Themida is a tool tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.
Themida is a tool tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed June 18, 2026; most recent activity June 19, 2026.
The Gentlemen ransomware-as-a-service (RaaS) gang has developed a sophisticated suite of endpoint detection and response (EDR) killers, including a tool called GentleKiller, which has at least eight variants. These…
Themida is a tool tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.
The most recent intelligence report mentioning Themida on ThreatCluster is dated June 19, 2026. Activity was first observed June 18, 2026, giving a tracked span from then to June 19, 2026.
Across ThreatCluster reporting, Themida most frequently co-occurs with Malware, Ransomware, FortiBleed, Complexul Energetic Oltenia, Oltenia, among 12 tracked related entities.
The most significant recent cluster is “Gentlemen Ransomware Uses Advanced EDR Killers to Evade Detection” (23 articles · Updated June 18, 2026). Themida appears across 1 threat cluster in total, listed above with sources.
Themida appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.