# LenAI

> As of 2026-08-17, LenAI is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware. ATT&CK coverage spans 75 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols), T1082 (System Information Discovery).

- **Nation:** N/A
- **Tracked threats:** 4
- **Categories:** MALWARE
- **As of:** 2026-08-17

## ATT&CK techniques observed

75 techniques observed across 4 of 4 tracked threats. Tactics: Stealth (formerly Defense Evasion) (17), Command and Control (13), Execution (8), Persistence (7), Collection (6), Initial Access (6).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 3 of 4 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 4 tracked threats
- [T1056](https://intel.threadlinqs.com/technique/T1056) Input Capture — Collection — observed in 2 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 4 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 4 tracked threats
- [T1112](https://intel.threadlinqs.com/technique/T1112) Modify Registry — Defense Impairment — observed in 2 of 4 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 4 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1189](https://intel.threadlinqs.com/technique/T1189) Drive-by Compromise — Initial Access — observed in 2 of 4 tracked threats

## Tracked threats

- [Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRig](https://intel.threadlinqs.com/threat/TL-2026-1979) — HIGH
- [ErrTraffic ClickFix-as-a-Service Campaign Delivers NetSupport RAT via Compromised Gizmodo Account](https://intel.threadlinqs.com/threat/TL-2026-0902) — HIGH
- [ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2](https://intel.threadlinqs.com/threat/TL-2026-0817) — HIGH
- [Aeternum C2 Botnet — Polygon Blockchain Smart Contract C2, Takedown-Resistant Infrastructure, LenAI MaaS](https://intel.threadlinqs.com/threat/TL-2026-0151) — CRITICAL

## Related CVEs

1 CVE referenced by tracked LenAI activity.

- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/LenAI
