PolicyMedium

US sanctions Tren de Aragua network behind $40.7 million ATM jackpotting scheme

OFAC designated 10 targets tied to a Tren de Aragua ATM jackpotting scheme that used Ploutus malware, including alleged developer Anibal Alexander Canelon Aguirre.

US sanctions Tren de Aragua network behind $40.7 million ATM jackpotting scheme

At a glance

  • On September 30, OFAC designated eight individuals and two Mexico-based companies linked to Tren de Aragua's ATM jackpotting operation.
  • Alleged Ploutus malware developer Anibal Alexander Canelon Aguirre, known as "Prometheus," is among those sanctioned.
  • Treasury estimates losses of $40.73 million across more than 1,500 attacks as of August 2025.
  • BleepingComputer reported that seven TRON addresses that received about $6.1 million were also designated.

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on September 30 sanctioned 10 targets involved in an ATM jackpotting scheme run by Tren de Aragua (TdA), the Venezuelan criminal organization the U.S. has designated as a foreign terrorist organization. According to the Treasury press release, the fraud scheme has become a key source of revenue for the group, with losses estimated at $40.73 million across more than 1,500 attacks on U.S. financial institutions as of August 2025.

What happened

The Treasury said the designations cover eight individuals and two Mexico-based companies tied to the jackpotting network. The most prominent name is Anibal Alexander Canelon Aguirre, also known as "Prometheus," whom the Treasury describes as the alleged engineer of the malware. BleepingComputer reported that he was added to the FBI's Ten Most Wanted Fugitives list in March 2026, and The Record reported that he allegedly deployed teams across the U.S. to target ATMs in remote areas.

The other sanctioned individuals are Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, Anthony Wuiliam Hernandez Guerrero and Aslhy Javier Galeano Basurto, according to the Treasury. The two designated entities are Enigma Community, S. de R.L. de C.V., owned by Martinez Pirona, and Soluciones Integrales Toluca, S.A. de C.V., owned by Mejia Castillo. In the same action, the Treasury also sanctioned Juan Gabriel Rivas Nunez, known as "Juancho," a high-ranking TdA leader it linked to illicit gold mining operations in South America.

The designations were made under Executive Orders 13581 and 13224, as amended. "President Trump's administration will not allow terrorist organizations like Tren de Aragua to exploit the U.S. financial system," Treasury Secretary Scott Bessent said in the release.

Technical details

Jackpotting attacks install malware on ATMs to force them to dispense cash. The Record described Ploutus as one of the most advanced ATM malware families, noting that it is loaded by physically connecting a laptop to the machine. BleepingComputer noted that other known jackpotting families include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer and SUCEFUL.

According to BleepingComputer, OFAC also listed seven TRON addresses that received roughly $6.1 million since March 2022. Chainalysis said the addresses are deposit addresses at a major cryptocurrency exchange, and The Record cited the firm's assessment that the proceeds flow through the same channels used to launder drug trafficking money.

Who is affected

The sanctions block any property of the designated parties under U.S. jurisdiction and generally bar U.S. persons from dealing with them, which matters for banks, exchanges and payment firms screening against the SDN list. The action builds on criminal cases: BleepingComputer reported that the Justice Department has charged 98 TdA-linked suspects since October 2025, and The Record reported that five men pleaded guilty to related charges in August 2026.

What to do

Financial institutions and ATM operators should screen customers and counterparties against the updated SDN list, including the designated TRON addresses. ATM owners should strengthen physical security of cabinets and service ports, monitor for unexpected device connections or reboots, and keep ATM software and hardened configurations current to reduce exposure to jackpotting malware.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.