Last seven days
- First activity
- Jul 26, 2026
- Last activity
- Jul 26, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Themida is a commercial software protector/packer used to obfuscate and protect executables, and in the provided reporting it is repeatedly referenced as a defense-evasion layer applied to malware.
Profile source: Mallory opens in a new tabThemida
Themida is a commercial software protector/packer used to obfuscate and protect executables, and in the provided reporting it is repeatedly referenced as a defense-evasion layer applied to malware. The content describes Themida-packed or Themida-protected payloads in multiple campaigns. In one Acronis-reported campaign distributing fake game cheats via GitHub and related lures, the downloaded payload background.exe was identified as a Themida-packed Vidar Stealer 2.0 sample. In Lazarus Group activity, including Operation Dream Job, malicious .db files were packed with Themida to evade detection. ESET also reported Lazarus using Themida-protected binaries in a South Korea-focused supply-chain-style campaign abusing the WIZVERA VeraPort software installation ecosystem; the signed initial downloader and another component were described as Themida-protected, with the version estimated at roughly 2.0 to 2.5. Across the cited reporting, Themida is associated with malware delivery and concealment rather than being the final payload itself, and is linked in the content to Lazarus operations and to Vidar Stealer 2.0 delivery. High-confidence behaviors directly mentioned are packing/protecting binaries to hinder analysis and evade detection. No standalone infection vector or IoCs specific to Themida itself are provided beyond its use as a protection layer on malicious files.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
The signed initial downloaders are Themida-protected binaries... This component is a Themida-protected file. We estimate the version of Themida to be 2.0-2.5.
MITRE ATT&CK
Reporting
During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.
The signed initial downloaders are Themida-protected binaries... This component is a Themida-protected file. We estimate the version of Themida to be 2.0-2.5.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.