# US Sanctions Tren de Aragua Members for ATM Jackpotting Attacks

> US Treasury sanctions eight Tren de Aragua members, including Ploutus malware developer, for ATM jackpotting attacks across the United States.

- Published: 2026-10-04T13:35:22.000Z
- Severity: info
- Category: Threat Intel
- Tags: ATM Jackpotting, Financial Crime, Malware, Tren De Aragua, Ploutus
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/
- Canonical: https://runtimerebel.com/blog/us-sanctions-tren-de-aragua-members-for-atm-jackpotting-attacks

## Key points

- US Treasury sanctioned eight Tren de Aragua members for their role in multi-million dollar ATM jackpotting attacks targeting US financial institutions.
- Automated teller machines (ATMs) across the United States were targeted by the Ploutus malware and other similar variants.
- Financial institutions should enhance ATM security measures, monitor for malware deployment, and implement strong physical and logical access controls.

The U.S. Treasury Department has taken significant action against the Venezuelan transnational criminal organization [Tren de Aragua](https://en.wikipedia.org/wiki/Tren_de_Aragua) (TdA), sanctioning eight key members involved in widespread ATM jackpotting attacks across the United States. These sanctions are part of a broader, sustained U.S. government effort to dismantle the financial infrastructure of transnational criminal organizations, as detailed by [BleepingComputer](https://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/). The crackdown highlights the increasing sophistication of financial fraud tactics employed by such groups and the critical need for financial institutions to bolster their defenses against these evolving threats.

## Analysis of Tren de Aragua's ATM Jackpotting Operations

The designated individuals include Anibal Alexander Canelon Aguirre, known as "Prometheus," who is alleged to be the developer of the potent Ploutus [malware](/glossary#malware) used in these ATM attacks. Aguirre has been on the FBI's Most Wanted Fugitives list since March, underscoring the severity of his involvement. Six of his associates — Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo — were also sanctioned for their roles in the illicit network. While Prometheus’s network operates from Mexico and Venezuela, their operations directly target U.S.-based automated teller machines.

ATM jackpotting involves criminals deploying specialized malware on bank and credit union ATMs to force them to dispense cash, often referred to as "black box attacks." After emptying the machines, the attackers typically use an attached USB keyboard or the built-in PIN pad to delete evidence of the intrusion. The source material names several malware families associated with such attacks, including Ploutus, ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, and SUCEFUL. These malware variants represent a serious threat, allowing attackers to manipulate ATM operations and exfiltrate large sums of money.

According to the Office of Foreign Assets Control (OFAC), Tren de Aragua members have stolen an estimated $40.73 million from U.S. financial institutions through over 1,500 alleged ATM jackpotting attacks as of August 2025. The stolen funds are then laundered and transferred to TdA members internationally, often utilizing cryptocurrency. TRM Labs reported that the Treasury added seven TRON addresses to its Specially Designated Nationals and Blocked Persons List (SDN List), which have collectively received approximately $6.1 million in inflows since March 2022 and are linked to TdA-associated addresses. This illustrates the complex methods used for illicit financial flows.

## Mitigating ATM Jackpotting Threats

The extensive financial impact and the sophistication of the [Tren de Aragua](https://en.wikipedia.org/wiki/Tren_de_Aragua)'s operations underscore the urgency for financial institutions to reassess and enhance their security postures. The TdA's **ATM jackpotting TTPs** (Tactics, Techniques, and Procedures) involve both physical access to machines and the deployment of advanced malware, requiring a multi-layered defense strategy.

## Recommendations for Enhanced ATM Security

To effectively counter threats like **detecting Ploutus malware on ATMs** and preventing similar jackpotting incidents, financial institutions should prioritize the following actions:

*   **[Physical Security](/glossary#physical-security) Enhancements:** Strengthen physical access controls for ATMs, including enhanced locking mechanisms, alarm systems, and video surveillance. Regular, unannounced physical inspections can deter tampering.
*   **Software and Network [Hardening](/glossary#hardening):** Implement rigorous [patch](/glossary#patch) management for ATM operating systems and application software. Isolate ATM networks from the broader corporate network and apply strict [firewall](/glossary#firewall) rules to prevent unauthorized communication.
*   **Malware Detection and Prevention:** Deploy advanced [endpoint](/glossary#endpoint) detection and response ([EDR](/glossary#edr)) solutions specifically tailored for ATMs. Implement whitelisting to ensure only approved applications can run, effectively preventing the execution of unauthorized malware like Ploutus. Regular security audits and [penetration testing](/glossary#penetration-testing) focused on ATM vulnerabilities are also crucial.
*   **Transaction Monitoring and Anomaly Detection:** Implement real-time monitoring of ATM transactions for unusual activity, such as unusually large withdrawals or multiple withdrawals from the same machine in a short period. [AI](/glossary#ai)-driven anomaly detection systems can flag suspicious patterns that indicate jackpotting attempts.
*   **Employee Training:** Train staff, especially those responsible for ATM maintenance and security, to recognize signs of tampering, suspicious activity, and [social engineering](/glossary#social-engineering) attempts that could facilitate malware deployment.

These measures are vital in protecting against the significant financial losses and reputational damage that ATM jackpotting attacks can inflict. Proactive defense and vigilance remain the best countermeasures against evolving criminal enterprises.

**Related:** [SPECTRE Malware: UAT-10147 Targets IIS, Linux Servers with Rootkits](/blog/spectre-malware-uat-10147-targets-iis-linux-servers-with-rootkits), [Jscrambler npm Package Backdoored with Infostealer Malware](/blog/jscrambler-npm-package-backdoored-with-infostealer-malware)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/us-sanctions-tren-de-aragua-members-for-atm-jackpotting-attacks
