U.S. Treasury Sanctions Tren de Aragua's ATM Jackpotting Network
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) announced sanctions on September 30, 2026 against 10 targets tied to a Tren de Aragua (TdA) cybercrime network responsible for ATM jackpotting attacks that stole an estimated $40.73 million from U.S. financial institutions. The designation covers eight individuals and two Mexico-based companies, along with seven TRON cryptocurrency addresses added to the Specially Designated Nationals and Blocked Persons (SDN) List. Treasury said the scheme, which relies on custom malware to force cash machines to dispense money on command, became a key revenue stream funding the broader TdA criminal enterprise — including drug trafficking, human smuggling, and murder-for-hire operations.
At the center of the network is Anibal Alexander Canelon Aguirre, known by the alias "Prometheus," a fugitive added to the FBI's Ten Most Wanted Fugitives list in March 2026. U.S. court filings allege Aguirre engineered the Ploutus malware strain used to compromise ATMs in the scheme, operating out of Mexico and Venezuela. The other sanctioned individuals — Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo — are accused of supporting roles in deploying the malware and laundering stolen proceeds.
Details
| Attribute | Value |
|---|---|
| Action | OFAC sanctions designation (SDN List) |
| Date announced | September 30, 2026 |
| Lead agency | U.S. Department of the Treasury (OFAC) |
| Criminal organization | Tren de Aragua (TdA) — designated a Foreign Terrorist Organization, February 2025 |
| Individuals sanctioned | 8, including alleged malware developer Anibal Alexander Canelon Aguirre ("Prometheus") |
| Entities sanctioned | 2 Mexico-based companies |
| Crypto addresses designated | 7 TRON addresses, approximately $6.1 million in tracked inflows since March 2022 |
| Reported losses | $40.73 million (as of August 2025) |
| Reported attack volume | 1,500+ alleged ATM jackpotting incidents |
| Malware strain cited | Ploutus |
| Related DOJ action | 98 individuals indicted since October 2025; sentences up to 20–335 years |
How the Scheme Worked
Physical ATM Compromise
ATM jackpotting is a hands-on attack: operatives physically access the top of an ATM enclosure — often at machines in remote or low-traffic locations — to connect a laptop or other device directly to the machine's internals. From there, malware is installed that can command the ATM's cash dispenser to empty itself on cue, bypassing normal transaction and account-debit processes entirely. BleepingComputer reported that the malware families associated with jackpotting campaigns targeting U.S. ATMs include Ploutus, ATMitch, ATMii, GreenDispenser, Alice, RIPPER, Skimer, and SUCEFUL, with Ploutus specifically named in court filings tied to this network.
Laundering Through Crypto and Shell Companies
Treasury said proceeds from the jackpotting attacks were funneled through cryptocurrency — the seven designated TRON addresses received roughly $6.1 million since March 2022 — and through the two Mexico-based companies now on the SDN list. Blockchain analytics firms Chainalysis and TRM Labs, which supported the investigation, found that counterparties to the sanctioned wallets had also interacted with money-laundering networks used by drug-trafficking groups in Mexico and Colombia, as well as by Venezuela-based launderers. All seven addresses are deposit addresses at a single centralized exchange, prompting Treasury to urge virtual asset service providers and financial institutions to screen for exposure.
A Contested Attribution
It is worth noting a caveat raised by independent researchers: while U.S. court filings and Treasury's designation tie Aguirre to the Ploutus malware, outlet reporting (via The Record) notes that some malware researchers have not independently verified a technical link between the Ploutus codebase and Aguirre or Tren de Aragua specifically. The attribution reflects the government's investigative and prosecutorial findings rather than independently confirmed malware forensics.
Impact Assessment
| Impact Area | Description |
|---|---|
| Financial sector | $40.73 million in direct losses reported across more than 1,500 ATM jackpotting incidents tied to the network |
| Sanctions exposure | U.S. persons and financial institutions are now prohibited from transacting with the designated individuals, companies, and crypto addresses |
| Crypto/VASP risk | Exchanges and virtual asset service providers must screen for exposure to the seven designated TRON addresses or risk secondary sanctions liability |
| National security framing | Treasury and DOJ continue to treat TdA's cyber-enabled fraud as material support for a designated Foreign Terrorist Organization |
| Ongoing prosecutions | DOJ has indicted 98 individuals since October 2025 on related charges, including bank burglary, bank fraud, and unauthorized computer access |
| Physical security gap | Jackpotting continues to exploit weak physical access controls on standalone and remote ATMs rather than network-level vulnerabilities |
Recommendations
For Financial Institutions and ATM Operators
- Harden physical access to ATM top-boxes with tamper-evident seals, locks rated for forced entry, and alarmed enclosures, particularly at unattended or remote sites.
- Enforce BIOS/firmware-level allow-listing and disable unused USB and service ports on ATM controllers to block unauthorized peripheral connections.
- Deploy ATM-specific endpoint protection capable of detecting known jackpotting malware families (Ploutus, ATMitch, ATMii, GreenDispenser, Skimer, and related strains).
- Increase monitoring for off-hours cash-dispenser commands and anomalous dispense volumes that fall outside normal transaction patterns.
For Security Teams and Compliance Staff
- Screen customer and counterparty wallets against the newly designated TRON addresses and update sanctions-screening tools with the OFAC SDN additions.
- Review Suspicious Activity Report (SAR) filing procedures for any transactions potentially linked to the sanctioned individuals or Mexico-based entities.
- Share indicators of compromise and physical-attack patterns with regional banking ISACs and law enforcement partners.
For the Public and Consumers
- Avoid using standalone or poorly lit ATMs in isolated locations when possible, and report any signs of tampering (loose panels, exposed wiring, unusual attachments) to the ATM operator immediately.
- Monitor bank and card statements for unauthorized activity, though jackpotting primarily targets the ATM's own cash reserves rather than individual customer accounts.
Key Takeaways
- OFAC sanctioned eight Tren de Aragua members, two Mexico-based companies, and seven TRON addresses over a $40.73 million ATM jackpotting scheme.
- The network's alleged lead malware developer, Anibal Alexander Canelon Aguirre ("Prometheus"), is an FBI Ten Most Wanted fugitive linked to the Ploutus ATM malware.
- More than 1,500 jackpotting attacks have been reported against U.S. ATMs as part of this funding stream for Tren de Aragua.
- Proceeds were allegedly laundered through cryptocurrency deposit addresses and shell companies before reaching TdA members internationally.
- The sanctions follow a year of escalating DOJ action, with 98 individuals indicted since October 2025 facing sentences up to 335 years.
- ATM jackpotting remains a physical-access attack — tamper-resistant hardware and port lockdown are more effective defenses than network-perimeter controls alone.
For related CosmicBytez Labs coverage of this ongoing campaign, see our earlier reporting on the FBI's warning of a $20 million ATM jackpotting surge and the Kansas guilty pleas tied to the same Tren de Aragua funding scheme.
Sources
- US sanctions Tren de Aragua gang members in ATM hacks crackdown — BleepingComputer
- Treasury Sanctions Financial Network of Foreign Terrorist Organization, Tren de Aragua, After Theft of Millions from U.S. Banks — U.S. Department of the Treasury
- US sanctions 10 over ATM malware scheme tied to Tren de Aragua — The Record
- Treasury Sanctions Tren de Aragua ATM Jackpotting Network, Including Seven TRON Addresses — TRM Labs