A researcher published a proof-of-concept showing Linux shellcode delivered over an acoustic channel and executed by a receiver that demodulates audio with the Goertzel algorithm. The scheme uses frequency-shift keying at 300 baud, mapping bits to 2200 Hz and 1200 Hz tones, while a Python transmitter wraps the payload in a frame containing a 5-byte preamble, a 16-bit big-endian length field, the payload, and a 1-byte XOR checksum to improve synchronization and integrity.
On the receiving side, a C program records 6 seconds of 48 kHz, 16-bit mono audio through ALSA, brute-forces 16 sample offsets to recover alignment, scans for the preamble, reconstructs the payload, and verifies the checksum before allocating RWX memory with mmap to run the recovered shellcode. The demonstration was presented as educational research into more reliable acoustic payload transfer in noisy environments, with the author also noting future work to hide shellcode as frequency-domain coefficients to reduce memory visibility to EDR tools.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A follow-up blog post detailed fixes for two reliability issues in the acoustic Bell 202 FSK receiver: bit straddling from unsynchronized sampling boundaries and ALSA buffer overruns. The updated PoC used 0.1-second chunked audio capture with EPIPE recovery, brute-force sub-bit alignment scanning, and then decoded and executed Linux x86_64 shellcode recovered from audio.
A blog post published an educational proof of concept for delivering and executing Linux shellcode over an acoustic FSK channel. The write-up described framing and synchronization improvements, Goertzel-based demodulation, checksum validation, and execution of the recovered payload from RWX memory.
A new part of the educational PoC series showed how to embed a Bell 202 FSK data stream into music, encode it as MP3, and recover the transmitted frame on the receiving side despite compression and playback/capture clock drift. The write-up also described receiver changes for coarse offset search, symbol-clock recovery, repeated-frame handling, and checksum-failure recovery, while noting the technique is not an MP3 parser exploit and requires a separate listening receiver.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalware.news
Open sourcecocomelonc.github.io
Open sourcemalware.news
Open sourcegithub.com
Open sourcecocomelonc.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.