TrojPix Hits 8.1 Mbps Pulling Data Off Air-Gapped PCs

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- TrojPix, developed by researchers at Shandong University, leaks data from air-gapped PCs by tweaking on-screen pixels in ways invisible to the eye, so the video cable carrying them radiates a faint radio signal a nearby receiver can decode.
- TrojPix hit a peak throughput of 8.1 Mbps and reached 208 meters in tests (measured separately), fast enough to exfiltrate a 100 MB file in under two minutes — turning the threat from leaking a password into moving whole files.
- TrojPix needs no admin rights or hardware changes — user-level malware that can draw to the screen is enough, and the team tested it across nine monitor brands and fifteen video cables.
- The prior state-of-the-art TEMPEST-LoRa channel, presented at CCS 2025, topped out at 87.5 meters and 21.6 kbps; TrojPix's peak throughput is hundreds of times higher, though the two use different receivers under different conditions and aren't head-to-head comparable.
- TrojPix supports two hiding modes: faking a powered-off display that keeps the screen dark while it transmits, or burying the signal inside whatever is already on screen.
- Countermeasures can't patch the emission itself — defenses are physical: fiber-optic video links (which carry no such signal), cable and room shielding, and keeping malware off the machine in the first place.
Why it matters: Air-gapped machines — the last line of defense for classified networks and critical-infrastructure systems — now face a video-cable exfiltration channel fast enough to move whole files instead of just credentials, with a 100 MB file leaving in under two minutes. No software patch exists; only physical countermeasures like fiber-optic links or TEMPEST-style shielding.




