CherryPicker POS
Aliases: cherry_picker, cherrypicker, cherrypickerpos
- First seen
- 2016-07-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:52:26
Targeted industries: retail-and-hospitality
Context
CherryPicker POS is a malware family designed to target point-of-sale systems, primarily in the retail and hospitality sectors. It is known for scraping memory to steal credit card information during transactions.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Cherry_Picker_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Cherry Picker (report)
- trustwave.com — New Memory Scraping Technique In Cherry Picker Pos Malware (report)
- trustwave.com — Shining The Spotlight On Cherry Picker Pos Malware (report)
- cocomelonc.github.io — Malware Pers 5 (report)