Latest News
September 24, 2026 | Text: Markus Selinger | Antivirus for Windows
The tricks that attackers use – here’s how the security solutions deal with harmful malware
Cyberattackers are always planning devious attacks to target Windows systems. And it is not always a boilerplate attack that is easily detected. Often, it is a combination of various attack methods that attempt to circumvent the security systems under Windows or even neutralize them. And that’s when an infostealer or ransomware does the dirty work. The Advanced Threat Protection test, or ATP test, utilizes 10 scenarios to determine how well the security solutions can detect and defend against these covert and concealed attacks. If the solutions do not live up to their promise, the attackers can steal the data or even encrypt the systems. 21 security packages for consumer and corporate users put their skills to the test.
21 protection packages and solutions under Windows 11 in the ATP test
Here’s how well the security packages for consumer and corporate users fared in defending against the ransomware and infostealer attacks in 10 different attack scenarios
Media outlets often report on large corporations or federal agencies that have been hit hard by infostealers or ransomware and suffered tremendous damage: companies such as Shell, Philips and General Electric, whose data was presumably stolen, or McKesson, whose data was encrypted and that received a ransom demand for 55 million US dollars.
Unfortunately, there are also many normal people who have been adversely affected, but they do not make the headlines when their systems are encrypted. Yet, they still suffer losses, such as encrypted data and photos, of considerable personal value.
21 protection products in the ATP test
21 security products for consumer users and corporate users prove their mettle under Windows 11 in 10 real-world attack scenarios in the latest Advanced Threat Protection (ATP) test.
Included in the test for consumer users were 10 security products from Avast, AVG, Avira, Bitdefender, ESET, K7 Computing, Kaspersky, McAfee, Norton and Surfshark. In the test lineup were also 11 endpoint solutions for corporate users from Acronis, Avast, Kaspersky (with two versions), Microworld, Net Protector, Norton, Qualys, Symantec, Trellix and WithSecure.
A product can earn up to 35 points in the ATP test: 20 points for defending against 5 infostealers and 15 points for the 5 scenarios with ransomware. In each scenario, a security solution can earn a total of 3 or 4 points; however, deductions (sometimes just half a point) are made for any errors. The tables indicate the overall score for each product. The graphics at the end of the article show the results of each attack scenario in each stage of testing.
The testers apply the same techniques that cybercriminals also employ in their exploits. This test includes two highly specialized attack tactics, briefly explained:
DLL sideloading: Using this attack technique, a legitimate executable file loads a file with a DLL extension, in the guise of a trusted process, from an unexpected directory. The attackers had previously replaced the file with a malicious version. In Windows, many applications first search for specific DDL files in their working directory before reverting to system paths.
Our examples used “vulkaninfo.exe”, a legitimate, digitally signed executable file from a third-party vendor, as a trusted host, into which a manipulated file with a DLL extension had been injected into its directory. When “vulkaninfo.exe” searches for the corresponding library and loads it, the infected test DLL file will be executed as a trusted application.
Scheduled tasks: Attackers can exploit the Windows Task Scheduler to trigger a task to run malicious code in a user’s account or on a system account one time or routinely.
We created a scheduled task in our example that launches PowerShell as the execution mechanism. PowerShell is then used to load the harmful DLL which can then be executed as part of the scheduled task.
The 10 test scenarios
All attack scenarios are documented according to the standard of the MITRE ATT&CK database. The individual sub-techniques are listed in the MITRE database for “Techniques”, for example, “T1566.001” under “Phishing: Spearphishing Attachment”. Each test step is thus defined among the experts and can be logically understood. In addition, all attack techniques are explained, along with how and why the malware infection occurs and impacts systems.
ATP test:10 security packages for consumer users
10 security packages for consumer users demonstrated their ability to fend off attacks using cutting-edge technology under Windows 11 in the May/June 2026 ATP test. The vendors’ researchers and developers for the majority of products in the latest round of testing deserve a lot of praise for their successes. 9 of the 10 products tested performed well when protecting the systems in the 10 scenarios. For this excellent achievement, they all earned the full 35 points for their protection score in the table.
The only product that unexpectedly encountered issues in this ATP test was Bitdefender. The Total Security package detected the attackers in all 10 scenarios; however, it ran into problems with 3 ransomware samples. The product detected the ransomware, yet it only partly prevented it from executing. Likewise, the internal security modules were not totally effective either. In the end, encryption occurred in individual files in all three cases. This cost it valuable points. For this reason, the lab only awarded the product with 1.5 out of 3 points in two scenarios and 1 point for one scenario. This left Bitdefender with only 30 out of 35 possible points when it came to the protection score.
Given that each product tested achieved the required 75 percent (at least 26.5 points) out of 35 points for the protection score in the test and regularly participates in the Windows tests they all received the “Advanced Certified” certificate from AV-TEST.
ATP test:11 endpoint solutions for corporate users
In our testing, the 11 security solutions for corporate users under Windows 11 also showed a strong performance in the May/June 2026 ATP test. 10 of the 11 endpoint products detected and disabled the infostealers and ransomware in all 10 scenarios of the test, thereby demonstrating that they provide reliable protection for corporate users. For this they received the maximum 35 points for their protection score in the table. The 10 products are from the following vendors: Acronis, Avast, Kaspersky (both versions), Microworld, Net Protector, Norton, Qualys, Symantec and WithSecure.
Trellix was the only product that encountered problems in the latest test. It performed superbly in the 5 scenarios with ransomware; however, it ran into problems detecting the infostealers. The attackers were not detected in two cases, and what’s worse, the internal security modules failed to stop them, too. They spread throughout the system, plundering all of the data from the system in the end. It meant that Trellix lost a total of 8 points for these two scenarios. All in all, Trellix only earned 27 out of 35 points in the protection score on the table.
All of the endpoint solutions tested fulfilled the requirements for certification as “Advanced Approved Endpoint Protection”. For this, they need to achieve the required 75 percent (at least 26.5 points) out of 35 points for the protection score in the test and regularly participate in the bimonthly Windows tests.
Many products in the ATP test offer a high level of security
Most of the security packages and solutions were not tricked by the attackers when they used covert or concealed files or other attack tactics. 19 of the 21 products tested for consumer and corporate users completed the May/June 2026 ATP test under Windows 11 without making a single error, which earned them the maximum protection score of 35 points. This shows that the products are equipped to perform their job very well and provide strong protection for personal or business data, even in challenging situations.

































