Livehunt allows you to hook into the stream of files submitted to VirusTotal and get notified whenever one of them matches a certain rule written in the YARA language. Applying YARA rules to the files submitted to VirusTotal you should be able to get a constant flow of malware files classified by family, discover new malware files not detected by antivirus engines, collect files written in a given language or packed with a specific run-time packer, create heuristic rules to detect suspicious files, and, in general, enjoy the benefits of YARA's versatility acting on the huge amount of files processed by VirusTotal every day.
Besides hunting for files in real time as they arrive to VirusTotal, you can also apply your YARA rules to files sent in the past with Retrohunt. A Retrohunt job takes around ~3-4 hours to complete and scans over 600TB of files sent to VirusTotal during the past year.
Both Livehunt and Retrohunt can be automated using the VirusTotal API v3.