effectively turning a standard monitor into a covert communication channel. The technique requires no administrator rights or hardware modifications, relying solely on user-level malware to draw to the screen. The researchers demonstrated the method's capabilities, achieving a peak throughput of 8.1 Mbps and a range of 208 meters, showcasing the potential for rapid data transfer. This method builds upon established techniques like TEMPEST and TEMPEST-LoRa, but significantly increases data transfer speeds. It’s important to note that this technique doesn’t represent a method for initial system compromise; it’s a post-intrusion exfiltration method. Effective defenses against TrojPix involve physical security measures such as utilizing fiber-optic cables and shielding sensitive areas, alongside proactive malware prevention.

Read the full article at The Hacker News