Iran has unveiled its second domestically developed antivirus software, dubbed Ayyza, using artificial intelligence and machine learning to detect both known and previously unidentified cyber threats.
The antivirus was developed by an Iranian knowledge-based company and is designed to provide protection against a range of threats, including malware, viruses, Trojans, ransomware and advanced persistent threats (APTs).
Mohammad Shafieinia, the company’s director, said the development of Ayyza focused on combining several security technologies to improve the detection of complex and multi-stage attacks.
“We tried to use more up-to-date technologies and artificial intelligence to detect complex and multi-stage attacks, while creating a combined ecosystem of XDR, EDR and antivirus technologies,” he was quoted as saying by ISNA.
He said the objective was to increase the system’s detection rate and provide users with a higher level of protection against sophisticated threats.
According to Shafieinia, Ayyza’s detection engine has been developed entirely by the company and uses technologies operating at the Windows kernel level.
“The engine of this antivirus has been fully developed by us and uses Windows kernel-level technologies to provide higher detection accuracy, as well as greater speed and agility,” he said.
The company says the software has also been designed to minimize the use of hardware resources, particularly CPU and RAM, an issue Shafieinia described as increasingly important as the cost of computing resources rises.
🤖 Iran ranks among world’s top 14 nations in AI knowledge creation
— Iran First (@IranFirst_PTV) June 17, 2026
🔹 Iran has secured a place among the world’s leaders in artificial intelligence knowledge creation, according to Vice President for Science and Technology.https://t.co/M1pv1yLCrk#IranFirst pic.twitter.com/aaNnG7OKYj
“One of the important issues in both our country and the world is hardware resources,” he said. “Security software must reduce CPU and RAM usage and be optimized so that it does not slow down the systems users work with.”
Another feature highlighted by the developers is the antivirus’s ability to receive updates without a direct reliance on the internet.
Updates can be delivered offline or through Iran’s National Information Network, according to Shafieinia.
He also pointed to the product’s machine-learning capabilities as a means of identifying emerging threats.
“Our machine-learning system can detect different types of attacks, and its performance is not limited to attacks for which a specific signature already exists,” he said.
The system, he added, can identify previously unknown malware and potentially detect “zero-day” attacks—vulnerabilities or attack methods for which no prior record or signature exists.
However, he stressed that no single security product can address every cybersecurity threat.
He said the company has developed additional tools that work alongside the antivirus, including systems for privileged access management (PAM) and preventing data leakage.
“For detecting intelligent agents and attacks designed by artificial intelligence, we have another product that can identify these attacks and transfer its feedback to the antivirus,” he said.
Shafieinia also highlighted the need for greater integration between cybersecurity products used by organizations, noting that many systems currently operate in isolation.
“We need to move toward integration, coordination and, in technical terms, orchestration among the different security products used by organizations,” he said.
The company, which has around 15 years of experience in the cybersecurity sector, says its products are already deployed across numerous Iranian infrastructures, including banking, financial and governmental systems.
Its more established products, including a data-leak prevention system and PAM solution, have been in operation for more than a decade across more than 70 critical, sensitive, and important infrastructures in Iran.