Skip to content

LenAI

LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework.

Profile source: Mallory opens in a new tab

LenAI

Family profile

LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework. LenAI has advertised ErrTraffic on Russian-language underground forums and Telegram since at least December 2025. ErrTraffic is used to inject obfuscated JavaScript into compromised WordPress sites, fingerprint and filter visitors, and present ClickFix social-engineering lures impersonating common verification checks or system errors. The framework supports delivery of clipboard-based PowerShell execution chains and provides customer-facing functionality including campaign statistics, payload-command generation, operating-system detection, and geographic and referrer filtering. ErrTraffic uses EtherHiding, resolving rotating command-and-control infrastructure through Polygon smart contracts, which complicates conventional infrastructure takedowns. The Beer ErrTraffic cluster has been assessed as LenAI-operated and rented to affiliates, with distinct smart contracts used by separate customers to distribute various stealers, loaders, remote-access tools, and other malware. LenAI also advertised Aeternum C2, a native botnet loader whose operators write encrypted commands to Polygon smart contracts for retrieval and execution by infected endpoints. Aeternum includes a web management panel, endpoint-targeting options, virtualization checks, and build-scanning functionality intended to reduce antivirus detection. LenAI later offered the Aeternum toolkit and source code for sale. A separate ErrTraffic Analytics cluster is attributed to another operator using an older purchased version of the framework and should not be treated as LenAI activity.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 30, 2026
Last activity
Oct 7, 2026
Feed role
C2 / Distribution
Host form
16 IP / 5137 hostnames

Leading locations

  • US2325
  • DE453
  • FR387
  • IT256
  • BR206
  • IN145
  • GB141
  • ES91
  • SG83
  • ZA81
  • PL71
  • TR62

Leading providers

  • Cloudflare, Inc.572
  • Oracle Corporation481
  • Hostinger International Limited397
  • Cloudflare London, LLC310
  • IONOS SE263
  • OVH SAS248

Infrastructure traits

  • Hosting 4949
  • Anycast 1329

Samples

Recent associated samples

MITRE ATT&CK

LenAI in ATT&CK

26 distinct techniques