Antivirus redefined: How NordVPN’s next-gen antivirus works

The way people experience online threats has changed over time, and so have their expectations of antivirus software. A recent NordVPN survey found that 73% of Americans believe antivirus software protects against threats such as identity theft, phishing, scams, data breaches, and online tracking.¹ In fact, CrowdStrike reports that malware-free attacks have grown from 40% of detections in 2019 to 82% in 2025.² Together, these trends are reshaping the antivirus category. This article explores what we mean by “next-generation antivirus,” how it differs from traditional antivirus, and how NordVPN approaches online protection.

August 3, 2026

8 min read

NordVPN's next-gen antivirus

Why did the antivirus category need a new approach?

Traditional antivirus software was built around a relatively simple model. A malicious file reaches the device, the antivirus compares it against a database of known malware signatures, and if there’s a match, the file is blocked or removed.

That model still plays an important role. Malware remains a significant threat, and downloaded files continue to require inspection and control.

The problem is that many of today’s most damaging attacks never involve a malicious file at all. Instead, attackers often rely on:

  • Phishing websites that steal credentials.
  • Fake online stores that collect payment information.
  • SMS and messaging scams.
  • Caller ID spoofing and AI-generated voice scams.
  • Session hijacking.
  • Credential stuffing.
  • Identity theft.
  • Social engineering.²

Consumers are also adapting to this shift. According to a new NordVPN survey of 1,200 US adults, antivirus software is still the most popular cybersecurity tool, with 52% of Americans reporting they use it — more than password managers (41%), firewalls (36%), VPNs (31%), or identity theft protection (25%). Yet many also expect antivirus software to do more than detect malware. For example, 34% believe it blocks phishing attacks, 30% think it protects against identity theft, and 27% expect it to secure their data on public Wi-Fi.*

NordVPN’s scam experience research found that one in three respondents (33%) had fallen victim to an online scam. Among those victims, 49% lost money — and of those, 20% lost more than $100. Despite the financial impact, fewer than half (46%) reported the incident to the authorities.

These findings show that people no longer see antivirus software as software that simply removes viruses. They expect it to help protect them from the threats they’re most likely to encounter online.

*The survey referenced in this section was conducted by NordVPN between January 15 and 19, 2026, among 1,200 US internet users aged 18–65. Participants were recruited through the Cint research panel using quotas for age, gender, and place of residence to create a nationally representative sample. This research is unpublished. Throughout this article, it is cited as the NordVPN US cybersecurity expectations survey (January 2026).³

How does NordVPN redefine the antivirus category?

People don’t think about online threats in terms of malware, phishing, or scams. They simply want one product that helps protect them online. NordVPN’s research reflects that shift — users already expect antivirus software to protect them from much more than malicious files.³ 

NordVPN defines a next-generation antivirus (NGAV) around those expectations. A next-gen antivirus combines artificial intelligence (AI), threat intelligence, URL reputation analysis, malware scanning, and dedicated phishing and scam protection to help detect a wide range of online threats.

Working together, these technologies help identify phishing attempts, scam websites, malicious downloads, and other online threats that people are likely to encounter every day. They’re all built into the NordVPN app, bringing multiple layers of protection together in one place.

It’s what NordVPN means by next-generation antivirus — protection designed around the way people experience online threats today.

Next-gen vs. traditional antivirus

A traditional antivirus and a next-generation antivirus take different approaches to identifying online threats. While both are designed to improve users’ security, they rely on different technologies and focus on different types of threats.

Traditional antivirus

Next-generation antivirus

Detects using known malware signatures

Uses AI-powered detection, URL reputation analysis, malware scanning, and threat intelligence

Protects against malicious files

Protects against malware, phishing, scams, and malware-free attacks

Relies on malware database updates

Continuously adapts using live threat intelligence

Detects threats after a malicious file appears

Helps identify threats before, during, and after an attack

Protects the device

Helps protect the device, online accounts, and digital identity

Whether it’s a traditional antivirus or a next-generation antivirus, the goal is the same — helping people stay safer online.

Online security isn’t one size fits all. The next-generation antivirus reflects NordVPN’s approach to helping people stay safer online.

How does NordVPN’s next-gen antivirus work?

NordVPN’s next-generation antivirus uses multiple detection technologies that help identify threats at different stages of an attack:

Each layer addresses a different type of threat, helping stop attacks before credentials are stolen, malware executes, or an account is compromised. If you’d like a deeper technical explanation of the underlying architecture, read our next-generation antivirus whitepaper.

Real-time URL and domain reputation analysis

Many attacks start with a website rather than a downloaded file. Phishing pages, fake online stores, and other fraudulent websites are designed to steal credentials, payment information, or personal data before malware ever reaches a device.

Around 3.4 billion phishing emails are sent every day. In 2025, the Anti-Phishing Working Group (APWG) recorded 3.8 million phishing attacks. Given the scale of phishing attacks, identifying malicious websites before users visit them is critical.

