INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

TrojPix Attack Leaks Data From Air-Gapped Systems via Video

| 2026-07-06 08:50 LOW LOW DATA BREACH
Executive Summary
AI-generated
On July 6, 2026, researchers at Shandong University demonstrated a new technique called TrojPix that can leak data from air-gapped systems via video cable emissions. The attack works by tweaking on-screen pixels in ways the eye cannot see to radiate a faint radio signal that a nearby receiver can decode. This method requires user-level malware and no administrator rights, making it a potential threat for endpoint security. TrojPix has been tested with a peak throughput of 8.1 Mbps, reaching distances of up to 208 meters, which is significantly faster than traditional air-gap covert channels crawling at bits or kilobits per second. The attack can move large files in under two minutes and has been shown to work across nine monitor brands and fifteen video cables, making it a potentially powerful tool for cyber espionage.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ag•••••.btz
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
StuxnetStuxnet
Target & Sectors
Global Scope
Incident Timeline
‎Jul 06, 2026
Threat actors used TrojPix to transmit data from air-gapped systems via video cable emissions.
data_breach 100 MB file
data_breach 8.1 Mbps
Tactical Metrics
Metrics
data_breach
100
Mb File
Metrics
data_breach
8
Mbps
Intelligence Sources