TALK: What Still Works: Malware Analysis in the Age of Agents

Pierre-Marc Bureau

ABSTRACT

Twenty years into malware analysis, I keep asking myself the same question every time I read about a new AI capability: am I completely missing the boat on something crucial, or is this a distraction?

AI has genuinely saved me time on malware analysis, speeding up tedious tasks through automation and faster result validation. But it also creates real distractions: plain slop, and analysts falling victim to the Dunning-Kruger effect. The difference, in my experience, comes down to domain expertise. Analysts who understand the objectives of malware writers and operators, as well as the strengths and weaknesses of each tool category (disassemblers, decompilers, debuggers, etc.) get real value out of new AI capabilities. Analysts without that grounding end up wasting time and tokens.

This talk walks through lessons learned from doing malware analysis in the age of agents, with hands-on examples from a recent analysis of LegionLoader, a malware family used to distribute infostealers in a pay-per-install scheme, ranging from unpacking to understanding the command-and-control protocol and extracting core artifacts such as cryptographic keys and indicators.

Pierre-Marc Bureau

Pierre-Marc Bureau is an independent security researcher. He has more than 20 years of experience in malware analysis, threat intelligence, reverse engineering, and the disruption of large-scale criminal operations. Over the last decade, he has held several roles at Google — first on Chrome, then on Safe Browsing, and most recently within the Threat Analysis Group (now part of Google's Threat Intelligence Group). Across the roles, he has focused on protecting billions of users from malware and phishing. He has also supported external partners and internal Google teams in combatting financially motivated threat actors.

Before joining Google, he worked at ESET and Dell SecureWorks. At both ESET and Google, he has built and led teams of analysts. He has presented at international conferences including Black Hat Europe, Recon, Hack.lu, and Virus Bulletin.

https://www.linkedin.com/in/pierre-marc-bureau-b084a33/

MORE FROM RINGZER0 COUNTERMEASURE FALL 2026

Great! Next, complete checkout for full access to Ringzer0
Welcome back! You've successfully signed in
You've successfully subscribed to Ringzer0
Success! Your account is fully activated, you now have access to all content
Success! Your billing info has been updated
Your billing was not updated