NordVPN’s next-generation antivirus checks the reputation of URLs and domains in real time to help identify phishing websites, scam pages, and other malicious destinations before users interact with them.

File scanning

Malware remains an important cyber threat, which is why file scanning continues to be an important part of NordVPN’s next-generation antivirus.

Downloaded files are scanned before they execute and compared against known malware indicators to help identify threats early. NordVPN also continues to expand its malware protection capabilities, including expanded system scanning, while treating file protection as one layer of a broader security approach.

Threat-intelligence feeds

Cybercriminals are constantly developing new attack techniques. New phishing domains, malicious websites, and malware campaigns appear continuously. NordVPN combines its own detection capabilities with continuously updated threat intelligence to identify new threats and stop attacks sooner.

Artificial intelligence

Instead of relying on one large AI model, NordVPN uses multiple smaller machine learning models trained for specific security tasks. Individual models evaluate phishing websites, scam stores, malware-related indicators, and other threat patterns independently, allowing each model to be updated independently as attackers develop new techniques. 

Depending on the protection layer, analysis may happen directly on the device, within the browser extension, or in NordVPN’s backend systems. When cloud processing is required, only the information needed to identify a potential threat is processed, helping balance effective detection with user privacy.

Does NordVPN’s next-gen antivirus actually stop threats?

The best way to evaluate any cybersecurity product is to look at how it performs in independent tests and against real-world threats.

Independent testing shows that NordVPN’s next-generation antivirus performs well against real-world phishing threats. In AV-Comparatives’ anti-phishing certification test, it detected 96% of phishing websites with zero false positives, outperforming all other tested products. NordVPN’s scam, phishing, and malware protection also ranked among the top-rated solutions for malicious link blocking in an assessment by AV-TEST.**

NordVPN’s next-generation antivirus product telemetry shows the volume of threats users encounter every day. On average, it blocks:

  • Almost 150,000 threats every day.
  • Around 100,000 malware threats.
  • Approximately 40,000 phishing attempts.
  • Roughly 10,000 scams.

In April alone, NordVPN’s scam, phishing, and malware protection blocked 4.8 million threats, including more than 3 million malware-hosting domains and 1.8 million phishing and scam domains.***

**Please note that all certificates mentioned in this article were awarded to a NordVPN feature formerly known as Threat Protection Pro™. Threat Protection Pro™ is now referred to as scam, phishing, and malware protection in the NordVPN app. Its capabilities and functionality have not been affected.

***The performance data referenced in this section is based on unpublished NordVPN product telemetry and internal testing collected in April 2026. It reflects threat events blocked by NordVPN’s protection technologies across categories, including malware, phishing, scams, malicious websites, and other harmful or suspicious content. Throughout this article, this data is cited as the NordVPN next-generation antivirus product telemetry (April 2026).

Built to protect your privacy

NordVPN has designed its next-generation antivirus with privacy in mind. Whenever possible, threat analysis happens on the device. If cloud processing is needed, only the data required to assess a potential threat is sent, and any link to the user is removed beforehand.

The next-gen antivirus also limits the information it processes by checking files using hashes whenever possible, stripping personal details from URLs before cloud lookups, and hashing authentication cookies before analysis. Its architecture doesn’t rely on user identifiers, helping protect privacy by design.

To improve the experience, NordVPN collects only limited, non-sensitive product metrics with user consent, such as feature usage, blocked threat volumes, and satisfaction feedback. This data helps improve protection without profiling individual users.

Online security starts with a click.

Stay safe with the world’s leading VPN

References

¹ Šlekytė, Irma. Security tools & information leaks survey. Available from: https://nordvpn.com/blog/security-tools-and-information-leaks-survey/ 

² CrowdStrike. 2025 Global Threat Report. Available from: https://www.crowdstrike.com/global-threat-report/ opens in a new tab 

³ NordVPN. NordVPN US cybersecurity expectations survey (January 2026). Unpublished research.

⁴ Šlekytė, Irma. Scam experience research. Available from: https://nordvpn.com/blog/scam-experience-research/ 

⁵ Virbickas, Domininkas. Next-gen antivirus whitepaper. Available from: https://nordvpn.com/blog/nordvpn-next-gen-antivirus-whitepaper/ 

⁶ Valimail. More than 3 billion fake emails are sent worldwide every day, a Valimail report finds. Available from: https://www.valimail.com/newsroom/more-than-3-billion-fake-emails-are-sent-worldwide-every-day-valimail-report-finds/ opens in a new tab 

⁷ Anti-Phishing Working Group (APWG). Phishing Activity Trends Report: Fourth Quarter 2025. Available from: https://docs.apwg.org/reports/apwg_trends_report_q4_2025.pdf opens in a new tab

⁸ NordVPN. Next-generation antivirus product telemetry (April 2026). Unpublished product telemetry.

Cybersecurity expert Domininkas Virbickas

Domininkas Virbickas

Cybersecurity expert, Product director at NordVPN