ATT&CKReferencesTrustwave Cherry Picker

Trustwave Cherry Picker

Merritt, E.. (2015, November 16). Shining the Spotlight on Cherry Picker PoS Malware. Retrieved April 20, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCherry Picker

Cherry Picker exfiltrates files over FTP.

T1070.004
File Deletion
MalwareCherry Picker

Recent versions of Cherry Picker delete files and registry keys created by the malware.

T1546.010
AppInit DLLs
MalwareCherry Picker

Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.