Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 23, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 16 hostnames
LenAI is a cybercrime actor associated with the development, advertising, and sale of malware-as-a-service tooling on underground forums and Telegram.
Profile source: Mallory opens in a new tabLenAI
LenAI is a cybercrime actor associated with the development, advertising, and sale of malware-as-a-service tooling on underground forums and Telegram. The actor is most closely linked to ErrTraffic, a malicious traffic-distribution and ClickFix delivery framework sold to affiliates since at least late 2025, and has also been tied to Aeternum C2, a blockchain-based botnet loader. LenAIโs activity is financially motivated and centered on enabling downstream malware delivery rather than a single exclusive payload family.
ErrTraffic is designed for injection into compromised WordPress sites, where it presents social-engineering lures such as fake verification prompts and deceptive browser or system dialogs to induce victims to execute malicious PowerShell commands. The framework supports geofiltering, referrer filtering, operating-system detection, statistics, and WordPress plugin-based deployment, and has been marketed for Windows, Linux, and macOS targeting. A notable characteristic is its use of Polygon blockchain smart contracts and public RPC infrastructure as a dead-drop resolver to conceal and rotate command-and-control destinations, an EtherHiding-style design that complicates disruption.
Research has linked LenAI most strongly to the active โBeerโ ErrTraffic cluster, which appears to be rented to multiple affiliates under a MaaS model. That cluster has delivered a broad range of commodity malware, including stealers, loaders, RATs, and related crimeware. Campaigns associated with ErrTraffic have relied on compromised WordPress infrastructure, stolen administrator credentials, obfuscated JavaScript injectors, clipboard-delivered PowerShell execution, and follow-on malware deployment. In observed intrusions, ErrTraffic has been used in combination with other MaaS offerings, including Cruciferra, to facilitate DLL side-loading, process hollowing, and deployment of information stealers such as Remus; some linked chains also included abuse of a vulnerable signed driver to disable security products.
LenAI has also been associated with Aeternum C2, a native C++ loader and command-and-control framework that stores encrypted tasking in Polygon smart contracts and retrieves instructions through public RPC endpoints. Aeternum includes a web-based management panel, anti-analysis checks such as virtualization detection, and features intended to reduce antivirus detection. The actor publicly advertised pricing for both subscription-style access and source-code sales, indicating a commercial crimeware business model.
Overall, LenAI appears to operate as a cybercriminal service provider focused on initial access enablement, social-engineering-driven malware delivery, resilient blockchain-backed command-and-control, and affiliate support for broader malware distribution ecosystems.
Samples
4580f7cbdd3d0a776f86f6f34813b5f81a3cbf4df0e224d3b077b02d0d6f8c1a 85416824fbe85a2df3266e59eea11ed5d54f444615dcaba4c4f3fa739b5d4d5f 8a5c3f12c8a35c14985c8e1fc41603da170c78d10c175b49b7159f350689fa6b fe1a76a9c147971e933db951803748f0a3fc89d42faca86b5c7e84d25747d390 2c0da359b478fb4cc932a3a324667bac94d71fe1ed4b6e46cd83afe402a1167b 4eb4d21fbd99a89054c3d2d567198f3216218118aba20d486ba09d3a0ad777c8 45aab00ff5c17b0a92ee918d6d994b5a292cb5b56fe5a336a2d2dc8d43a96f56 7a4696cb062e4cbbc1e257edc42504c0bb47b869d7e88bb6c014945dd826b69f c0e5e9dbbc7c9fdb02040356872971b720066da9eb933ef6443b390226a31e3b e69e6031981c56d16d5a08a66031326a41746ec2046e1f07d499fa8af957ddda MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.