AV TEST
  • Tests
    • Particuliers
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Entreprise
      • Windows Antivirus
      • MacOS Antivirus
      • Android Antivirus
    • Internet of Things
      • Smart Home
      • Caméras IP
      • Smart Watches & Fitness-Tracker
      • Autre
      • Tous les tests IoT
    • Produit de sécurité informatique
  • Nouvelles
    • Toutes les actualités
    • Awards
    • Antivirus pour Android
    • Antivirus pour MacOS
    • Antivirus pour Windows
    • Tests mandatés
    • Tests de réparation pour Windows
    • Recherche
    • Internet des objects (IoT)
    • Contrôle parental
    • Tests de VPN
    • Autres tests
    • Divers
  • Services
  • Resources
    • À propos de l'institut
      • Institut
      • Certification
      • Procédés de test
      • Emplois
    • Statistiques
      • AV-ATLAS.org
      • Logiciels malveillants
      • Spam
    • Media
      • Presse
      • Rapports de Test
      • Publications
    • Newsletter
    • FAQ
  • Contact
    • Contact
    • Conditions générales
    • Mentions légales
    • Confidentialité

©  2026 AV-TEST  | SITS Deutschland GmbH

AV TEST AV TEST
  • Tests
    • Particuliers
    • Entreprise
    • Internet of Things
    • Produit de sécurité informatique
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus
    • Windows Antivirus
    • MacOS Antivirus
    • Android Antivirus
    • Smart Home
    • Caméras IP
    • Smart Watches & Fitness-Tracker
    • Autre
    • Tous les tests IoT

    Contactez-nous

    Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous.

    Kontakt
  • Nouvelles
    • Toutes les actualités
    • Awards
    • Antivirus pour Android
    • Antivirus pour MacOS
    • Antivirus pour Windows
    • Tests mandatés
    • Tests de réparation pour Windows
    • Recherche
    • Internet des objects (IoT)
    • Contrôle parental
    • Tests de VPN
    • Autres tests
    • Divers
    Services

    Network Threat Protection -
    Testé et certifié par AV-TEST

    SAVOIR PLUS >

    Contactez-nous

    Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous.

    Contactez-nous
  • Services
  • Resources
    • À propos de l'institut
    • Statistiques
    • Media
    • Newsletter
    • FAQ
    • Institut
    • Certification
    • Procédés de test
    • Emplois
    • AV-ATLAS.org
    • Logiciels malveillants
    • Spam
    • Presse
    • Rapports de Test
    • Publications

    Abonnez-vous à
    la Newsletter AV-TEST

    savoir plus
  • Contact
    • Contact
    • Conditions générales
    • Mentions légales
    • Confidentialité
  • IOT-TESTS.ORG
  • AV-ATLAS.ORG

Dernières Actualités

28 septembre 2026

Cybersecurity Awareness Month 2026: The new threat – AI-powered malware

Cybercriminals use AI for their malware, but not necessarily in an attempt to make it smarter. They mainly use AI to automate the entire scope of the attack. But security package vendors are not asleep at the wheel, they are padding their detection systems with AI, too. Here’s an analysis of the current situation when it comes to the detection of AI-powered cyberattacks.

Artificial intelligence is changing the malware landscape, in particular by acting as an accelerant: It makes known attack methods faster, cheaper, more scalable and more accessible for criminals with less technical know-how. AI does not automatically mean that there is no more need for human to make decisions and it doesn’t necessary lead to the creation of entirely new categories of malware. Nevertheless, the AV-TEST experts have been noticing an uptick in the number of malware samples and attack tactics powered by AI. 

According to Erik Heyland, Head of Testing Labs at AV-TEST, “studies across the globe indicate that there are traces of AI-driven polymorphism in nearly 75 percent of newly discovered malware today. It’s something we’re seeing in our testing and also on AV-ATLAS, our threat intelligence platform, which records and publishes data on the actual threats out there in real time. This means that there will be nearly 100 million new malware samples added this year, and we’re only talking about Windows here. As of September 2026, there were already more than 1 billion Windows samples in our detection databases!”

AI-powered cyberattacks are on the rise

The entire industry as well as many vendors of security products are continually researching the field of AI-powered malware and agentic AI attacks. Some of their findings include:

  • In 2025, CrowdStrike observed that the number of agentic AI attacks had increased by 89 percent.
  • The role of AI is transforming from helper to that of active operator: Check Point reports that AI is undergoing a transformation from an assisting digital planner into an active operator of live cyberattacks in 2026.
  • It is becoming easier to develop malware. Anthropic released a report analyzing 832 accounts that were banned due to malicious activity. 67.3 percent leveraged AI to write the malicious code or prepare the cyberattacks.

