ATT&CKSoftwareCherry Picker

Cherry Picker

S0107

Malware.View on attack.mitre.org

About this malware

Cherry Picker is a point of sale (PoS) memory scraper.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Cherry Picker exfiltrates files over FTP.

T1070.004
File Deletion

Recent versions of Cherry Picker delete files and registry keys created by the malware.

T1546.010
AppInit DLLs

Some variants of Cherry Picker use AppInit_DLLs to achieve persistence by creating the following Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows "AppInit_DLLs"="pserver32.dll"

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Trustwave Cherry Picker Open source
    Merritt, E.. (2015, November 16). Shining the Spotlight on Cherry Picker PoS Malware. Retrieved April 20, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.