cocomelonc
cybersecurity enthusiast, author, speaker and mathematician. Author of popular books:
MD MZ Malware Development Book (Github, 2022, 2024)
MALWILD: Malware in the Wild Book (Github, 2023)
Malware Development for Ethical Hackers Book: (Packt, 2024)
AIYA Mobile Malware Development Book (Github, 2025)
Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress)
Author and tech reviewer at Packt.
Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine
Malpedia contributor
Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Positive Hack Talks, etc conferences
Session
Modern AV and EDR platforms treat malware as data: they compute Shannon entropy, match byte patterns, and blacklist known cryptographic primitives. AES resembles AES. XOR is XOR.
The statistical fingerprint is always there - until you stop looking at the payload as data and start looking at it as a signal.
This presentation shows how Digital Signal Processing (DSP), particularly the Discrete Fourier Transform (DFT) and DFT-like math algorithms, with a phase shifted mathematical key, converts shellcode bytes into a buffer of complex floating point frequency coefficients. The output is mathematically indistinguishable from sensor noise or audio noise. No byte patterns: No signature of high entropy . There is no recognizable structure until the matching key is used at runtime by the Inverse DFT.
The delivery mechanism completely bypasses the network layer. The payload is encoded into audio tones and played through a speaker using FSK. A victim machine demodulates the tones with the Goertzel algorithm of a standard microphone, rebuilds the shellcode and executes it. The covert channel is physics. Like acoustic weapon. There is no socket. There is no pipe. There is no network alert.
We present a working, open-source PoC for Linux and Windows covering two threat models:
shellcode delivery (attacker -> speaker -> air -> victim mic -> execute) and data exfiltration (victim -> speaker -> air -> attacker mic -> stolen data). All source code will be released after session.