SANDS Lab presents at global security conference 'VB2025' — unveils next-gen CTI technology powered by generative AI
SANDS Lab presented next-generation CTI technology using generative AI at VB2025, drawing attention from the global security industry.
SANDS Lab (KOSDAQ 411080, CEO Kim Ki-hong) announced it presented next-generation CTI (cyber threat intelligence) technology using generative AI at 'Virus Bulletin 2025' (VB2025), one of the world's most prestigious cybersecurity conferences, held in Berlin, Germany from September 24-26.
VB2025 is an international security conference hosted by global antivirus testing body Virus Bulletin, bringing together security companies and researchers from around the world every year since 1989 to share the latest threat-analysis findings. SANDS Lab presented in both of this year's main tracks — Green Room and TIPS (Threat Intelligence Practitioners' Summit) — earning recognition for its research capabilities from the global security industry.
In the Green Room session, SANDS Lab's research team (senior researchers Jeon Chan-bin, Kim Chang-gyun, and Lim Seung-beom) presented a case study using LLM technology to emulate an expert malware analyst and automatically track and analyze 'x86,' a new IoT botnet malware discovered in January.
'x86' infected more than one million IoT devices worldwide, showing outsized impact despite its simple structure. The team applied a hybrid automation framework combining function-level embedding-vector analysis with large language models, using it to clearly trace the malware's lineage as qBot → Demon → Rebirth → Rebirth Reborn and attribute it to threat group 'CTX-5341.'
In the TIPS session, SANDS Lab's threat analysis team lead Heo Su-man presented on improving CTI evaluation frameworks around the quality and usability of threat intelligence data. He pointed out the limits of today's threat intelligence — generated in the tens or hundreds of millions daily — where a focus on sheer quantity erodes real reliability and regional/contextual value, and proposed a 'quality- and trust-based evaluation model' that goes beyond simple IoC sharing to clarify collection background, evaluation purpose, and grounds for generation.
CEO Kim Ki-hong said, "The research unveiled at VB2025 is next-generation CTI technology using generative AI to emulate an expert analyst's capabilities and automatically track and analyze malware. We will continue to lead AI- and LLM-based security technology that can respond to evolving cyber threats, contributing to the development of the global security ecosystem."