Agenda - Cybersecurity Conference

Talks at AVAR 2026
A Familiar Face: Analysis of a new Sharp Panda attack campaign
Nguyen Duc Kiem, Doan Minh Long, Viettel Cyber Security
An Open Directory and a SEA of Victims: Tracing a China-Nexus Operation Through an OPSEC Mistake
Sathwik Ram Prakki, Group-IB
Automated Payload Recovery and Tactic Detection Across macOS Active Families
Rajesh Krishna Nikam, CrowdStrike
Beyond the Implant: Reverse Engineering Native AOT Malware and Exposing a 30,000-Agent Operator Ecosystem
Baskar M, Rahul Ramesh, Cyderes
Breaking Boundaries: Infostealer Strategies in the App-Bound Encryption Era
Vojtěch Krejsa, Jan Rubín, Gen Digital
Bundled and Under the Radar: Malware Abuse of Bun and Deno
Jaromír, Check Point
Countering EDR/DR Bypass: A Multi-Layered Approach to Detection, Response, and Data Protection
Varun Prasanth K, SivaSelvan Dhandapani, Staples Innovation Hub
Cybersecurity Assurance for Drone & UAV Infrastructure
Gopinath Lakshmanan, Sify Technologies
Dead Container Walking: Post-Incident Analysis When Your Workload Is Already Gone
Saurabh Mishra, Optum
Diffing for Intent: Stopping Supply-Chain Malware at the Code-Signing Gate
Rishal Dwivedi, Kushal Rajput Lilhare, Adobe
From Compiler to Concealment: Why Zig Is Becoming the Language of Choice for Linux Threat Actors
Tejaswini Sandapolla, Sentinelone
From Function-Centric AI to Continuous Cyber Resilience: Exploring Agentic AI for Adaptive and Quantum-Ready Cybersecurity
Felissa Mariz Marasigan, Mr Mark Jenri Ocampo, EY-GDS
From Open Directories to AI-Coded Malware: How a Pakistan-Nexus Threat Actor Leaked Their Entire Arsenal Targeting Afghan Telecom and South Asian Critical Infrastructure
Subhajeet Singha, Acronis International GmBH
Garbage In, Verdict Out: AI-Driven Malware Triage and the Disassembler It Never Questions
Jagadeesh Chandraiah, Sophos
Harmonizing AI Agents and Human Analysts in CTI – Are CTI Agents Friends or Rivals to Junior Analysts
Takahiro Kakumaru, NEC Corporation
Hidden in the Overlay Analysis of Backdoor Leveraging Encrypted Overlay Communications for ORB
Yuma Masubuchi, JPCERT/CC
HijackLoader: Polymorphic DLL Injection as a Vector for Multi-Stage Attacks
Oleg Gayduk, Maxim Demidenko, Doctor Web
I.A.P. – It’s Always Policies! (… Until Reality Gets Involved)
Righard Zwienenberg, ESET
Eddy WIllems, WAVCi
Intent-Driven Contextual Reasoning Using Sentence Transformers for Business Email Compromise Detection
Abhishek Singh, Mimecast
Lord Of The Ring 0
Adhokshaj Mishra, Animesh Roy, SentinelOne
Maritime Cyber Security
Akash Saksena Capgemini
Masks, Monsters, and Drivers : Inside the Chaos, Kraken, and DeadLock Ransomware Operations
Chetan Raghuprasad, Cisco Talos
mrhOTshOT: Replaying the World’s Deadliest ICS Attacks — Complete IT+OT Kill Chains for 12 Real Malware Families
Malav Vyas, Asher Loranca, Palo Alto Networks
npm install –dprk: DeceptiveDevelopment’s Supply-Chain Playbooks Against Developers
Ettore Bordoni, ESET
Operation RTO Heist: Anatomy of a Long-Running RTO Phishing Campaign Targeting Indian Users
Rupali Parate, Cyble
Practical Binary Emulation and Taint Analysis for De-obfuscation
Tạ Đăng Vinh, Nguyễn Duy Bình, VNPT Cyber Immunity
PromptSpy: A Framework for Simulating Indirect Prompt Injection Across Autonomous Email Pipelines
Prashant Kumar, Forcepoint Software India Pvt. Ltd
Reconstructing the DPRK Cyber Ecosystem: Infrastructure Pivoting, Malware Lineage, and Operational Attribution
Dixit Panchal NetProtector AV, Mr Vaibhav Billade Deloitte
RenEngine Loader: Catch’Em All – Inside a 1.6 Million-Victim Global Stealer Campaign Hidden in a Game Engine
Rahul Ramesh, Reegun Richard Jayapaul, Cyderes
Rule-Based versus Semantic Web Application Firewalls under LLM-Driven Adaptive SQL-Injection Evasion at the Maximum Protection Setting
Karan Khatri Regmi, SecureIQ Lab
Same Actor, New Voice: Testing Whether AI Rewriting Actually Breaks Threat Actor Attribution
Rishika Subhash Desai, BforeAI
The State of the macOS *Fix Ecosystem and Apple’s Defenses
Bhargav Rathod, Palo Alto Networks
Selective AI Augmentation for Scalable and Cost-Efficient Malware Triage
Tonmoy Jitu, Rowland Yu, Sophos
The Phone Bill You Never Made: Six Years of VoIP Toll Fraud Operations
Abhinav Thakur, Cyble
Transparency Wars: Exposing Hidden Biases in Testing
Luis Corrons, Gen Digital
Righard Zwienenberg, ESET
Weaponizing Trust: An Analysis of TeamPCP’s Cross-Platform Multi-Wave Supply Chain Attacks
Praveen Babu D, Srinivasan E, K7 Computing Pvt Ltd
Who’s the Boss Now: Hijacking WhatsApp Web Sessions for Enterprise Fraud
Azhagan K M S, Priyadharshini P, K7 Computing Pvt Ltd
Reserve Papers
Confining Cross-Site Prompt Injection in Web Agents
Viren Chaudhari, Rushikesh Chandak, Qualys
Good Vibes, Shady Scripts :: Vow to Protect, Woe to Detect
Kaarthik R Muthukrishnan, K7 Computing Pvt Ltd
Install. Execute. Persist. Repeat : LLM-Assisted Reverse Engineering of Execution Paths in Malicious Packages
Satyam Singh, Avinash Kumar, Dr. Nirmal Singh, Zscaler Inc.
Living Off Trusted Software: Anatomy of a Modern Spear-Phishing Campaign
Shrutirupa Banerjiee, Anjali Raut, Seqrite

Note:

  • The above is the list of confirmed papers and speakers. More papers and speakers will be added soon. Please bookmark this page to view the detailed AVAR 2026 Agenda.
  • The above list is not in the order of presentation