BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//BZU839
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251022T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Signal processing and math for malware RnD for fun and profit - co
 comelonc
DTSTART;TZID=Europe/Luxembourg:20261022T111500
DTEND;TZID=Europe/Luxembourg:20261022T114500
DTSTAMP:20261009T054124Z
UID:pretalx-hack-lu-2026-BZU839@pretalx.com
DESCRIPTION:Modern AV and EDR platforms treat malware as data: they comput
 e Shannon entropy\, match byte patterns\, and blacklist known cryptographi
 c primitives. AES resembles AES. XOR is XOR.\nThe statistical fingerprint 
 is always there - until you stop looking at the payload as data and start 
 looking at it as a signal.\n\nThis presentation shows how Digital Signal P
 rocessing (DSP)\, particularly the Discrete Fourier Transform (DFT) and DF
 T-like math algorithms\, with a phase shifted mathematical key\, converts 
 shellcode bytes into a buffer of complex floating point frequency coeffici
 ents. The output is mathematically indistinguishable from sensor noise or 
 audio noise. No byte patterns: No signature of high entropy . There is no 
 recognizable structure until the matching key is used at runtime by the In
 verse DFT.\n\nThe delivery mechanism completely bypasses the network layer
 . The payload is encoded into audio tones and played through a speaker usi
 ng FSK. A victim machine demodulates the tones with the Goertzel algorithm
  of a standard microphone\, rebuilds the shellcode and executes it. The co
 vert channel is physics. Like acoustic weapon. There is no socket. There i
 s no pipe. There is no network alert.\n\nWe present a working\, open-sourc
 e PoC for Linux and Windows covering two threat models:\nshellcode deliver
 y (attacker -> speaker -> air -> victim mic -> execute) and data exfiltrat
 ion (victim -> speaker -> air -> attacker mic -> stolen data). All source 
 code will be released after session.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/BZU839/
END:VEVENT
END:VCALENDAR
