VYPR
breachPublished Sep 30, 2026· 1 source

US Sanctions 10 Over ATM Malware Scheme Tied to Tren de Aragua

The U.S. Treasury has sanctioned 10 individuals and companies linked to the Tren de Aragua criminal organization for their involvement in a widespread ATM jackpotting scheme.

The U.S. Treasury Department has imposed sanctions on 10 individuals and associated companies for their alleged roles in a lucrative ATM jackpotting scheme that has drained millions of dollars from cash machines across the United States. The Office of Foreign Assets Control (OFAC) specifically targeted Venezuelan nationals and several entities they control, accusing them of laundering funds stolen through illicit operations. U.S. officials estimate that at least 1,500 such attacks have occurred, resulting in approximately $40.7 million in losses.

Treasury officials have directly linked this ATM jackpotting operation to the Tren de Aragua, a notorious Venezuelan transnational criminal organization, identifying it as a "key source of revenue for the organization." The proceeds from the ATM thefts were reportedly funneled to Tren de Aragua members who then worked to conceal the illicit origins of the money. This concealment was allegedly achieved through the use of cryptocurrency or by laundering the funds through companies owned by the organization in Mexico and other countries.

The Justice Department has previously asserted "extensive direct and indirect links" between the Ploutus malware, commonly used in these ATM jackpotting attacks, and the Tren de Aragua. Analysis from blockchain firm Chainalysis further supports these connections, noting that the financial channels used for ATM jackpotting proceeds often overlap with those used for drug trafficking money. Chainalysis experts observed that counterparties of the wallets associated with Tren de Aragua had exposure to laundering operations utilized by Colombian and Mexican drug cartels, as well as a Venezuelan national previously charged with laundering a billion dollars.

This latest action by the Treasury is part of a broader U.S. government effort to dismantle the ATM jackpotting scheme. To date, at least 98 individuals have been indicted for their involvement in the malware scheme, with five men having already pleaded guilty to related charges. Prosecutors and the Treasury Department have released visual evidence, including videos and photos, depicting individuals connecting laptops to ATMs and installing the Ploutus malware, which forces the machines to dispense all available cash.

The FBI has identified Anibal Alexander Canelon Aguirre as the alleged developer of the Ploutus malware. Aguirre, who is currently on the FBI's most wanted list, is accused of deploying multiple teams across the U.S. to carry out these attacks, often targeting ATMs located in more remote areas. The Treasury Department stated it possesses photographs of Aguirre with proceeds from these ATM jackpotting crimes, and several other individuals named in the sanctions are accused of facilitating the laundering of these funds through cryptocurrency.

Security experts and government agencies have been warning about variants of the Ploutus malware for nearly a decade. Google researchers have previously described it as "one of the most advanced ATM malware families" they have encountered. While the Ploutus malware itself has been a known threat, the specific connection and operational integration with a large criminal syndicate like Tren de Aragua highlight an evolving and increasingly organized approach to cyber-enabled financial crime.

Synthesized by Vypr AI