LenAI is a cybercriminal operator and malware-as-a-service vendor active on Russian-language underground forums and Telegram since at least December 2025. LenAI advertises and sells ErrTraffic, a traffic-distribution and ClickFix framework used to inject malicious JavaScript into compromised WordPress sites. ErrTraffic presents fake verification or error prompts that induce victims to execute clipboard-delivered PowerShell commands, facilitating downstream malware delivery. Its features include social-engineering templates, operating-system detection, geographic and referrer filtering, payload delivery, execution statistics, JavaScript and AES obfuscation, and blockchain-based dead-drop resolution of command-and-control infrastructure through Polygon smart contracts. LenAI is assessed to operate the ErrTraffic "Beer" cluster and rent it to affiliates, whose campaigns have delivered information stealers, loaders, remote-access tools, and other malware. LenAI also advertised Aeternum C2, a native loader whose operators use Polygon smart contracts and public RPC endpoints for resilient command-and-control, with virtualization checks and antivirus-evasion-oriented build scanning. LenAI's activity is financially motivated through subscriptions, source-code sales, and malware-toolkit sales.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
87 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a cybercriminal actor in connection with the Exvicy activity, but the reference provides no specific operational role, tooling, targets, or campaign actions for this actor.
Seller of the ErrTraffic crimeware service, which supplies compromised-site JavaScript injections and ClickFix lures to deliver the Cruciferra loader. The campaign operators are unconfirmed.
Operator/vendor associated with the ErrTraffic MaaS loader used in active campaigns that redirect victims from compromised WordPress sites to ClickFix lures and malicious PowerShell execution.
Operator and seller of the ErrTraffic Malware-as-a-Service offering; assessed to operate the 'Beer' cluster and provide affiliates with a ClickFix/TDS framework for malware delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.