Cherry Picker

Cherry Picker is a point of sale (PoS) memory scraper. [1]

ID: S0107
Type: MALWARE
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1103 AppInit DLLs

Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"[1]

Enterprise T1048 Exfiltration Over Alternative Protocol

Cherry Picker exfiltrates files over FTP.[1]

Enterprise T1107 File Deletion

Recent versions of Cherry Picker delete files and registry keys created by the malware.[1]

References