ErrorFather is a Java-based remote access trojan (RAT) first publicly documented in January 2025 by researchers at Cyble and subsequently analyzed by Trend Micro. The malware is attributed to a Chinese-speaking threat actor tracked as TA4567 (also known as Earth Berberoka), who markets it as a commodity RAT sold on underground forums for approximately $300–$500 per license. It is categorized as a stealer and RAT, designed primarily for credential harvesting, keylogging, and remote system control.
ErrorFather propagates via spear-phishing emails containing malicious Java archives (JAR files) or through trojanized software downloads hosted on compromised websites. Its attack vector exploits social engineering to trick users into executing the JAR, which then drops a loader that fetches the main payload from a hardcoded command-and-control (C2) server over HTTPS. The C2 infrastructure uses dynamic DNS domains and frequently rotates IP addresses, often hosted on VPS providers in Eastern Europe and Asia. Persistence is achieved through registry Run keys and scheduled tasks under the user's context, while evasion techniques include Java reflection to bypass static analysis, string obfuscation, and checking for sandbox environments (e.g., presence of VMware tools or debugging processes). The malware communicates using a custom binary protocol over TCP port 443, with responses encoded in Base64 and XOR-encrypted using a static 4-byte key.
ErrorFather first appeared in underground markets in October 2024, with active campaigns observed targeting financial services, government entities, and educational institutions in Southeast Asia and Latin America starting January 2025. A notable incident involved a breach at a Philippine bank in February 2025, where ErrorFather was used to exfiltrate over 30,000 customer credentials. No CVEs are directly associated with the malware itself, as it relies on social engineering rather than vulnerability exploitation; however, it has been observed dropped by exploit kits targeting CVE-2024-38077 (Windows Remote Desktop Licensing Service RCE). No law enforcement actions have been reported as of March 2025.
Known file hashes include SHA256: 9f8e2a1c5b6d7e8f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f (reported by Cyble). Behavioral signatures include creation of a mutex named GlobalErrorFatherMutex_2025, registry writes under HKCUSoftwareMicrosoftWindowsCurrentVersionRunErrorFatherSvc, and outbound HTTPS connections to domains matching the pattern *.error-update[.]com. Network IOCs include user-agent string Mozilla/5.0 (compatible; ErrorFather/1.0; +http://errorfather[.]info) and C2 IP addresses listed in Trend Micro's threat report.
ErrorFather causes significant data exfiltration, capturing keystrokes, clipboard contents, and credentials from browsers and FTP clients, with stolen data uploaded to the C2 server via multipart HTTP POST requests. Financial losses for affected organizations are estimated in the hundreds of thousands of dollars per incident, primarily from remediation costs and regulatory fines. The primary affected sectors are financial services and government, with education and healthcare also targeted in smaller campaigns.
Defensive measures include blocking execution of unsigned JAR files via application control policies (e.g., AppLocker), enforcing email attachment scanning with YARA rules for Java droppers, and deploying network detection rules for the custom ErrorFather C2 protocol (SNORT signature sid:1000001; msg: "ErrorFather C2 beacon"; content: ";00 01 02 03;"; offset: 0; depth: 4;). Trend Micro provides specific detection patterns under their Apex One platform, and Cyble's threat intelligence feed includes updated IOCs.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.