AMTSO-compliant consumer Android malware detection test plan (ID: 202608C), defining scope, methodology, environment, and schedule for August 2026.
This document describes the Test Plan for the Testing Ground Labs (TGL) Android Malware Detection Test 2026 August C (Consumer Products). The Test is designed to independently assess the efficiency of consumer security solutions for Android OS in detecting currently widespread malicious mobile applications.
AMTSO Standard Compliance Statement
This Test has been designed to comply with the Anti-Malware Testing Standards
Organization, Inc. (“AMTSO”) Testing Protocol Standard for the Testing of
Anti-Malware Solutions, Version 1.3 (the “Standard”). This Test Plan has
been prepared using the AMTSO Test Plan Template and Usage Directions,
Version 2.4. Testing Ground Labs is solely responsible for the content of
this Test Plan.
Android is a mobile operating system developed by Google. It is based on a modified version of the Linux kernel and other open-source software and is designed primarily for touchscreen mobile devices such as smartphones and tablets. In addition, Google has developed Android TV for televisions, Android Auto for cars, and Wear OS for wrist watches, each with a specialized user interface. Variants of Android are also used on game consoles, digital cameras, PCs, and other electronics.
The popularity and openness of the Android ecosystem introduce numerous security risks for end users and organizations. Malicious activities on Android devices may include:
To protect systems and data from these and other threats, dedicated Android-based security applications exist and must be evaluated regularly against evolving malware. This Test is intended to provide an independent and repeatable assessment of the malware detection capabilities of consumer Android security solutions under realistic conditions.
In this Test, Testing Ground Labs plans to evaluate the capabilities of consumer security solutions for Android OS to detect Android threats collected from multiple sources, as well as to assess their resistance to false positives.
As a result of the Test, a certification mark will be granted to security solutions depending on their results. Testing Ground Labs plans to examine consumer security solutions for Android OS from a range of vendors (collectively, the “Test Subjects”). Specific Test Subject vendors and Participants will be determined after the Public Test Notification has been issued in accordance with AMTSO requirements.
The following high-level scope applies:
| Vendor | Software |
|---|---|
| AhnLab | AhnLab V3 Mobile Security |
| Avast | Avast Mobile Security |
| Avira | Avira Antivirus Security for Android |
| Dr.Web | Dr.Web Mobile Security Suite |
| ESET | ESET Mobile Security |
| Kaspersky | Kaspersky Plus for Android |
| McAfee | McAfee Mobile Security |
| NortonLifeLock | Norton 360 (Norton Mobile Security) |
| Total Defense | Total Defense Mobile Security |
The Test methodology is designed to be transparent, repeatable, and aligned with AMTSO best practices. The detailed process is as follows.
Testing Ground Labs selects security solutions of interest to include in this Test. Additionally, any vendor may submit a request to participate. Testing of any security solution (both those chosen by Testing Ground Labs and those submitted directly by a vendor) is free of charge to the vendor.
Every vendor will be provided with a feedback process, whereby the test lab will share Test results with that vendor. Vendors will have an opportunity to investigate their own results and submit disputes, if any, in accordance with the Dispute Process defined in this Test Plan.
Opt-Out Policy
If any vendor supplies sufficient reason as to why Testing Ground Labs
should not include their products in an upcoming or on-going Test,
Testing Ground Labs will review this request and make the corresponding
decision on a case-by-case basis.
Conflict of Interest Disclosure
At the time of this Test Plan’s release, no known conflicts of interest
exist.
Funding
This Test is free of charge for participation. Any vendor who wishes to
obtain post-Test services or other extra services may contact Testing
Ground Labs by email. Use of the Test results (including reference to
the Test report or use of Test seals) is permitted only under a marketing
rights agreement between Testing Ground Labs and the interested vendor.
The primary test environment for this Test is:
Malicious and non-malicious Android installers are collected by the Testing Ground Labs threat collection system during the two months preceding the Test commencement date. Malware is sourced from multiple feeds and regions (including China region–based sources). Non-malicious (clean) applications are used to measure false positive detection rates. Candidates for legitimate sample testing include newly released apps collected from multiple public app stores (including, but not limited to, Google Play).
Malicious and legitimate applications are independently verified by Testing Ground Labs to the extent reasonably practical, to ensure that each sample is correctly categorized as malicious or non-malicious at the time of testing.
Upon completion of the full Test, Testing Ground Labs will provide each participating vendor with data for their own non-optimal results (missed malware samples and false positives). TGL does not share a vendor’s detailed results or data with other vendors. Any tested security vendor may request the hashes of their missed samples and false positives.
Start Date Range:
Test configuration is scheduled to begin on
22nd August, 2026, and Test commencement is forecast for
27th August, 2026.
Test Duration and Calculated End Date:
The final Test Report is anticipated during the week of
20th September, 2026.
Milestones:
Interim schedule milestones are listed below.
| Index | Test Activity | Start Date Range | Dependencies |
|---|---|---|---|
| 1 | Test Commencement | August 27 2026 | — |
| 2 | Confirm Vendor Configuration Feedback | August 23 2026 – August 26 2026 | — |
| 3 | Milestone 1 – Preliminary Results | September 1 2026 | (1), (2) |
| 4 | Milestone 2 – Test Report First Edition – End of Testing Period | September 7 2026 | (3) |
| 5 | Feedback and Dispute Resolution Time – Retests as Needed | September 15 2026 | (3) |
| 6 | Milestone 3 – Issue Final Report – End Date for Test | September 20 2026 | (5) |
Communications:
All Participants will be notified if the schedule changes by two weeks or more.
Risks and Risk Management:
No additional risks are known at this time. Any material changes to
Test design or risk profile that might affect fairness or balance
will be disclosed to all Participants in a timely manner.
All security solutions in the Test will be granted access to their cloud reputation, update, and other backend services, to match typical real-world deployment conditions for end users.
Instructions for enabling and exporting logging within each product must be provided by the Participant to Testing Ground Labs upon request. Logs may be used to investigate unexpected behaviors, disputed results, or technical issues during the Test.
Any configuration information needed for automatic or manual product updates during the Testing Period must be disclosed by the Participant. Testing Ground Labs will endeavor to ensure that all tested products are up to date prior to and during testing, in line with normal end-user expectations.
For each security solution, a Final Score will be calculated once the full Test has been performed, based on malware detection and false positive counts.
For each security solution, the Final Score is defined as:
Final Score = (Detection %) × 100 − 0.2 × FP
Based on the Final Score, a corresponding rating will be granted to each participating security solution, according to the table below.
| Final Score | Monthly Award |
|---|---|
| 98.00 – 100.00 | ★★★★★ 5-star rating |
| 95.00 – 97.99 | ★★★★ 4-star rating |
| 90.00 – 94.99 | ★★★ 3-star rating |
False positives (FP) are computed based on detections within the designated set of clean application installers. Each false positive reduces the Final Score by 0.2 points under the above formula.
The dispute process runs for eight business days commencing from the end of the Test (i.e., following Milestone 2: Test Report First Edition). Please refer to Section 6 (Schedule) for additional timing details.
The general Dispute Process operates as follows:
I understand and agree that I am submitting this Test Plan, and the following Attestations, on behalf of the entity listed below, and I represent and warrant that I have authority to bind such entity to these Attestations. All references to “I” or “me” or similar language refer to such entity. I represent and warrant that the following Attestations are true, to the best of my knowledge and belief, and that each of the following commitments will be upheld to the best of my ability.
I hereby affirm, to the best of my knowledge and belief, that this Test Plan complies with the AMTSO Testing Standards as of the date hereof.