LenAI is a cybercrime actor associated with the development, advertising, and sale of malware tooling under a malware-as-a-service model. The actor is linked to ErrTraffic, a malicious traffic-distribution and ClickFix delivery framework used on compromised WordPress sites, and to Aeternum C2, a botnet loader that uses the Polygon blockchain for resilient command-and-control. LenAI has marketed these tools on underground forums and Telegram, including subscription access, configured builds, and source-code sales. ErrTraffic is associated with JavaScript injected into compromised WordPress sites to present ClickFix lures and deliver follow-on malware. The framework uses blockchain-based dead-drop resolution to conceal and rotate command-and-control infrastructure, supports geofiltering and operating-system detection, and has been used to distribute multiple commodity malware families including stealers, loaders, and remote-access tooling. Reporting links LenAI with the active "Beer" ErrTraffic cluster, which appears to function as a rental platform for multiple affiliates using distinct smart contracts and payload chains. Campaigns tied to this cluster have included fake AI-themed websites and other social-engineering lures, while access to WordPress sites has been obtained through stolen administrator credentials and maintained through backdoors and persistent malicious plugins. LenAI is also linked to Aeternum C2, a native C++ loader and command platform that stores encrypted tasking in Polygon smart contracts and allows infected hosts to retrieve instructions through public RPC endpoints. The platform includes a web-based management panel, anti-analysis checks such as virtualization detection, and features intended to reduce antivirus detection. The design minimizes reliance on conventional infrastructure and increases resistance to takedown. Overall, LenAI appears to operate as a financially motivated crimeware developer and service provider rather than a nation-state actor, enabling downstream affiliates or customers to conduct malware delivery, credential theft, and related post-compromise activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operator and seller of the ErrTraffic Malware-as-a-Service offering; assessed to operate the 'Beer' cluster and provide affiliates with a ClickFix/TDS framework for malware delivery.
Advertised and attempted to sell the Aeternum C2 botnet loader/toolkit, which uses a blockchain-based C2 design (Polygon smart contracts) to issue commands to infected bots and includes anti-analysis and AV-evasion features.
Advertises and sells the Aeternum C2 botnet loader/toolkit (including panel access and allegedly full C++ source code), and is also linked to the ErrTraffic crimeware solution used to automate ClickFix-style social engineering on compromised websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.