Check out the results from our first round of ATT&CK Evaluations at!

Cherry Picker

Cherry Picker is a point of sale (PoS) memory scraper. [1]

ID: S0107
Aliases: Cherry Picker
Platforms: Windows

Version: 1.0

Techniques Used

EnterpriseT1103AppInit DLLsSome variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"[1]
EnterpriseT1048Exfiltration Over Alternative ProtocolCherry Picker exfiltrates files over FTP.[1]
EnterpriseT1107File DeletionRecent versions of Cherry Picker delete files and registry keys created by the malware.[1]