Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 3997 hostnames
LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework.
Profile source: Mallory opens in a new tabLenAI
LenAI is a financially motivated cybercrime vendor associated with the development, sale, and operation of ErrTraffic, a malware-as-a-service traffic-distribution framework. LenAI has advertised ErrTraffic on Russian-language underground forums and Telegram since at least December 2025. ErrTraffic is used to inject obfuscated JavaScript into compromised WordPress sites, fingerprint and filter visitors, and present ClickFix social-engineering lures impersonating common verification checks or system errors. The framework supports delivery of clipboard-based PowerShell execution chains and provides customer-facing functionality including campaign statistics, payload-command generation, operating-system detection, and geographic and referrer filtering. ErrTraffic uses EtherHiding, resolving rotating command-and-control infrastructure through Polygon smart contracts, which complicates conventional infrastructure takedowns. The Beer ErrTraffic cluster has been assessed as LenAI-operated and rented to affiliates, with distinct smart contracts used by separate customers to distribute various stealers, loaders, remote-access tools, and other malware. LenAI also advertised Aeternum C2, a native botnet loader whose operators write encrypted commands to Polygon smart contracts for retrieval and execution by infected endpoints. Aeternum includes a web management panel, endpoint-targeting options, virtualization checks, and build-scanning functionality intended to reduce antivirus detection. LenAI later offered the Aeternum toolkit and source code for sale. A separate ErrTraffic Analytics cluster is attributed to another operator using an older purchased version of the framework and should not be treated as LenAI activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
05f06e445e2a315d1a6e5eb07679c3c868953ea6d5e04141553be37b73709e26 1f641164daba9a55c529cf1079b3eb54160218999c5db44ab18e73dee42bb4e7 3e946706f34ad1564d355fcaa4a176d9fa9dfda7de95ef2e38962cc722611868 57db7a8ba3045665ef2adc4c34d227ccf76515dbd6c7d6580990ece1e99c08fb 59542af0729d86a74643ebd93085df1f44fe722a64ce46f2ad6c50dc02d03f58 dc7aec96b3959a8467556bb4fe013e006cb6be84ba66d72fa4b8d52fdd9038ff ec321669aa549c30fd18a0e82c65bd555b678f7c8edd969ecf99288d1f0aff17 f43a8bded8118fe101f6563149783be06097cb02d56a07af03bf6b7c84169898 f5cb11e31d983de1fe78063827b6c7f289264054333d541c5ad906f27c517d7c 32f7201801a8cc77fa41732e29d260e68d7be923bda5b0e9790dcabdc2163318 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.