They do not use zero day samples in this test.
But some financial malware as Zbot, Nymaim, Shiotob, Gozi, Neurevt and their variants, use multi-flow attacks fragmented on multiple streams of information, with the purpose of confusing the sandboxing tools that perform object's analysis individually. These items will be labeled as harmless, because they are just part of the game.
Otherwise the attack is perpetrated with a logic that integrates components injected on multiple vectors (web, mail, files) of the attack surfaces with the purpose of hiding the activities to security solutions.
By seeing the online banking test, they seem pretty optimistic.