AMTSO-Compliant Test Plan

Android Malware
Detection Test Plan

AMTSO-compliant consumer Android malware detection test plan (ID: 202608C), defining scope, methodology, environment, and schedule for August 2026.

Test Window August–September 2026
Plan Version 1.0
Initial Release 2026.08.25
202608C
AMTSO Test ID (Planned)
Android 14
Target Platform
1k–2k
Malware Samples
300–500
Clean Installers
AMTSO Compliance (Illustrative)
AMTSO Testing Protocol Standard v1.3 Alignment
This Test Plan has been prepared using the AMTSO Test Plan Template and is designed to comply with the AMTSO Testing Protocol Standard for the Testing of Anti-Malware Solutions, Version 1.3.
Navigation

Table of Contents

v1.0 · 2026.08.25 Initial Test Plan publication for the August 2026C Consumer Android Malware Detection Test.
Section 01

Introduction

Keywords
anti-malware; compliance; assessment; testing; test plan; Testing Ground Labs; Android Detection
Initial Release
August 25th, 2026 · Version 1.0

This document describes the Test Plan for the Testing Ground Labs (TGL) Android Malware Detection Test 2026 August C (Consumer Products). The Test is designed to independently assess the efficiency of consumer security solutions for Android OS in detecting currently widespread malicious mobile applications.

AMTSO Standard Compliance Statement
This Test has been designed to comply with the Anti-Malware Testing Standards Organization, Inc. (“AMTSO”) Testing Protocol Standard for the Testing of Anti-Malware Solutions, Version 1.3 (the “Standard”). This Test Plan has been prepared using the AMTSO Test Plan Template and Usage Directions, Version 2.4. Testing Ground Labs is solely responsible for the content of this Test Plan.

Android is a mobile operating system developed by Google. It is based on a modified version of the Linux kernel and other open-source software and is designed primarily for touchscreen mobile devices such as smartphones and tablets. In addition, Google has developed Android TV for televisions, Android Auto for cars, and Wear OS for wrist watches, each with a specialized user interface. Variants of Android are also used on game consoles, digital cameras, PCs, and other electronics.

The popularity and openness of the Android ecosystem introduce numerous security risks for end users and organizations. Malicious activities on Android devices may include:

To protect systems and data from these and other threats, dedicated Android-based security applications exist and must be evaluated regularly against evolving malware. This Test is intended to provide an independent and repeatable assessment of the malware detection capabilities of consumer Android security solutions under realistic conditions.

Section 02

Scope and Participants

In this Test, Testing Ground Labs plans to evaluate the capabilities of consumer security solutions for Android OS to detect Android threats collected from multiple sources, as well as to assess their resistance to false positives.

As a result of the Test, a certification mark will be granted to security solutions depending on their results. Testing Ground Labs plans to examine consumer security solutions for Android OS from a range of vendors (collectively, the “Test Subjects”). Specific Test Subject vendors and Participants will be determined after the Public Test Notification has been issued in accordance with AMTSO requirements.

The following high-level scope applies:

Planned Test Subjects
Vendor Software
AhnLab AhnLab V3 Mobile Security
Avast Avast Mobile Security
Avira Avira Antivirus Security for Android
Dr.Web Dr.Web Mobile Security Suite
ESET ESET Mobile Security
Kaspersky Kaspersky Plus for Android
McAfee McAfee Mobile Security
NortonLifeLock Norton 360 (Norton Mobile Security)
Total Defense Total Defense Mobile Security
Section 03

Methodology

The Test methodology is designed to be transparent, repeatable, and aligned with AMTSO best practices. The detailed process is as follows.

  1. Test Device Preparation
    Several Android-based mobile devices are prepared and clean backup images are created. The primary platform for this Test is:
    • Android 14 on Samsung Galaxy S22 (256 GB internal storage).
  2. Sample Collection
    Approximately 1,000–2,000 Android malware samples and 300–500 different clean Android application installers are collected and delivered in a mixed set to the internal storage of the mobile devices. Malware samples are collected from multiple sources (including China region–based feeds and other international channels). Clean applications are obtained from Google Play and other legitimate app stores.
  3. Product Installation
    Selected consumer security applications are installed on the physical mobile devices using their default configuration.
  4. Product Updates
    Each security application and its antivirus bases (signatures and related components) are updated to the latest available versions before testing begins and as needed during the Test Period.
  5. On-Demand Scan (Static Detection)
    A full scan of the mixed collection is run by each security application. Malware detection rates and false positive detections are recorded.
  6. On-Execution Detection (Dynamic Behavior)
    Each malicious sample that was not detected during the on-demand scan is subsequently installed and executed. Any detection that occurs during or after execution is recorded.
  7. Benign Application Handling
    Installation of clean applications is not performed. They are scanned only, to measure the false positive detection rate without unnecessary risk to device stability.
Section 04

Participation

Testing Ground Labs selects security solutions of interest to include in this Test. Additionally, any vendor may submit a request to participate. Testing of any security solution (both those chosen by Testing Ground Labs and those submitted directly by a vendor) is free of charge to the vendor.

Every vendor will be provided with a feedback process, whereby the test lab will share Test results with that vendor. Vendors will have an opportunity to investigate their own results and submit disputes, if any, in accordance with the Dispute Process defined in this Test Plan.

Opt-Out Policy
If any vendor supplies sufficient reason as to why Testing Ground Labs should not include their products in an upcoming or on-going Test, Testing Ground Labs will review this request and make the corresponding decision on a case-by-case basis.

Conflict of Interest Disclosure
At the time of this Test Plan’s release, no known conflicts of interest exist.

Funding
This Test is free of charge for participation. Any vendor who wishes to obtain post-Test services or other extra services may contact Testing Ground Labs by email. Use of the Test results (including reference to the Test report or use of Test seals) is permitted only under a marketing rights agreement between Testing Ground Labs and the interested vendor.

Section 05

Environment

Physical Configuration

The primary test environment for this Test is:

Sample Relevance

Malicious and non-malicious Android installers are collected by the Testing Ground Labs threat collection system during the two months preceding the Test commencement date. Malware is sourced from multiple feeds and regions (including China region–based sources). Non-malicious (clean) applications are used to measure false positive detection rates. Candidates for legitimate sample testing include newly released apps collected from multiple public app stores (including, but not limited to, Google Play).

Curation Process

Malicious and legitimate applications are independently verified by Testing Ground Labs to the extent reasonably practical, to ensure that each sample is correctly categorized as malicious or non-malicious at the time of testing.

Distribution of Test Data

Upon completion of the full Test, Testing Ground Labs will provide each participating vendor with data for their own non-optimal results (missed malware samples and false positives). TGL does not share a vendor’s detailed results or data with other vendors. Any tested security vendor may request the hashes of their missed samples and false positives.

Section 06

Schedule

Start Date Range:
Test configuration is scheduled to begin on 22nd August, 2026, and Test commencement is forecast for 27th August, 2026.

Test Duration and Calculated End Date:
The final Test Report is anticipated during the week of 20th September, 2026.

Milestones:
Interim schedule milestones are listed below.

Index Test Activity Start Date Range Dependencies
1 Test Commencement August 27 2026 —
2 Confirm Vendor Configuration Feedback August 23 2026 – August 26 2026 —
3 Milestone 1 – Preliminary Results September 1 2026 (1), (2)
4 Milestone 2 – Test Report First Edition – End of Testing Period September 7 2026 (3)
5 Feedback and Dispute Resolution Time – Retests as Needed September 15 2026 (3)
6 Milestone 3 – Issue Final Report – End Date for Test September 20 2026 (5)

Communications:
All Participants will be notified if the schedule changes by two weeks or more.

Risks and Risk Management:
No additional risks are known at this time. Any material changes to Test design or risk profile that might affect fairness or balance will be disclosed to all Participants in a timely manner.

Section 07

Control Procedures

Connectivity Validation

All security solutions in the Test will be granted access to their cloud reputation, update, and other backend services, to match typical real-world deployment conditions for end users.

Logging

Instructions for enabling and exporting logging within each product must be provided by the Participant to Testing Ground Labs upon request. Logs may be used to investigate unexpected behaviors, disputed results, or technical issues during the Test.

Updates

Any configuration information needed for automatic or manual product updates during the Testing Period must be disclosed by the Participant. Testing Ground Labs will endeavor to ensure that all tested products are up to date prior to and during testing, in line with normal end-user expectations.

Section 08

Scoring Process

For each security solution, a Final Score will be calculated once the full Test has been performed, based on malware detection and false positive counts.

For each security solution, the Final Score is defined as:

Final Score = (Detection %) × 100 − 0.2 × FP

Based on the Final Score, a corresponding rating will be granted to each participating security solution, according to the table below.

Final Score Monthly Award
98.00 – 100.00 ★★★★★  5-star rating
95.00 – 97.99 ★★★★  4-star rating
90.00 – 94.99 ★★★  3-star rating

False positives (FP) are computed based on detections within the designated set of clean application installers. Each false positive reduces the Final Score by 0.2 points under the above formula.

Section 09

Dispute Process

The dispute process runs for eight business days commencing from the end of the Test (i.e., following Milestone 2: Test Report First Edition). Please refer to Section 6 (Schedule) for additional timing details.

The general Dispute Process operates as follows:

  1. Testing Ground Labs provides each vendor with detailed results only for their own security solution, including hash values associated with any missed malware samples and false positive detections.
  2. The vendor responds within eight business days to Testing Ground Labs, providing fact-based disagreements or evidence regarding any sub-optimal results, if applicable.
  3. Testing Ground Labs reviews each submission and responds with a decision indicating whether the dispute is accepted or denied. If accepted, appropriate corrections (including re-tests, where feasible) may be reflected in the final Test results and report.
Section 10

Attestations

I understand and agree that I am submitting this Test Plan, and the following Attestations, on behalf of the entity listed below, and I represent and warrant that I have authority to bind such entity to these Attestations. All references to “I” or “me” or similar language refer to such entity. I represent and warrant that the following Attestations are true, to the best of my knowledge and belief, and that each of the following commitments will be upheld to the best of my ability.

  1. I will provide public notification on the AMTSO website covering my obligation for notification of a Public Test, regardless of whether a potential Participant is in actual receipt of such notification prior to the Commencement Date of a Test. (Section 1, Section 4, Section 6)
  2. All products included in this Test will be analyzed fairly and equally. (Section 2, Section 3, Section 5)
  3. I will disclose any anticipated or known imbalance or inequity in the Test design to all Participants in the Test. (Section 2, Section 3)
  4. Although I may charge for participation in a Test, I will not charge any additional fees for a vendor to be a Test Subject under the Standards. (Section 4)
  5. I will disclose any material conflicts of interest or other information that could materially impact the reliability of the Test. (Section 4)
  6. I will disclose how the Test was funded. (Section 4)

I hereby affirm, to the best of my knowledge and belief, that this Test Plan complies with the AMTSO Testing Standards as of the date hereof.

Signature
Name
Jeffrey Wu
Test Lab
Testing Ground Labs
AMTSO Test ID
To Be Assigned