Mousejacking is an attack that exploits wireless keyboard or mouse traffic to impersonate the device and inject commands into a connected computer. The attacker uses a nearby radio device to capture or spoof input signals, which can lead to malware installation, credential theft, or privileged account abuse.
Mousejacking and how it works
Mousejacking is a proximity-based input injection attack against wireless peripherals. It targets the trust that a computer places in a mouse or keyboard receiver, then exploits that trust to send unauthorized clicks or keystrokes as if they came from the legitimate device.
The core idea is not malware on the peripheral itself, but abuse of the wireless link and its pairing or encryption weaknesses. Once an attacker can impersonate the device or the receiver accepts forged traffic, the attacker can control the host with the same authority as normal user input.
Attack path and prerequisites
Mousejacking typically depends on a nearby attacker with radio capability and a vulnerable wireless protocol, receiver, or configuration. Some attacks require only passive observation before active injection; others rely on weak pairing, predictable addressing, or insufficient authentication in the peripheral link.
Because the attack happens over the air, the victim may not notice any obvious physical intrusion. The useful window is often small and opportunistic, but the technique is effective in offices, meeting rooms, and other places where users assume wireless peripherals are benign.
What mousejacking can do
Once the attacker can inject input, the consequences can move quickly from nuisance to full compromise. A single trusted click can open a shell, launch a browser payload, alter security settings, or start a download that leads to malware installation.
Mousejacking is especially dangerous because it abuses the normal trust boundary between human input and system control. If the injected commands are accepted as legitimate user actions, the attacker may be able to steal credentials, create persistence, or abuse privileged sessions already open on the machine.
Defensive controls and where to focus
Defence starts with understanding which wireless peripheral technologies are in use and whether they rely on strong, modern encryption and authenticated pairing. Legacy 2.4 GHz receivers and poorly designed dongles have historically been the most exposed, so inventory and replacement decisions matter.
Where possible, prefer peripherals and receivers with strong pairing and encryption, keep firmware updated, and restrict unattended access to endpoints that accept wireless input. On sensitive systems, physical control of the workstation still matters because proximity is part of the attack condition.
Risk and Threat Considerations
Mousejacking matters because it turns a convenience feature into a local attack path. The attacker does not need account credentials first, only nearby access and a device link that can be spoofed or abused.
Failure mechanism: A compromised or weakly protected wireless receiver accepts forged mouse or keyboard traffic, letting the attacker inject commands that the host treats as trusted user input.
Impact: The result can include malware delivery, privilege escalation through injected actions, credential theft, and control of an already authenticated session.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Mousejacking abuses trusted input to reach authenticated user actions. |
| IA-3 — Device Identification and Authentication | Wireless peripherals and receivers need device trust before accepting input. | |
| IA-5 — Authenticator Management | The attack often depends on weak or outdated wireless credential handling. | |
| Recommendation — Harden interactive sessions so injected input cannot be used to gain or extend user access. Require authenticated device pairing before accepting wireless peripheral traffic. Rotate, protect, and replace weak wireless peripheral secrets and credentials promptly. | ||
| CIS Controls v8 | CIS-4 — Secure Configuration of Enterprise Assets and Software | Peripheral and firmware hardening reduces exposed wireless input paths. |
| CIS-6 — Access Control Management | Mousejacking can create unauthorized access through trusted input streams. | |
| Recommendation — Standardize secure peripheral configurations and remove vulnerable wireless input devices. Limit interactive access on sensitive systems to reduce impact from injected commands. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | The attack exploits implicit trust in local input and nearby devices. |
| Recommendation — Assume nearby input devices are untrusted until explicitly verified. | ||
Practitioner Guidance
What to watch for: Treat wireless peripheral security as an endpoint control, not just a hardware preference. If a fleet still uses older dongles or mixed peripheral models, the risk profile can vary widely between systems even when the user experience looks identical.
Governance implication: Security teams should know which endpoints allow wireless input, which receivers are in circulation, and whether the vendor supports secure pairing and firmware maintenance. That visibility makes it easier to decide where wireless convenience is acceptable and where it is not.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org