HomeSecurityPIXHELL: Steals data from Air-Gapped computers

PIXHELL: Steals data from Air-Gapped computers

A new side-channel attack, known as PIXHELL, targets Air-Gapped computers, breaching the “audio gap” and exploiting sensitive information through the noise produced by the screen’s pixels.

PixHell air-gap

“The malicious software on air-gap and audio-gap computers creates specific pixel patterns that generate noise in the frequency range 0 – 22 kHz”, said Dr. Mordechai Guri, head of the Offensive Cyber Research Lab in the Software and Information Department.

The malicious code exploits the sound produced by coils and capacitors to control the frequencies emanating from the screen. These acoustic signals can encode and transmit sensitive information

This attack is noteworthy, as it does not require specialized audio hardware, a speaker, or an internal speaker in the target computer. Instead, it exploits the LCD screen to generate acoustic signals.

See also: Slim CD: Data breach affects 1.7 million people

Air-Gapping is a fundamental security measure that aims to protect critical environments related to missions from potential threats, physically and logically isolating them from external networks such as the Internet. This is usually achieved by disconnecting network cables, disabling wireless interfaces, and disabling USB connections.

However, these security measures can be bypassed through malicious attacks or breaches supply chain, either hardware or software. Another possible scenario involves an unsuspecting employee plugging in an infected USB drive, activating malware, which can create a backdoor data leak channel.

“Techniques such as phishing or social engineering methods can be used to trick individuals with access to Air-Gap systems into taking actions that compromise security, such as clicking on malicious links or downloading infected files,” said Dr. Mordechai Guri.

«Hackers can also use attacks on the software supply chain, targeting application dependencies or third‑party libraries. By compromising these dependencies, they can introduce vulnerabilities or malicious code that may go unnoticed during their deployment».

As was the case in the recent RAMBO, PIXHELL exploits malware deployed on the compromised host to create an audio channel that allows information to be leaked from Air-Gap-enabled systems.

Read more: New RAMBO attack steals data using RAM

This is due to the presence of inductors and capacitors in the internal structures and power supplies of LCD displays. These elements vibrate at audio frequencies, creating a high-frequency noise when electrical current passes through the coils, a phenomenon called “coil whine”.

In particular, changes in power consumption can cause mechanical vibrations or piezoelectricity in capacitors, leading to the generation of audible noise. A critical factor affecting the consumption pattern is the number of active pixels and their distribution on the screen, as white pixels require more energy to display compared to dark pixels.

«Additionally, when alternating current (AC) flows through the screen's capacitors, they vibrate at specific frequencies», said Dr. Guri. «Acoustic emissions arise from the internal electrical components of the LCD screen, and their characteristics are affected by the actual bitmap, the pattern, and the intensity of the pixels displayed on the screen.»

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

By carefully monitoring the pixel patterns displayed on the screen, our technique generates specific sound waves at specific frequencies from LCD screens. A hacker can then exploit this method to extract data in the form of audio signals, which are then modulated and transmitted to a nearby Windows or Android. This device can then demodulate the packets and recover the information.

It is important to note that the power and quality of the emitted audio signal depend on many factors, including the specific structure of the display, its internal power supply, and the positions of the coil and capacitor.

See also: Cisco's merchandise store targeted by cyberattack

Another critical factor is that the PIXHELL attack is visible to users watching the LCD screen, as it involves displaying a bitmap pattern with alternating black and white lines. "To maintain their anonymity, hackers can implement a strategy that involves broadcasting data while the user is away," explained Dr. Guri. "For example, the 'overnight attack' on covert channels is performed during hours when the device is off, thus reducing the risk of detection and exposure."

The attack could manifest covertly during work hours, reducing the pixel colors to very low levels before transmission, using specific RGB levels (1,1,1), (3,3,3), (7,7,7) and (15,15,15). Thus, the user gets the impression that the screen is black. However, this approach tends to reduce «significantly» the audio production levels. So it is not flawless and a user may notice irregular patterns if they examine the screen carefully.

PIXHELL air-gap

This is not the first time that the limitations of the “audio-gap” have been circumvented in experimental settings. Dr. Guri’s previous research has utilized sounds from various sources, such as computer fans (Fansmitter), hard drives (Diskfiltration), CD/DVD drives (CD-LEAK), power supplies (POWER-SUPPLAY), and inkjet printers (Inkfiltration).

Read more: Account breaches surpass Ransomware as top cyberthreat

For your protection, it is recommended to use an audio jammer to neutralize the transmission, monitor the audio spectrum to detect unusual signals, limit physical access to authorized personnel, prohibit the use of smartphones , and implement an external camera to detect unusual patterns on the screen.

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS