Skip to main content
Emerging ThreatsMalware & Ransomware

US Treasury Sanctions Tren de Aragua Members Over $40 Million ATM Hacks

Bank lobby with ATMs, one vandalized with panel open and cash on floor.

"While Prometheus's network is based in Mexico and Venezuela, the scheme targets U.S.-based automated teller machines (ATMs), where criminals deploy malicious software (malware) to force ATMs to dispense cash. The stolen funds are then laundered and transferred to TdA members in various countries," the Office of Foreign Assets Control (OFAC) said.

Treasury sanctions eight Tren de Aragua members

The U.S. Treasury Department has designated eight members of the Venezuelan gang Tren de Aragua (TdA) for their roles in ATM jackpotting attacks that have siphoned millions from U.S. bank and credit union machines. The list of designated individuals includes Anibal Alexander Canelon Aguirre (known as "Prometheus") and six associates named in the announcement: Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo. OFAC framed the sanctions as part of a broader, sustained enforcement effort and tied the designations to transnational criminal activity that reaches into the United States.

The ATM "jackpotting" playbook and malware families

The Treasury and OFAC described how jackpotting attacks work in operational terms: criminals install malware on ATMs to coerce machines into dispensing cash and then erase evidence using an attached USB keyboard or the ATM's built‑in PIN pad. The announcement named multiple malware families associated with these campaigns, including ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus. OFAC specifically alleges that Aguirre developed the Ploutus malware used in some of the ATM hacks.

Scale of theft and coordinated law enforcement action

OFAC estimated that, as of August 2025, Tren de Aragua members have stolen $40.73 million from U.S. financial institutions across more than 1,500 alleged ATM jackpotting attacks. The department described the Treasury's actions as "part of a sustained, whole-of-government campaign" that has produced over 30 actions targeting more than 300 individuals and entities tied to transnational criminal organizations since 2025.

The Justice Department and the FBI have also been active. Since October 2025, the U.S. Justice Department has charged 98 suspects linked to TdA and involved in ATM jackpotting schemes; the charges carry maximum prison terms ranging from 20 to 335 years per defendant. The FBI warned in February that criminals had stolen over $20 million in 2025 in a large surge of ATM hacking incidents. In early September, five Venezuelan nationals pleaded guilty after unsuccessful attempts to install malware during jackpotting attempts in Wamego and Manhattan, Kansas.

Cryptocurrency pathways: TRM Labs findings and OFAC action

Alongside personnel designations, the Treasury added cryptocurrency addresses to its Specially Designated Nationals and Blocked Persons List. TRM Labs identified seven TRON addresses that the Treasury designated; those addresses have received approximately USD 6.1 million in total inflows since March 2022 and have sent funds to other TdA-associated addresses, according to TRM's summary cited by the Treasury.

That linkage draws a direct line, in the Treasury's assessment, between cash dispensed from U.S. ATMs via malware and cross-border laundering using cryptocurrency rails tied to TdA-associated accounts.

What this means for U.S. financial institutions, law enforcement, and the Tren de Aragua network

  • U.S. banks and credit unions: The OFAC description of malware families and the use of USB keyboards or built‑in keypads to delete evidence underlines an operational threat to physical ATM security and incident response processes at affected institutions.
  • Law enforcement and prosecutors: The coordinated mix of sanctions, criminal charges (98 suspects since October 2025), and public warnings (including an FBI notice about $20 million stolen in 2025) demonstrates a multi‑front approach—sanctions, indictment, and public attribution—targeting both actors and financial conduits.
  • Tren de Aragua and transnational enablers: OFAC and TRM Labs' actions—designation of individuals, a group designation dating to July 2024, a State Department Foreign Terrorist Organization designation in February 2025, and the tagging of cryptocurrency addresses—make clear the U.S. view that TdA operates as a transnational criminal enterprise with a multi-jurisdictional money‑movement network.

The Treasury cast these measures as one piece of an ongoing campaign: "These actions form part of a sustained, whole-of-government campaign that has resulted in over 30 actions against more than 300 individuals and entities tied to transnational criminal organizations since 2025," OFAC said. The combined use of sanctions, criminal charges, and cryptocurrency blacklisting signals continued pressure on both the actors who deploy ATM malware and the financial channels that move their proceeds.

Read the original story