Register to stream ATT&CKcon 2.0 October 29-30

Cherry Picker

Cherry Picker is a point of sale (PoS) memory scraper. [1]

ID: S0107
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1103 AppInit DLLs Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll" [1]
Enterprise T1048 Exfiltration Over Alternative Protocol Cherry Picker exfiltrates files over FTP. [1]
Enterprise T1107 File Deletion Recent versions of Cherry Picker delete files and registry keys created by the malware. [1]