AVLab Cybersecurity Foundation Advanced In-the-Wild Malware 2026 Test Series

Test Lab

AVLab Cybersecurity Foundation

Test Title

AVLab Cybersecurity Foundation Advanced In-the-Wild Malware 2026 Test Series

AMTSO Test ID

AMTSO-LS1-TP178

Platform

Windows

Vendor

AVAST, Bitdefender, Elastic, Emsisoft, ESET, F-Secure, MalwareBytes, Microsoft, MKS_vir, Norton, Threatdown, Trend Micro, Trinetra, Watchguard, Webroot

Publication date

2026-02-25

Statement from Test Lab

The name perfectly captures the nature of the tests. The samples used in the study come from real attacks on honeypots, i.e. traps that pretend to be systems or protocols and intercept malware.

Tested products

VendorProductVendor status
ElasticDefendincluded
EmsisoftEnterprise Security + EDRincluded
MKS_virEndpoint Security + EDRincluded
ThreatdownEndpoint Protection + EDRincluded
TrinetraEndpoint Protection (C-DOT)included
WatchguardEndpoint Securityincluded
AVASTFree Antivirusparticipant
BitdefenderTotal Securityincluded
ESETSmart Securityincluded
F-SecureTotalincluded
MalwareBytesPremiumincluded
MicrosoftDefenderincluded
NortonAntivirus Plusincluded
Trend MicroInternet Securityincluded
WebrootAntivirus included

AMTSO Standard compliance info

Notification issued

2026-01-05

Notification method

Publicly posted test plan, Contact list notification

Test plan

Additional links

Commencement date

2026-01-15

Participants

1
These Vendors chose to adopt Participant status under the AMTSO Standard, gaining certain guaranteed rights in return for attestations.

“Included” Vendors

14

These Vendors did not chose to adopt Participant status under the AMTSO Standard, but may have engaged with the test lab in other ways.

Commentary dates

CommentaryStart dateEnd date
Phase 1 Commentary2026-01-052026-02-19
Phase 2 Commentary2026-02-192026-02-26

AMTSO Standard compliance status

Confirmed Compliant with AMTSO Standard v1.3 (Round 1 January)Compliance report