Hey TSCM Crew! The Cable Was Always Talking

Hey TSCM Crew! The Cable Was Always Talking, TSCM, counterintelligence, counterespionage, spy, countermeasures, C. Constantin Poindexter

TrojPix, TEMPEST, and the Eternal Return of the Compromising Pixel, my counterintelligence reading for those who own more than one spectrum analyzer

Every eighteen months or so, the security-adjacent internet rediscovers that copper radiates. There is a burst of excitement, a headline containing the word “unhackable” in scare quotes, and a great many people who have never held a near-field probe explaining to one another that air-gapped systems are now obsolete. Then everyone goes back to leaving the SCIF door propped open with a fire extinguisher.

This cycle’s entry is TrojPix, and credit where it is due, a good paper. It is not, however, a game-changer.

What the researchers actually did

TrojPix comes out of Shandong University and Quan Cheng Laboratory, authored by Guoming Zhang and colleagues, and is accepted to the 35th USENIX Security Symposium (Zhang et al. 2026). The mechanism is elegant in its parsimony. Digital video interfaces encode pixel data using Transition-Minimized Differential Signaling, and TMDS (being a high-speed switching serial protocol over unbalanced-enough copper) radiates. Everyone has known this since the 80s.

The contribution is that the authors demonstrate the mapping is deterministic and controllable. Modify pixel values in a way the human visual system cannot resolve, the canonical example being the least significant bit of the blue channel, and you produce a predictable, addressable change in the electromagnetic signature on the cable. The display becomes a modulator. The cable becomes the antenna. User-mode malware becomes a transmitter without touching a driver, a device, or an administrator’s password.

They evaluated across nine COTS monitor manufacturers and fifteen COTS video cables, in two operational modes: fake screen-off, in which the display appears dark while continuing to transmit, and foreground embedding, in which the payload rides inside whatever the user is legitimately looking at. Reported results: peak throughput of 8.1 Mbps, maximum range of 208 meters, average bit correct rate around 99 percent, and structural similarity indices of 0.998–0.999 with a fifty-person perceptual study in which nobody noticed anything (Zhang et al. 2026). The prior state of the art in this niche managed 21.6 kbps at 87.5 meters (The Hacker News 2026). That is genuinely good engineering. Now let us be adults about it.

The 8.1 Mbps that does not exist at 208 meters

The single most-repeated distortion in the coverage, and in every breathless social media repost, is the implicit bundling of peak throughput and maximum range into one system. They were measured separately, a point The Hacker News (2026) had the discipline to state explicitly and almost nobody else did.

This should be obvious to anyone who has ever done a link budget. Channel capacity is a function of signal-to-noise ratio. SNR falls off with distance, and the emission in question is an unintended one, meaning the transmit power is whatever leaked out of a cable that was designed to comply with FCC Part 15 and CISPR 32. You do not get megabit rates at two hundred meters off parasitic radiation. You get megabit rates in the lab at short standoff, and you get the two-hundred-meter figure at a data rate that would embarrass a 1200-baud modem. Both numbers are true. A sentence containing both of them is NOT.

The receiver is not in anyone’s pocket

The reporting indicates the collection side used a USRP X310 with a directional antenna and a low-noise amplifier. That is several thousand euros of gear, commercially available, but not a dongle taped to a Raspberry Pi in a hedge (HackingPassion 2026). This matters enormously, and it matters in the counterintelligence/countermeasures favor.

Think about what the adversary’s collection geometry actually requires: a stable, powered, aimed platform maintaining a favorable path to a specific building elevation, for however long the exfiltration takes, without being noticed. That is not a cyber problem. That is a physical surveillance detection problem, i.e., the discipline in which our C.I. community has ninety years of institutional practice. The attack has not defeated the perimeter. It has converted the adversary’s problem into one that is squarely inside your area of competence, and made it harder for him, because now he has to bring an ice cream truck or telco-looking van.

Priority, or: read your own literature

Wim van Eck (1985) published the foundational demonstration that video display emanations could be reconstructed at a distance. Thirteen years later, Markus Kuhn and Ross Anderson described “Soft Tempest”, and here it is worth quoting their own framing of the attack case, malicious code encoding stolen information in a machine’s RF emissions, optimized for some combination of reception range, receiver cost, and covertness, specifically via the video cable (Kuhn and Anderson 1998, 124–42). Kuhn’s dissertation extended this to displays generally (Kuhn 2003), Loughry and Umphress (2002) did the optical analogue, and Mordechai Guri has spent a decade industrializing the entire genre, most relevantly with PIXHELL, which modulates pixel patterns to produce acoustic emissions from LCD coils and capacitors (Guri 2024).

