Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

Themida

Themida is a commercial software protector/packer used to obfuscate and protect executables, and in the provided reporting it is repeatedly referenced as a defense-evasion layer applied to malware. The content describes Themida-packed or Themida-protected payloads in multiple campaigns. In one Acronis-reported campaign distributing fake game cheats via GitHub and related lures, the downloaded payload background.exe was identified as a Themida-packed Vidar Stealer 2.0 sample. In Lazarus Group activity, including Operation Dream Job, malicious .db files were packed with Themida to evade detection. ESET also reported Lazarus using Themida-protected binaries in a South Korea-focused supply-chain-style campaign abusing the WIZVERA VeraPort software installation ecosystem; the signed initial downloader and another component were described as Themida-protected, with the version estimated at roughly 2.0 to 2.5. Across the cited reporting, Themida is associated with malware delivery and concealment rather than being the final payload itself, and is linked in the content to Lazarus operations and to Vidar Stealer 2.0 delivery. High-confidence behaviors directly mentioned are packing/protecting binaries to hinder analysis and evade detection. No standalone infection vector or IoCs specific to Themida itself are provided beyond its use as a protection layer on malicious files.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Lazarus

The signed initial downloaders are Themida-protected binaries... This component is a Themida-protected file. We estimate the version of Themida to be 2.0-2.5.

via eset welivesecurity blogwelivesecurity.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Stealth

7 techniques
T1027Obfuscated Files or InformationEvidence4

Modern software anti-analysis methods are based on more sophisticated packers/protectors, e.g. Themida, Armadillo or ASProtect which pack the program code and tamper with entry point addresses so it is hard to find the program's original entry point (OEP). That is also true for the program's import address table (IAT).

T1027.001Binary PaddingEvidence1

Appendix D lists "T1027.001 Obfuscated Files or Information: Binary Padding"; the report discusses use of VMProtect, Themida, and script/binary obfuscation.

T1027.002Software PackingEvidence7

Additionally, Sophos.exe (see below) which was packed with Themida, was executed.

T1027.006HTML SmugglingEvidence1

After virtualization, the code is transformed into a complex, obfuscated form that is hard to analyze. The devirtualizer restores the original logic, making the code readable again.

T1218.010Regsvr32Evidence1

Cobalt Strike (license ID "666", packed with Themida) launched via regsvr32.exe or rundll32.exe.

T1218.011Rundll32Evidence1

Cobalt Strike (license ID "666", packed with Themida) launched via regsvr32.exe or rundll32.exe.

T1622Debugger EvasionEvidence1

It fills the structure with strings and signatures matching popular virtualization platforms, sandbox environments, and debugging tools... ollydbg, idaq, ida64, windbg, x32dbg, x64dbg, ghidra, cheatengine, dnspy...

Discovery

1 technique
T1622Debugger EvasionEvidence1

It fills the structure with strings and signatures matching popular virtualization platforms, sandbox environments, and debugging tools... ollydbg, idaq, ida64, windbg, x32dbg, x64dbg, ghidra, cheatengine, dnspy...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.