The United States Treasury Department has taken a major step in its ongoing crackdown on ATM jackpotting attacks by sanctioning eight members of the Venezuelan gang Tren de Aragua (TdA). The sanctioned individuals are accused of stealing millions of dollars from ATMs across the US using sophisticated malware and coordinated schemes.
At the center of this operation is Anibal Alexander Canelon Aguirre, also known as “Prometheus,” a key figure in the TdA gang. Aguirre has allegedly developed the Ploutus malware, a piece of software specifically designed to compromise ATMs by forcing them to dispense cash and deleting evidence. The malware is deployed via an attached USB keyboard or the built-in PIN pad, allowing thieves to quickly drain the ATM’s funds.
The TdA gang’s operations are not limited to Venezuela; their network stretches across Mexico and targets US-based ATMs. Once the funds are stolen, they are laundered and transferred to other countries, often through complex financial networks. The Treasury Department has designated TdA as a Transnational Criminal Organization, and the Department of State has labeled it a Foreign Terrorist Organization due to its alleged ties to organized crime.
The scope of the TdA gang’s activities is staggering. According to estimates from the Office of Foreign Assets Control (OFAC), the group has stolen over $40 million from US financial institutions across more than 1,500 ATM jackpotting attacks since August 2025. To put this number into perspective, that’s equivalent to around $26,000 per attack. Furthermore, seven TRON addresses associated with TdA have received approximately $6.1 million in total inflows since March 2022.
The US government’s efforts against the TdA gang are yielding results. Since October 2025, the US Justice Department has charged 98 suspects linked to the gang, who now face maximum prison terms ranging from 20 to 335 years each. The Treasury Department’s sanctions on the eight TdA members are part of a broader campaign that has resulted in over 30 actions against more than 300 individuals and entities tied to transnational criminal organizations since 2025.
As the battle against ATM jackpotting attacks continues, financial institutions must remain vigilant and implement robust security measures to protect their customers’ funds. This includes regular software updates, strict access controls, and ongoing employee training on cybersecurity best practices. By staying informed about the latest threats and working together, we can prevent these types of attacks from happening in the first place.
In light of this development, it’s essential for individuals and businesses to take proactive steps in securing their financial information and protecting themselves against such cybercrimes. This includes keeping software up-to-date, being cautious when using ATMs or online banking services, and reporting any suspicious activity immediately. By staying informed and taking the necessary precautions, we can all play a role in combating these sophisticated threats and safeguarding our financial security.
Source: Bleeping Computer — 2026-10-02