CNABHunter is a custom Python-based financial-fraud tool targeting Brazilian CNAB remittance files used by companies and banks to exchange payment instructions. It systematically searches local and network directories for CNAB files, parses transaction records, and exfiltrates payment metadata to attacker-controlled HTTP infrastructure. The tool can poll command-and-control infrastructure for instructions and rewrite payment information in CNAB files, including banking details, PIX keys, and barcodes, to redirect legitimate payments to attacker-controlled destinations. No specific threat actor, initial-access method, or target operating system is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazil-focused financial malware that manipulates CNAB payment/remittance instructions to facilitate fraud. Unlike BraZetsu, it is not described as only identifying CNAB files.
CNABHunter est uniquement cité dans la liste finale « Malware / Outils » sans description supplémentaire.
A tool targeting Brazilian CNAB payment-exchange files. It can locate and parse such files and, at operator command, modify payment details—including bank account information, PIX keys, and barcodes—to divert payments to attackers.
A Python-based financial-fraud tool that finds and parses Brazilian CNAB corporate remittance files, exfiltrates payment metadata, polls for operator commands, and can rewrite legitimate payment records with attacker-controlled banking details, PIX keys, or barcodes. It overlaps with BraZetsu in its CNAB-file discovery directory list.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.