TrojPix is Soft Tempest with twenty-eight years of better DSP, a modern SDR, and a proper imperceptibility evaluation. That is a real contribution. It is an engineering delta, not a conceptual one, and describing it as a “new air-gap bypass” is a bit like announcing the discovery of the wheel with rubber on it.

The precondition swallows the finding

TrojPix is an exfiltration channel. It is not an access vector. The malware must already be resident on the isolated host, which means it arrived by the ordinary routes, i.e., a dirty thumbdrive, supply chain, firmware, a human being with a badge and a grudge, etc. Stuxnet and Agent.BTZ crossed air gaps on USB drives, not over radio.

So the risk equation is unchanged in its dominant term. If the adversary can get arbitrary code onto an isolated machine, you have a very serious problem already. The interesting question was never whether he could get the data out. It was whether he could get 400 megabytes out in six minutes instead of dribbling an AES key over a weekend. TrojPix improves his egress bandwidth. It does not improve his ingress.

The threat model wanders off the reservation

The paper, and every article about it, invokes military command centers, nuclear control systems, and financial institutions. Note what was actually tested, i.e., consumer monitors from Dell, Samsung, LG, AOC, Philips, Lenovo, TCL, Huawei, and Redmi, and fifteen commodity cables (Cyber Press 2026). Facilities that genuinely hold the data being invoked do not run Redmi panels on unshielded HDMI. They run inspectable-space doctrine, RED/BLACK separation, shielded enclosures, and equipment procured against emanation-security criteria, i.e., the framework that has existed since NSTISSAM TEMPEST/1-92 and its national equivalents. If your accredited space is leaking recoverable TMDS at 208 meters, TrojPix is not your problem. You’ve f. up and your accreditation is. Conversely, in the open-plan office where those Redmi monitors actually live, there is a wireless network and the adversary will simply use it, because he is not a masochist.

What the sweep community should actually take away are three things, none of which fit in a post, but here we go.

The emission is physics, so the countermeasures are physical. Fiber-optic video links carry no exploitable copper transient. Shielding, zone control, and RF jamming of the relevant band remain the answers they have always been. No patch removes Maxwell’s equations from the environment.

Deliberate modulation is, paradoxically, easier to catch than passive leakage. A van Eck emanation is an unstructured artifact. A TrojPix emission is a structured, periodic, deliberately regular signal bearing a fixed relationship to the pixel clock. Structure is what your analyzer is for. The implication is not that sweeps are futile; it is that episodic sweeps are futile and persistent spectrum monitoring against a characterized baseline is not.

The fake-screen-off mode is a gift. A monitor that is off should not be receiving an active TMDS stream. That is a host-side, software-detectable state inconsistency, and it costs nothing to instrument. The stealthiest mode in the paper is also the one with the loudest logical tell.

The authors withheld operational detail and initiated disclosure with cable manufacturers, and nothing resembling this has been observed in the wild (HackingPassion 2026). It is laboratory work mapping the boundary of the physically possible, which is precisely what USENIX exists to publish.

I am recognizing here and sharing that the air gap was never a control. It is a topology. Anyone who mistook it for a control had a problem long before a graduate student in Jinan started flipping the blue channel. So, no. A collector can’t just sit 200m away and read your mail, but, . . .

C. Constantin Poindexter, MA in Intelligence, Graduate Certificate in Counterintelligence, JD, CISA/NCISS OSINT certification, DoD/DoS BFFOC Certification

Bibliography

  • Cyber Press. 2026. “TrojPix Attack Uses Imperceptible Pixels to Steal Data From Air-Gapped Networks.” July 2026. https://cyberpress.org/trojpix-attack-air-gapped/.
  • Guri, Mordechai. 2024. “PIXHELL Attack: Leaking Sensitive Information from Air-Gap Computers via ‘Singing Pixels.'” Offensive Cyber Research Lab, Ben-Gurion University of the Negev.
  • HackingPassion. 2026. “TrojPix Steals Data From Air-Gapped Computers Through the Screen.” July 2026. https://hackingpassion.com/trojpix-air-gap-attack/.
  • Kuhn, Markus G. 2003. “Compromising Emanations: Eavesdropping Risks of Computer Displays.” PhD diss., University of Cambridge. Technical Report UCAM-CL-TR-577.
  • Kuhn, Markus G., and Ross J. Anderson. 1998. “Soft Tempest: Hidden Data Transmission Using Electromagnetic Emanations.” In Information Hiding: Second International Workshop, IH’98, edited by David Aucsmith, 124–42. Lecture Notes in Computer Science 1525. Berlin: Springer.
  • Loughry, Joe, and David A. Umphress. 2002. “Information Leakage from Optical Emanations.” ACM Transactions on Information and System Security 5 (3): 262–89.
  • Poller, Jack. 2026. “When ‘Air-Gapped’ Stops Meaning Anything: What TrojPix Should Teach Every CISO.” Security Boulevard, July 8, 2026. https://securityboulevard.com/2026/07/when-air-gapped-stops-meaning-anything-what-trojpix-should-teach-every-ciso/.
  • The Hacker News. 2026. “New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions.” July 2026. https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html.
  • van Eck, Wim. 1985. “Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?” Computers & Security 4 (4): 269–86.
  • Zhang, Guoming, Huiting Zhang, Zhenwei Lu, Heqiang Fu, Xin Gao, Riccardo Spolaor, Yetong Cao, Yanni Yang, and Pengfei Hu. 2026. “TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation.” In Proceedings of the 35th USENIX Security Symposium. Berkeley, CA: USENIX Association. https://www.usenix.org/conference/usenixsecurity26/presentation/zhang-guoming.
Share this post:

