Hack.lu 2026

Signal processing and math for malware RnD for fun and profit

Modern AV and EDR platforms treat malware as data: they compute Shannon entropy, match byte patterns, and blacklist known cryptographic primitives. AES resembles AES. XOR is XOR.
The statistical fingerprint is always there - until you stop looking at the payload as data and start looking at it as a signal.

This presentation shows how Digital Signal Processing (DSP), particularly the Discrete Fourier Transform (DFT) and DFT-like math algorithms, with a phase shifted mathematical key, converts shellcode bytes into a buffer of complex floating point frequency coefficients. The output is mathematically indistinguishable from sensor noise or audio noise. No byte patterns: No signature of high entropy . There is no recognizable structure until the matching key is used at runtime by the Inverse DFT.

The delivery mechanism completely bypasses the network layer. The payload is encoded into audio tones and played through a speaker using FSK. A victim machine demodulates the tones with the Goertzel algorithm of a standard microphone, rebuilds the shellcode and executes it. The covert channel is physics. Like acoustic weapon. There is no socket. There is no pipe. There is no network alert.

We present a working, open-source PoC for Linux and Windows covering two threat models:
shellcode delivery (attacker -> speaker -> air -> victim mic -> execute) and data exfiltration (victim -> speaker -> air -> attacker mic -> stolen data). All source code will be released after session.


Modern AV and EDR platforms treat malware as data: they compute Shannon entropy, match byte patterns, and blacklist known cryptographic primitives. AES resembles AES. XOR is XOR.
The statistical fingerprint is always there - until you stop looking at the payload as data and start looking at it as a signal.

This presentation shows how Digital Signal Processing (DSP), particularly the Discrete Fourier Transform (DFT) and DFT-like math algorithms, with a phase shifted mathematical key, converts shellcode bytes into a buffer of complex floating point frequency coefficients. The output is mathematically indistinguishable from sensor noise or audio noise. No byte patterns: No signature of high entropy . There is no recognizable structure until the matching key is used at runtime by the Inverse DFT.

The delivery mechanism completely bypasses the network layer. The payload is encoded into audio tones and played through a speaker using FSK. A victim machine demodulates the tones with the Goertzel algorithm of a standard microphone, rebuilds the shellcode and executes it. The covert channel is physics. Like acoustic weapon. There is no socket. There is no pipe. There is no network alert.

We present a working, open-source PoC for Linux and Windows covering two threat models:
shellcode delivery (attacker -> speaker -> air -> victim mic -> execute) and data exfiltration (victim -> speaker -> air -> attacker mic -> stolen data). All source code will be released after session.

The initial thought began with me considering how to deliver a payload via an alternative physical channel. I consulted radio enthusiasts, spent hours on Google, and, of course, debated options with AI. My primary candidates were:

  • acoustic / audio - the simplest method using standard speakers and microphones.
  • ultrasonic - an "invisible" channel using the same FSK approach but at 18-22 kHz, making it inaudible to humans.
  • SDR / RF - transmitting via HackRF or LimeSDR and receiving via an RTL-SDR dongle.
  • IR / Optical - using an LED and a photodiode, encoded as pulse-width modulation (PWM).

After evaluating these vectors, I chose the acoustic / audio path for the zero-hardware dependency reason, another goal wasn't just to play a sound; it was to build a mathematical pipeline. Starting with an audible acoustic signal allowed me to perfect the Goertzel Algorithm and synchronization logic first. Also I already have using an DFT experience for shellcode encryption.

Then, we solve the two biggest enemies of acoustic data transfer: Framing and Synchronization. We will transform our "beeping" script into a real-use communication protocol.

So, we built a reliable physical-layer link. However, there is a remaining problem: if an EDR scans the memory of our receiver while it is recording, it might see the shellcode bytes in the bits or payload arrays.

In the final part, we will introduce the Discrete Fourier Transform (DFT) again. We will stop sending raw bits and start sending frequency coefficients, ensuring the shellcode only exists as "mathematical noise" until the moment of execution.

Full functional demo with one and two laptops

cocomelonc

cybersecurity enthusiast, author, speaker and mathematician. Author of popular books:
MD MZ Malware Development Book (Github, 2022, 2024)
MALWILD: Malware in the Wild Book (Github, 2023)
Malware Development for Ethical Hackers Book: (Packt, 2024)
AIYA Mobile Malware Development Book (Github, 2025)
Malware Development for Ethical Hackers 2nd edition (Packt, 2026, in progress)
Author and tech reviewer at Packt.
Co founder of various cybersecurity research labs, author of many cybersecurity blogs, HVCK magazine
Malpedia contributor
Speaker at BlackHat, DEFCON, Security BSides, Arab Security Conference, Hack.lu, Positive Hack Talks, etc conferences