Cherry Picker is malware associated with file exfiltration and post-operation cleanup behavior. It has been observed exfiltrating files over FTP, indicating use as an intrusion tool for collecting and transferring victim data to attacker-controlled infrastructure. Recent versions also remove files and registry artifacts created during execution, reflecting deliberate anti-forensic and defense-evasion measures intended to reduce host-based evidence and hinder incident response. The available reporting supports Cherry Picker as a Windows-focused malware family with exfiltration and artifact-deletion capabilities, but does not provide sufficient high-confidence detail to more precisely characterize its broader functionality, infection chain, or operator attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware that deletes files and registry keys it created.
Malware that exfiltrates files over FTP.
Malware that deletes files and registry keys it created (anti-forensics).
Malware that deletes files and registry keys it created to reduce forensic artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.