The Peril of Pentagon Orders Russian Cyber Defense ‘Stand Down’

cyber, cyber operations, cyber threat, espionage, counterespionage, counterintelligence, russia

It if doesn’t frighten you, it should. “The Trump administration has ordered the United States to end offensive cyber operations targeting Russia, . . . (US News, Mar. 2025) Russia, or more particularly the Russian FIE poses a grave threat to U.S. national security. Threats posed by this state-actor and its state-supported proxies are grave both in terms of capability and intent. Russia has consistently demonstrated its capacity to execute sophisticated cyber operations targeting governments, corporations, critical infrastructure and individuals. The perils are multi-dimensional, including espionage, cyber warfare (or “war in the grey”), information operations, subversion, ransoming and economic disruption. Examples of Russia’s malign and nefarious cyber activity are plethora however recently the U.S. and Ukraine seem to enjoy the brunt of Putin’s ire. Here are some points to consider:

1. State-Sponsored Cyber Warfare

  • Russia’s GRU Unit 74455, a/k/a “Sandworm” conducts offensive cyber operations, often targeting critical infrastructure the U.S., its allies and shared economic interests.
  • The 2017 NotPetya attack caused over $10 billion in global damages, hitting Maersk, FedEx, and other major commercial concerns. This agent was designed for penetration of a particular type of accounting software used in Ukraine. While not specifically targeting the U.S., the global fallout of NotPetya getting into the wild is instructive. In financial terms, it was among the greatest events of “collateral damage during war” ever recorded.
  • Russian hackers have targeted Ukraine’s energy sector repeatedly. They have demonstrated a clear ability to take down critical infrastructure. Evidence of Russian FIS’s penetration of U.S. utilities, likely in search of weakness to exploit or to leave ‘back doors’ for future exploitation, has also been detected. Notably, Dragonfly 2.0, a Russian state-sponsored hacking group (also known as Energetic Bear), successfully infiltrated U.S. energy sector systems, including nuclear power plants.

2. Cyber Espionage

  • Groups like APT29 (Cozy Bear) and APT28 (Fancy Bear), linked to Russian FIE have hacked into government agencies. They have repeatedly compromised U.S. official networks. The SolarWinds penetration in 2020 is instructive.
  • Ongoing efforts to steal classified or proprietary information from defense, aerospace, and technology sectors save Russia billions in research and development. From 2020 to 2021, Russian hackers compromised multiple U.S. defense contractors that provide support to the Department of Defense (DoD), U.S. Air Force, and Navy APT28 “Fuzy Bear” stole information related to weapon systems (including fighter jets and missile defense technologies, communications and surveillance systems, naval and space-based defense projects.

3. Election Interference & Disinformation

  • Russia has weaponized social media. Troll farms such as the Internet Research Agency and more rescently AI-home-cooked content spread disinformation and misinformation to masssive audiences.
  • Russian cyber actors hacked the DNC and Clinton campaign, leaking emails via WikiLeaks in efforts to subvert the U.S. political process.
  • Operation Project Lakhta was ordered directly by Vladimir Putin. This was a “hacking and disinformation campaign” to damage Clinton’s presidential campaign.
  • The Justice Department seized thirty-two internet domains used in Russian government-directed foreign malign influence campaigns (“Doppelganger”).

4. Ransomware & Financial Cybercrime

  • Russia harbors cybercriminal groups like Conti, REvil, and LockBit, which launch ransomware attacks on U.S. hospitals, businesses, and municipal corporations.
  • Many ransomware gangs operate with tacit Kremlin approval—as long as they don’t target Russian entities. For instance, REvil’s malware is designed to avoid systems using languages from the Commonwealth of Independent States (CIS), which includes Russia. This evidences a deliberate effort to steer clear of Russian entities.

