Reviving TEMPEST Attacks With An Injected Signal

Lobsters Hottest News

Summary

Researchers have revived TEMPEST attacks using injected RF signals, demonstrating recovery of internal signals from modern electronics, including voice cloning and injection.

<p><a href="https://lobste.rs/s/ub3vw7/reviving_tempest_attacks_with_injected">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 09/22/26, 12:37 PM

# Reviving TEMPEST Attacks With An Injected Signal Source: [https://hackaday.com/2026/09/20/reviving-tempest-attacks-with-an-injected-signal/](https://hackaday.com/2026/09/20/reviving-tempest-attacks-with-an-injected-signal/) TEMPEST attacks are often the most effective way to break air\-gapped security: rather than directly accessing a computer, the attacker records the system’s unintended radio emissions and uses them to reconstruct its internal operations\. This kind of attack was much more effective in the days of noisy, high\-voltage CRT displays, and has gradually become less effective as electronics migrate to quieter, less powerful components\. A group of researchers, however, has found that even modern electronics can become[effective TEMPEST transmitters](https://arxiv.org/pdf/2609.04785)when irradiated with an RF signal\. The RF a device emits depends on the unintentional antennas in its internal structure\. These are difficult to eliminate, and it’s usually not worth the effort; they’re usually small enough that they only effectively radiate at much higher frequencies than the electronics carry\. The researchers’ technique, called InjectEave, radiated these electronics with a radio frequency tuned to their internal antennas, injecting that frequency into the circuit\. Nonlinear electronic components, such as amplifiers, then mix the injected frequency with the internal signal, creating RF sidebands\. This mixed signal then radiates out of the device and can be picked up and demodulated to recover the device’s internal signal\. In principle, almost any semiconductor device will perform mixing to some extent; in testing, the researchers had success with an amplifier, analog\-to\-digital converter, power converter, and switching MOSFETs, but detected no significant emissions without an injected signal\. For a portable setup, the researchers used a USRP B210 SDR for transmission and a spectrum analyzer to demodulate the received signal\. This was able to recover audio from wired headphones, wireless headphones, and a wireless landline, and detect the state of a smart lamp and a smart fan\. All of this worked over short distances, even through walls, and with a power amplifier, the range increased to 30 meters\. Even with multiple devices present, they could focus on one by tuning the injection frequency to resonate with its internal antennas\. Perhaps most impressive \(or concerning\) was a demonstration with the VoIP phone: the researchers were able to listen in on the person speaking, clone that person’s voice, synthesize new speech in that voice, and remotely inject it onto the phone call, altering the call in real time\. If the history of these attacks is any guide, it won’t be too long before we see an open\-source implementation of this technique; we’ve[already seen](https://hackaday.com/2017/11/26/a-tempest-in-a-dongle/)a[few approaches](https://hackaday.com/2023/03/07/pulling-data-from-hdmi-rf-leakage/)to[traditional TEMPEST](https://hackaday.com/2015/10/19/tempest-a-tin-foil-hat-for-your-electronics-and-their-secrets/)\. This kind of unintended nonlinear mixing can also be used to find[bugs](https://hackaday.com/2017/09/20/spy-tech-nonlinear-junction-detectors/)or[electronics](https://hackaday.com/2026/02/12/harmonic-radar-finds-hidden-electronics/)\. - [*![](https://hackaday.com/wp-content/themes/hackaday-2/img/share_face.png)*](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fhackaday.com%2F2026%2F09%2F20%2Freviving-tempest-attacks-with-an-injected-signal%2F) - [*![](https://hackaday.com/wp-content/themes/hackaday-2/img/share_twitter.png)*](https://twitter.com/intent/tweet?text=Reviving%20TEMPEST%20Attacks%20With%20An%20Injected%20Signal%20via%20@hackaday&url=https://hackaday.com/2026/09/20/reviving-tempest-attacks-with-an-injected-signal/) - [*![](https://hackaday.com/wp-content/themes/hackaday-2/img/share_in.png)*](https://www.linkedin.com/shareArticle?url=https%3A%2F%2Fhackaday.com%2F2026%2F09%2F20%2Freviving-tempest-attacks-with-an-injected-signal%2F) - [*![](https://hackaday.com/wp-content/themes/hackaday-2/img/share_mail1.png)*](mailto:?subject=Reviving+TEMPEST+Attacks+With+An+Injected+Signal%20|%20Hackaday&body=https%3A%2F%2Fhackaday.com%2F2026%2F09%2F20%2Freviving-tempest-attacks-with-an-injected-signal%2F)

Similar Articles

Prompt Injection Attacks Are Thwarting AI Hacking Agents

Wired

Researchers from Tracebit have developed 'context bombing,' a technique that uses prompt injections placed alongside sensitive data to trigger refusal mechanisms in AI hacking agents, significantly reducing the success rate of attacks.

Hacking Time: Spoofing Atomic Clocks with Audio Harmonics

Lobsters Hottest

The article discusses the vulnerability of consumer atomic clocks to signal spoofing via audio harmonics, detailing the technical challenges of receiving NIST's WWVB radio signals on the US East Coast due to ionospheric propagation issues.

Hacking your PC using your speaker without ever touching it

Hacker News Top

A security researcher reverse-engineers the Creative Sound Blaster Katana V2X firmware, uncovering vulnerabilities that allow attackers within 15 meters to turn the speaker into a covert spying tool and Rubber Ducky without physical access.