Skip to content

LenAI

LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework.

Profile source: Mallory opens in a new tab

LenAI

Family profile

LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework. LenAI has advertised ErrTraffic on Russian-language underground forums and Telegram since at least December 2025. ErrTraffic is used to inject obfuscated JavaScript into compromised WordPress sites, fingerprint and filter visitors, and present ClickFix social-engineering lures impersonating common verification checks or system errors. The framework supports delivery of clipboard-based PowerShell execution chains and provides customer-facing functionality including campaign statistics, payload-command generation, operating-system detection, and geographic and referrer filtering. ErrTraffic uses EtherHiding, resolving rotating command-and-control infrastructure through Polygon smart contracts, which complicates conventional infrastructure takedowns. The Beer ErrTraffic cluster has been assessed as LenAI-operated and rented to affiliates, with distinct smart contracts used by separate customers to distribute various stealers, loaders, remote-access tools, and other malware. LenAI also advertised Aeternum C2, a native botnet loader whose operators write encrypted commands to Polygon smart contracts for retrieval and execution by infected endpoints. Aeternum includes a web management panel, endpoint-targeting options, virtualization checks, and build-scanning functionality intended to reduce antivirus detection. LenAI later offered the Aeternum toolkit and source code for sale. A separate ErrTraffic Analytics cluster is attributed to another operator using an older purchased version of the framework and should not be treated as LenAI activity.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 9, 2026
Feed role
C2 / Distribution
Host form
1 IP / 3997 hostnames

Leading locations

  • US1621
  • FR398
  • DE340
  • BR132
  • IT117
  • IN110
  • ES104
  • CY89
  • GB83
  • NL70
  • CH67
  • SG64

Leading providers

  • Cloudflare, Inc.352
  • Hostinger International Limited304
  • OVH SAS285
  • Oracle Corporation276
  • Cloudflare London, LLC188
  • IONOS SE161

Infrastructure traits

  • Hosting 3829
  • Anycast 892
  • Proxy 10

Samples

Recent associated samples

MITRE ATT&CK

LenAI in ATT&CK

26 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.