Category: Security

Turning a Smartphone’s Speaker Amplifier into a Silent Intentional VHF Morse Transmitter

Thank you to Efe Işık (TA1EEI) for writing in and sharing with us his open-source project showing how to turn a modern Android smartphone’s internal Class-D speaker amplifier into a silent, intentional VHF Morse transmitter. Efe writes:

By pushing inaudible 21 kHz full-amplitude PCM audio via Android's AudioTrack, the amplifier's PWM switching circuit radiates near-field RF harmonics into the 144 MHz (VHF) band. The signal is strong enough to be received in AM mode on common SDRs and BK4819-based handheld transceivers (such as the Quansheng UV-K5) simply by placing the antenna near the speaker grill.

Everything is open-source, requires zero Android permissions, and includes instructions on receiver setup and frequency alignment.

With the software running on the Android device, simply use an SDR or handheld radio to look for the signal in the 144 - 146 MHz region. Increasing the volume can help increase transmission power.

This reminds us of the TrojPix project, a more sophisticated method that uses a program on a PC to imperceptibly modulate pixels on a screen, effectively turning video cable/screen EMI into an air-gapped data transfer path.

InjectEave: Eavesdropping on Headphones by Injecting a Carrier and Listening to the Modulated Retransmission

Researchers from the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University recently published a paper titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity".

The paper describes how an attacker can use a directional antenna to transmit a carrier signal toward an electronic device, where nonlinearities in its components modulate the signal, which connected cables then re-radiate as unintentional antennas. The attacker can then receive the modulated carrier at the same frequency as it is transmitted and demodulate the modulated sidebands.

The Injecteave Process
The Injecteave Process

In their experiments, they used a USRP B210 software-defined radio to transmit the CW injection signal at anywhere from 0 to 8 MHz (the exact frequency for a device is not specified in the paper for ethical considerations), and a spectrum analyzer to receive the injection-induced EM leakage. The spectrum analyzer demodulates the received mixed signal, then routes the baseband to a PC for further processing. They show how various wired and wireless headphones exhibited injection-induced leakage via the amplifier, and how landline desk phones, smart fans, and lamps were also susceptible.

They also show a real-world application where they eavesdropped on audio from headphones and desk phones through walls in a hotel, meeting room, and office.

Update: Thanks to a commenter for pointing out the InjectEave demo page at https://injecteave.github.io.

InjectEave: Real World Examples
InjectEave: Real World Examples

An HTML Browser Page that Uses Display Pixel Clock EMI Leakage to Transmit VHF Morse Code

Thank you to Efe (TA1EEI) for writing in and sharing an HTML web tool he created that uses a PC monitor to transmit Morse code. The tool works by modulating the monitor's pixel clocks to intentionally generate EMI leakage in the form of a Morse code signal. It transmits at 148.5 MHz.

Efe's work appears to be a much simpler version of TrojPix, a University research project that we posted about back in July. TrojPix is a more advanced system that introduces imperceptible pixel modulations into the screen, making high-bandwidth wireless data transfer possible via monitor EMI leakage.

The GitHub project page for Efe's VHF Monitor RF Transmitter explains exactly how the project works, including the video pixel clock and how it can be modulated and transmitted wirelessly. Efe has also provided a link to a Reddit post where there is a video, and discussion. 

VHF Morse Code Transmitted via an HTML Page
VHF Morse Code Transmitted via an HTML Page

More Information about the FrameRF Technical Surveillance Counter-Measures Platform – Technical Guest Post

Earlier this month, we posted about Stefano Cangiano, an Italian TSCM (Technical Surveillance Counter-Measures) specialist, and his recently released FrameRF product. Stefano describes FrameRF as "a professional SDR-based TSCM analysis platform designed to help operators rapidly identify, classify, and prioritize RF signals in complex environments." Its main use case is for identifying RF bugs, corporate security audits, and finding anomalous signals.

Recently, Stefano wrote in again and wanted to share some further technical details about his product. Stefano notes that the core idea of FrameRF is to solve the TSCM question: "What happened in the RF environment over the last few hours, and how did it behave?" The system logs RF activity as timestamped events across cellular, Wi-Fi, BLE, DECT, and other signals, correlates them with physical events, and highlights anomalies and intermittent transmitters like event-triggered GPS trackers as leads for further investigation.

Stefano's full write-up is available as a PDF, which you can download here.

The FrameRF Product
The FrameRF Product

KrakenSDR Tested as a GNSS Jammer and Spoofer Localizer

KrakenSDR is our 5-channel coherent software-defined radio designed for applications such as radio direction finding. It was successfully crowdfunded on Crowdsupply back in 2021. We've recently come across a 2025 paper in the Journal of the Institute of Navigation, describing how KrakenSDR was successfully tested as a real-world GNSS jammer and spoofer localizer.

Global Navigation Satellite System (GNSS) services such as GPS are easily jammed by hostile terrestrial signals due to their low transmit power. Jamming is commonly used in modern conflict environments, and is seen heavily in use around Ukraine, Russia, and the Middle East. Similarly, spoofing, which is transmitting a fake GNSS signal to trick receivers into seeing fake locations, is also in use. 

In their paper, Lasse Lehmann et al. from the Technical University of Denmark demonstrate the use of a KrakenSDR for detecting GPS L1 jammers at 1575.42 MHz. The tests were performed at Jammertest 2023, an annual event for open GNSS experiments, and they were able to locate a spoofer down to 18.1 meters via a vehicle-mounted KrakenSDR .