The incidence of exploits is accelerating

Published in 2026 by the UK Department of Science, Innovation and Technology, the International AI Safety Report found that AI is accelerating the search for vulnerabilities and the creation of exploit codes. The scientific review was overseen by a panel of more than 100 AI experts from more than 30 countries. It represents the largest international collaboration on AI safety research to date. For example, the experts reported on a competition in which an AI agent identified 77 percent of the vulnerabilities present in real software and for which it wrote the malicious code. Many cybercrime syndicates and state-sponsored groups actively use AI for their operations, which was also indicated in the international report.

However, AI can be utilized for more than just attacks, it can also be put to work in defending systems. For this reason, many vendors of security products rely on AI systems to improve detection of malware and cyberattacks and AI-generated phishing. As proof that it can work, the regular detection tests in the AV-TEST labs show how the different security packages and solutions for Windows, Mac and Android stand up to the latest malware samples.

Security solutions keeping AI-generated malware samples at bay

Security vendors are implementing internal security modules, which are supported or even powered by AI, in their solutions to complement the standard detection systems. But are these security products really able to fend off the latest threats? The live tests and 10 real-world attacks for each product, including the latest attack scenarios, demonstrate the capabilities of these products. The experts analyze how each phase of an attack of a recent malware sample progresses under Windows in these Advanced Threat Protection tests – or ATP tests, for short. If a security product or endpoint solution fails to detect an attack in the first phase, the internal analytic and security modules need to be triggered. The tests show that the vendors’ products are generally highly capable of fending off the attackers.

Looking toward the future

The recent increase in cyberattacks cannot always be directly attributed to the use of AI. However, the speed and scale at which these attacks occur indicate a connection to AI. In addition, less technically inclined actors are increasingly receiving access to a set of professional tools, through which they can further increase the number of autonomous cyberattacks.

Even if ChatGPT, Anthropic and Gemini make it difficult to write malware using their respective AI system, or if they ban it entirely, there are still countless offers on the dark web that explicitly allow this and some that even provide access to entire libraries of code.

“It’s a neck-and-neck race between cyberattackers and security vendors at times and AI will add a new dynamic in the pace of this development,” explains Erik Heyland, Head of Testing Labs at AV-TEST.

An expert’s opinion: Berlin City Government attacked by the Rhysida hacker group

Erik Heyland
Erik Heyland
Head of Testing Labs and Test Research at AV-TEST

The latest cyberattack targeting the computer systems of the Berlin City Government and press releases on BILD.de give reason to provide a brief of the Rhysida ransomware group.

The group has been operating since 2023 and is one of the most active groups of professional ransomware attacks. The latest incident once again shows that cyberattacks targeting local authorities and critical infrastructure are no longer the exception to the rule. These attacks are highly organized using stolen login credentials, rapidly dispersing across a network and leveraging a double extortion strategy, which involves data theft, encryption and extortion.

So this means that the decisive question is not whether an organization will be attacked, but rather how well it is prepared for attacks. AV-TEST, an independent testing institute, has played a key role in finding an answer to this question for more than 20 years. We help vendors, enterprises and public authorities by providing objective analyses of the efficacy of their security solutions and improving them through sound scientific evaluations, independent certifications and real-world advice.

In particular, our Advanced Threat Protection (ATP) tests show how reliable security solutions are in detecting and blocking the latest attack scenarios under real-world conditions. They provide a substantial foundation for enterprises and public authorities in making security-related decisions.

What’s more, AV-TEST publishes the results of its regular reviews of security products for free so corporate and consumer users can receive pertinent information. We place a focus on the independence and transparency in this process as it acts as a pivotal requirement for sound decision-making on investments and security applications.

Cyberresilience does not emerge from a promise made by the marketing department, but rather from verifiable protection.

You can find the entire article on BILD.de here. (only available in German language)

Résultats
actuels

  • Windows
  • MacOS
  • Android
  • Archives

  • Windows
  • MacOS
  • Android
  • Archives

  • Smart Home
  • Caméras IP
  • Smart Watches
  • Autre
Services

Network Threat Protection - Testé et certifié par AV-TEST

En savoir plus
Services

Threat Intelligence Platform par AV-TEST

Démarrer AV-ATLAS.org
Services

AV-TEST et la loi sur la cyber-résilience

En savoir plus

Abonnez-vous à la newsletter AV-TEST

Inscrivez-vous maintenant
Abonnez-vous à la newsletter AV-TEST
Inscrivez-vous maintenant
AV TEST

Contactez-nous

Pour toute demande adressée à l'institut AV-TEST, veuillez utiliser le formulaire de contact ci-dessous

Vers le formulaire de contact

Plan du site

  • Institut
  • Tests
  • Nouvelles
  • Certification
  • Publications
  • Contact

Contact

  • SITS Deutschland GmbH
    succursale de Magdebourg
  • Klewitzstraße 7
  • 39112 Magdeburg, Germany
  • E-Mail: info@av-test.com
  • Telefon: +49 391 6075460
  • Fax: +49 391 6075469

Conditions générales | Protection des données | Mentions légales

©  2026 AV-TEST  | SITS Deutschland GmbH