Skip to content

Themida

Themida is a commercial software protector/packer used to obfuscate and protect executables, and in the provided reporting it is repeatedly referenced as a defense-evasion layer applied to malware.

Profile source: Mallory opens in a new tab

Themida

Family profile

Themida is a commercial software protector/packer used to obfuscate and protect executables, and in the provided reporting it is repeatedly referenced as a defense-evasion layer applied to malware. The content describes Themida-packed or Themida-protected payloads in multiple campaigns. In one Acronis-reported campaign distributing fake game cheats via GitHub and related lures, the downloaded payload background.exe was identified as a Themida-packed Vidar Stealer 2.0 sample. In Lazarus Group activity, including Operation Dream Job, malicious .db files were packed with Themida to evade detection. ESET also reported Lazarus using Themida-protected binaries in a South Korea-focused supply-chain-style campaign abusing the WIZVERA VeraPort software installation ecosystem; the signed initial downloader and another component were described as Themida-protected, with the version estimated at roughly 2.0 to 2.5. Across the cited reporting, Themida is associated with malware delivery and concealment rather than being the final payload itself, and is linked in the content to Lazarus operations and to Vidar Stealer 2.0 delivery. High-confidence behaviors directly mentioned are packing/protecting binaries to hinder analysis and evade detection. No standalone infection vector or IoCs specific to Themida itself are provided beyond its use as a protection layer on malicious files.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 26, 2026
Last activity
Jul 26, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • CH1

Leading providers

  • WorkTitans B.V.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Lazarus

The signed initial downloaders are Themida-protected binaries... This component is a Themida-protected file. We estimate the version of Themida to be 2.0-2.5.

MITRE ATT&CK

Themida in ATT&CK

7 distinct techniques

Reporting

Research mentioning Themida

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.