A KrakenSDR Setup at Jammertest 2023
A KrakenSDR Setup at Jammertest 2023

Carshepherd: An Android RTL-SDR App For the Early Awareness of Nearby Emergency-Service Vehicles

Thank you to Cees for writing in and sharing his Android app, "Carshepherd," which is currently in the pre-release stage. Carshepherd works with a connected RTL-SDR and TETRA antenna to give drivers early awareness of nearby emergency-service activity (such as police, ambulance, fire) by detecting the TETRA uplink signal.

Cees notes that this is essentially the same as what hardware devices like 'Target Blu Eye' do to detect emergency services. Laser/radar detectors are illegal in most European countries, and while not advertised as such for legal reasons, Carshepherd could be a legal alternative for detecting laser/radar speed traps, detecting ProViDa video-based pacing vehicles, or just for general awareness.

The app works by continuously sweeping the TETRA bands, looking for the signature of a TETRA carrier. Once it detects a confirmed uplink carrier, it estimates proximity, which then triggers a readout and audible alert. The TETRA uplink is not always active, but emergency service vehicles often send bursts of uplink data every few seconds with GPS position updates, and, of course, during voice PTT.

The algorithm is based on a large labeled dataset from dozens of real-world test drives. The dataset trains an AI classifier that can even tell you whether an emergency unit is keeping pace with you (e.g., traveling down the same stretch of motorway as you) or whether you are approaching a stationary unit.

Carshepherd currently only works in countries whose emergency services use the TETRA communications protocol, which includes most of Europe and various other countries, but notably not the USA. However, Cees notes that they are working on a US version that will listen to the P25 network.

While Carshepherd has not yet been released, the pricing is indicated as €3.99 per month. You can sign up for the waitlist at www.carshepherd.nl.

Sept 5 2026 Update: Carshepherd is now live on the Google Play Store.

Carshepherd Android UI
Carshepherd Android UI

ESP32 Bit Pirate Updates: New LoRa and Meshtastic Analysis Features

Back in September 2025, we posted about the "ESP32 Bus Pirate" firmware, which transforms an ESP32-S3 into a multi-protocol debugging and hacking tool. We later covered an update in March 2026 that added waterfall displays, cellular modem support, and an external radio expander.

Although the ESP32 does not have true SDR capabilities, it can leverage its numerous built-in radio hardware components to achieve a range of interesting SDR-like features. Recently, "Geo," the creator of the ESP32 Bus Pirate, wrote in to share some recent firmware updates with us.

Geo notes that the project is now called "ESP32 Bit Pirate" and now includes LoRa/SX1262 support and Meshtastic analysis features.

ESP32 Bit Pirate can now transmit and receive LoRa packets, monitor RSSI, scan frequency activity, display a simple waterfall view and perform Channel Activity Detection. Radio parameters including frequency, bandwidth, spreading factor, coding rate, transmit power, preamble and sync word can be configured directly from the interface.

Packets can also be recorded to the ESP32 filesystem and replayed later together with their original radio configuration.

A dedicated Meshtastic analysis shell has also been added, allowing users to send, receive and inspect Meshtastic packets. The goal is not to replace a Meshtastic node, but to provide a debugging and experimentation interface for understanding and interacting with LoRa/Meshtastic traffic.

The latest update has also added new LoRa hardware support for the Heltec Vision Master T190 and Heltec WiFi LoRa 32 V4, a browser-based debugging ecosystem, a Python scripting lab, and a BPIO2 USB adapter mode.

The project is entirely open source, and the code can be found on their GitHub page.

ESP32 Bit Pirate LoRa Support Added
ESP32 Bit Pirate LoRa Support Added

FrameRF: An SDR-Based Technical Surveillance Counter-Measure Analysis Platform

Thank you to Stefano Cangiano, an Italian TSCM (Technical Surveillance Counter-Measures) specialist, for writing in and sharing with us about the release of his FrameRF product. Stefano writes:

After more than ten years of operational field experience, I developed FrameRF, a professional SDR-based TSCM analysis platform designed to help operators rapidly identify, classify and prioritize RF signals in complex environments.

Rather than replacing existing SDR software, FrameRF focuses on operational analysis by correlating multiple wireless technologies (Wi-Fi, Bluetooth, BLE, GSM, LTE and others) into a single workflow that supports real-world investigations.

FrameRF has been developed from real operational TSCM field experience, with the goal of reducing RF analysis time and helping operators make faster and more informed decisions during technical inspections.

To summarize, FrameRF appears to be a portable deployable kit, consisting of a laptop, SDR hardware, antennas, and custom software in a rugged briefcase. The product is intended to be used by TSCM specialists for applications like sweeping for RF bugs, corporate security audits, and finding anomalous signals.

It can do things like detect LTE voice activity, automatically classify signals, alert the user based on patterns, detect a DECT phone call, recognize Apple AirTags, estimate if different random Bluetooth MAC addresses belong to the same physical device, analyze the WiFi environment, reconstruct device relationships, and detect hidden WiFi networks and potential spoofing.

If you are interested, Stefano has provided a PDF brochure explaining the product further.

FrameRF Live Monitor
FrameRF Live Monitor
FrameRF – Professional RF Behavioral Analysis Platform | TSCM Video Demonstration