5. Potential for Cyber Escalation

  • Russia has declared NATO and the West and its “main enemy”. The risk of cyber retaliation is real. Russia has the capability to conduct supply chain attacks, disrupt banking systems, and interfere with military communications.
  • In 2020, Russian state-sponsored cyber actors compromised the software company SolarWinds, embedding malicious code into its Orion network management software. This supply chain attack affected approximately 18,000 organizations, including multiple U.S. government agencies and private sector companies. This was a surveillance mechanism which allowed Russia to monitor internal communications and exfiltrate sensitive data from the software users.
  • In 2008 Russia deployed specialty malware (“Agent.btz“) which penetrated the U.S. Department of Defense’s classified and unclassified networks. The breach, considered one of the most severe against U.S. military computers, led to the establishment of U.S. Cyber Command to bolster cyber defenses.

Conclusion

The Russian cyber threat is persistent, evolving, and highly strategic. The West has cyber defenses and deterrence strategies in place (like sanctions and counter-hacking operations) however the current Administration’s order to terminate much of that effort cripple U.S. national security.

Quick to react to reporting of the DoD’s posturing, the Cybersecurity and Infrastructure Security Agency (CISA) tweeted, “CISA’s mission is to defend against all cyber threats to U.S. Critical Infrastructure, including from Russia. There has been no change in our posture. Any reporting to the contrary is fake and undermines our national security.” Comforting however the words of a confidential source within CISA present a different picture. “A recent memo at the Cybersecurity and Infrastructure Security Agency (Cisa) set out new priorities for the agency, which is part of the Department of Homeland Security and monitors cyber threats against US critical infrastructure. The new directive set out priorities that included China and protecting local systems. It did not mention Russia, . . . analysts at the agency were verbally informed that they were not to follow or report on Russian threats, even though this had previously been a main focus for the agency.” (Guardian, Mar. 2025)

Russia is one of our most aggressive cyber adversaries as well as being recongnized by most nations as a ‘cyber threat pariah’ (i.e., most vocally by NATO, the EU and the U.N.). Given the President’s position on Russia, it’s impossible to say that U.S. continues to harden critical infrastructure, surveil Russian FIE cyber efforts and accomplish effective countermeasures. Russia’s offensive cyber capabilities will remain a major security challenge for the foreseeable future. The question is, are we willing to handicap our efforts to meet our adversaries with robust cyber capability or simply turn our heads away.

Share this post:

Iran Cyber Operations Target Utility Infrastructure

cyber, cyber operations, espionage, counterespionage, counterintelligence, cyber defense, CISA, countermeasures, constantin poindexter

Per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), “Since at least November 22, 2023, these IRGC-affiliated cyber actors have continued to compromise default credentials in Unitronics devices. The IRGC-affiliated cyber actors left a defacement image stating, “You have been hacked, down with Israel. Every piece of equipment ‘made in Israel’ is CyberAv3ngers legal target.” The victims span multiple U.S. states. The authoring agencies urge all organizations, especially critical infrastructure organizations, to apply the recommendations listed in the Mitigations section of this advisory to mitigate the risk of compromise from these IRGC-affiliated cyber actors.” (CISA, 12/01/2023)

The penetrations were aimed at critical utilities, in the extant case of U.S. water and water waste treatment infrastructure. Per CISA, “Beginning on November 22, 2023, IRGC cyber actors accessed multiple U.S.-based WWS facilities that operate Unitronics Vision Series PLCs with an HMI likely by compromising internet-accessible devices with default passwords. The targeted PLCs displayed the defacement message, “You have been hacked, down with Israel. Every equipment ‘made in Israel’ is Cyberav3ngers legal target.” The Water and Wastewater Systems Sector (Water Sector) underpins the health, safety, economy, and security of the nation. It is vulnerable to both cyber and physical threats.” The warning is instructive. The fallout from a successful compromise of public water systems can be severe. Andrew Farr warns, “The imagination can run wild with worst-case scenarios about what a threat actor could do to a water system, but Arceneaux explains that sophisticated actors could hack a system and manipulate pumps or chemical feeds without the utility even knowing they were in the system. They could also create a water hammer that could lead to cracked pipes or release untreated wastewater back into a source water body. What if that happens [to a water system] in a medium or a big city? Maybe it’s only for a few hours, but it could go on for a few days or weeks, depending on how extensive the damage is.” (Farr, WF&M, 04/11/2022) Darktrace reports the very real consequence of a successful water system compromise. “Earlier this month, cyber-criminals broke into the systems of a water treatment facility in Florida and altered the chemical levels of the water supply.” (Matthew Wainwright, Darktrace) If potable water delivered to consumers contains dangerous contaminants or improper balances of the “good” chemicals blended to the product (fluoride, chlorine, chloramine, etc.), it can cause negative health effects. Gastrointestinal illness, nervous system damage, reproductive system damage, and chronic diseases such as cancer are very real risks associated with the same.

CISA cyber defense model of the “brute force” methodology deployed by IRGC operatives may be viewed at MITRE.

Share this post: