Independent assessment of 9 consumer security solutions against 1,344 real-world Android malware samples.
Android, Google's mobile operating system built on a modified Linux kernel, remains the world's dominant computing platform — spanning phones, tablets, Android TV, and Android Auto.
Android holds roughly 72% of the global mobile OS market and powers close to 3.9 billion active devices, with penetration above 85% in large emerging markets such as India, Brazil, Indonesia, and Turkey. That scale, combined with device fragmentation and open sideloading, keeps the platform the single most attractive target for mobile-focused cybercrime.
Kaspersky's telemetry for Q1 2026 shows the shift clearly: banking trojans alone made up 52.96% of all detected malicious Android packages, out of more than 306,000 malicious installers identified in the quarter — continuing the roughly 50% quarter-on-quarter growth seen at the end of 2025. Attackers are moving past opportunistic malware toward organized, multi-stage fraud pipelines built to exploit user trust at scale.
Banking trojans remain the single largest category of Android threats. Dr.Web's Q2 2026 telemetry still ranks Android.Banker as the most widespread family despite a quarter-on-quarter dip, accounting for close to a quarter of all malware detections, while Zimperium's 2026 Banking Heist Report puts the year-over-year rise in malware-driven fraudulent transactions at 67%. Modern variants combine overlay screens that mimic legitimate banking apps with app-virtualization and Accessibility Service abuse to capture credentials and one-time passcodes undetected.
NFC-based fraud has moved from a niche technique to a fast-growing mainstream threat, with relay attacks on smartphones reported to have surged 188% in 2026. Malware built on frameworks such as NFCGate now supports both "direct" schemes, where victims are tricked into tapping a card to an infected phone, and the newer "reverse" scheme, where the infected device is set as the victim's own payment method and used to cash out through ATMs. Trojans like RatOn pair this NFC relay capability with full remote-access and automated-transfer functions, making the fraud difficult to distinguish from a legitimate transaction.
SMS-based phishing is now a leading initial-access vector on mobile, accounting for roughly 35% of all phishing activity and contributing, together with vishing, to close to a fifth of all breaches. Messages disguised as delivery notifications, tax refunds, or bank alerts continue to be the most effective lure, driving installs of spyware and banking trojans that bypass the scrutiny users apply to email.
Spyware remains a persistent, high-impact threat category, with detections continuing to climb through 2025 and into 2026. Once installed, these tools quietly exfiltrate contact lists, photos, private messages, and location data, monetizing it through blackmail, identity theft, or resale on darknet markets.
AI-assisted malware generation is now an established part of the threat landscape, helping attackers produce variants that slip past signature-based detection. Abuse of Android's Accessibility Services remains a favored escalation path: once granted, it lets malware automate fraudulent transactions, harvest credentials across other apps, and disable security software outright. Google reports that Play Protect flagged 27 million malicious sideloaded apps in 2025, more than double the prior year, underscoring how much of the threat still arrives outside the official store.
Device fragmentation compounds all of the above: a substantial share of the active Android install base still runs versions that no longer receive security patches, and counterfeit or pre-loaded devices remain a persistent supply-chain risk in some markets. Against this backdrop, continuous, independent evaluation of consumer security solutions is essential — which is the purpose of this test.
This section outlines the methodology behind the June 2026 test, designed to keep results objective and reproducible.
| Vendor | Software | Version |
|---|---|---|
| AhnLab | AhnLab V3 Mobile Security | 3.14.0.2(Build 4313) |
| Avast | Avast Mobile Security | 26.11.1.260616601 |
| Avira | Avira Antivirus Security for Android | 7.32.0 build No. 260611311 |
| Dr.Web | Dr.Web Security Space for Android | 12.9.11(2) |
| ESET | ESET Mobile Security | v. 11.2.7.0-15 |
| Kaspersky | Kaspersky for Android | 11.132.4.15652 |
| McAfee | McAfee Mobile Security | 10.6.1.8 |
| NortonLifeLock | Norton 360 (Norton Mobile Security) | 26.10.1.260610581 |
| Total Defense | Total Defense Mobile Security | 16.4.3 |
| Vendor | Total | Missed | Detected | Detection Rate | False Positives | Final Score |
|---|---|---|---|---|---|---|
| Avast | 1344 | 0 | 1344 | 100.00% | 0 | 100.00 |
| Avira | 1344 | 0 | 1344 | 100.00% | 0 | 100.00 |
| Kaspersky | 1344 | 0 | 1344 | 100.00% | 0 | 100.00 |
| NortonLifeLock | 1344 | 0 | 1344 | 100.00% | 0 | 100.00 |
| ESET | 1344 | 1 | 1343 | 99.93% | 0 | 99.93 |
| Total Defense | 1344 | 1 | 1343 | 99.93% | 0 | 99.93 |
| McAfee | 1344 | 2 | 1342 | 99.85% | 0 | 99.85 |
| AhnLab | 1344 | 7 | 1337 | 99.48% | 0 | 99.48 |
| Dr.Web | 1344 | 31 | 1313 | 97.69% | 0 | 97.69 |
For each security solution, a Final Score is calculated once the full test is performed:
Final Score = (Detection %) × 100 − 0.2 × FP
| Final Score | Monthly Award |
|---|---|
| 98.00 – 100.00 | ★★★★★ 5-star rating |
| 95.00 – 97.99 | ★★★★ 4-star rating |
| 90.00 – 94.99 | ★★★ 3-star rating |
Of the 9 tested products in the June 2026 Android Malware Detection Test from Testing Ground Labs, 8 achieved 5-star ratings and 1 achieved a 4-star rating across 1,344 malware samples. No product recorded any false positives among the 500 clean applications. Avast, Avira, Kaspersky, and NortonLifeLock achieved a perfect score of 100.00.
Gold highlight = 5-star rating (Final Score 98.00 – 100.00). Avast, Avira, Kaspersky, and NortonLifeLock achieved a Perfect Score (100.00) with zero false positives. Dr.Web achieved a 4-star rating (95.00 – 97.99) this cycle.
This test was conducted in accordance with the AMTSO Testing Protocol Standard v.1.3 (https://www.amtso.org/standards/). AMTSO compliance confirmation for this cycle is in progress; once complete, this report will be updated with the confirmed "Compliant" badge and the Certified Consumer marketing badge.
Unless otherwise stated, Testing Ground Labs (hereinafter referred to as "TG Labs"), owns the copyright of this report. Without prior written consent of TG Labs, no other organization or individual shall have the right to alter the contents of this report and use it for commercial purposes by any means (including but not limited to transmission, dissemination, reproduction, excerpt, etc.).
Unless otherwise stated, TG Labs shall be the rightful owner of the trademarks and service marks used in the report. Any action of infringing upon the legal rights of TG Labs is prohibited. TG Labs shall have the right to pursue the legal liability of the infringer in accordance with the law.
Before using this report issued by Testing Ground Labs (hereinafter "TG Labs"), please read and understand the following terms and conditions (the "Disclaimer") carefully, including provisions that limit or exclude TG Labs' liability and that restrict the rights of users. Use of this report constitutes acceptance of, and agreement to, all terms and conditions set forth herein.
TG Labs reserves the right to interpret, amend, and update this Disclaimer at any time.