CherryPicker POS

Aliases: cherry_picker, cherrypicker, cherrypickerpos

First seen
2016-07-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:52:26

Targeted industries: retail-and-hospitality

Context

CherryPicker POS is a malware family designed to target point-of-sale systems, primarily in the retail and hospitality sectors. It is known for scraping memory to steal credit card information during transactions.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cherry_Picker_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Cherry Picker (report)
  • trustwave.com — New Memory Scraping Technique In Cherry Picker Pos Malware (report)
  • trustwave.com — Shining The Spotlight On Cherry Picker Pos Malware (report)
  • cocomelonc.github.io — Malware Pers 5 (report)

External references