Executive Summary
The U.S. Treasury Department sanctioned eight members of Venezuelan gang Tren de Aragua in October 2026 for their role in sophisticated ATM jackpotting attacks that have stolen $40.73 million from U.S. financial institutions across over 1,500 incidents. Led by Anibal Alexander Canelon Aguirre ("Prometheus"), the criminal network deployed malware including Ploutus, ATMii, and GreenDispenser to force ATMs to dispense cash, then laundered proceeds through cryptocurrency addresses receiving $6.1 million in total inflows. The Treasury also designated seven TRON blockchain addresses linked to the operation, highlighting the gang's use of cryptocurrency for money laundering.
This incident demonstrates the evolving threat landscape where traditional organized crime groups increasingly leverage sophisticated malware and cryptocurrency infrastructure to target critical financial infrastructure, requiring enhanced egress security controls and blockchain transaction monitoring.
Why This Matters Now
ATM jackpotting attacks have surged dramatically with over $20 million stolen in 2025 alone, representing a critical escalation in financially-motivated cybercrime targeting physical banking infrastructure that requires immediate defensive countermeasures.
Attack Path Analysis
Tren de Aragua gang members conducted physical ATM jackpotting attacks by gaining physical access to ATMs, deploying malware like Ploutus through USB devices, escalating privileges to bypass security controls, establishing command channels for coordination, exfiltrating stolen cash and digital evidence, and causing significant financial impact across over 1,500 ATM attacks resulting in $40.73 million in losses.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Gang members gained physical access to ATM machines and deployed malware including Ploutus through USB keyboards or built-in PIN pads
Related CVEs
CVE-2017-9073
CVSS 9.8A vulnerability in Ploutus ATM malware allows attackers to execute arbitrary commands on targeted ATM systems, forcing cash dispensing without authentication.
Affected Products:
Various ATM Manufacturers Windows-based ATM Systems – Windows 7, Windows Vista, Windows XP Embedded
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Windows Command Shell
Registry Run Keys / Startup Folder
File Deletion
Data from Local System
Service Execution
Resource Hijacking
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External and Internal Penetration Testing
Control ID: 11.3
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Device Identity and Authentication
Control ID: Device Security
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GLBA Safeguards Rule – Access Controls
Control ID: 314.4(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of Tren de Aragua ATM jackpotting malware attacks, with $40.73 million stolen across 1,500+ incidents requiring enhanced egress security and threat detection capabilities.
Financial Services
Critical exposure to financial crime malware targeting automated systems, necessitating zero trust segmentation and encrypted traffic protection to prevent lateral movement and data exfiltration.
Computer/Network Security
Responsible for developing intrusion prevention systems and anomaly detection solutions to combat sophisticated ATM malware like Ploutus, requiring advanced threat intelligence and response capabilities.
Law Enforcement
Leading investigation and prosecution of 98 TdA suspects across multiple jurisdictions, requiring enhanced visibility tools and international coordination for transnational criminal organization operations.
Sources
- US sanctions Tren de Aragua gang members in ATM hacks crackdownhttps://www.bleepingcomputer.com/news/security/us-sanctions-tren-de-aragua-members-in-atm-jackpotting-crackdown/Verified
- Treasury Sanctions Members of Tren de Aragua for ATM Jackpotting Networkhttps://home.treasury.gov/news/press-releases/sb0640Verified
- FBI Adds Anibal Alexander Canelon Aguirre to Ten Most Wanted Fugitives Listhttps://www.fbi.gov/news/stories/anibal-alexander-canelon-aguirre-added-to-fbis-ten-most-wanted-fugitives-listVerified
- Treasury Sanctions Tren de Aragua ATM Jackpotting Network Including Seven TRON Addresseshttps://www.trmlabs.com/resources/blog/treasury-sanctions-tren-de-aragua-atm-jackpotting-network-including-seven-tron-addressesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would be relevant for ATM network infrastructure by constraining lateral movement between compromised systems and reducing the blast radius of coordinated attacks across multiple financial institution locations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely constrain the initial malware's ability to establish broader network connectivity beyond the directly compromised ATM system
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely reduce the scope of privilege escalation by constraining which system resources and services the compromised process could access
Control: East-West Traffic Security
Mitigation: Microsegmentation enforcement would likely constrain lateral propagation between ATM systems by blocking unauthorized east-west network flows across different financial institution networks
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely reduce the effectiveness of command coordination by providing detection capabilities for suspicious communication patterns across distributed ATM infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit the attackers' ability to exfiltrate digital evidence and maintain persistent access across the compromised ATM network infrastructure
While physical cash theft would likely still occur at directly compromised ATMs, the overall financial impact would be significantly reduced due to constrained attack scope and limited lateral propagation
Impact at a Glance
Affected Business Functions
- Automated Teller Machine Services
- Cash Dispensing Operations
- Financial Transaction Processing
- Customer Banking Services
Estimated downtime: 1 days
Estimated loss: $40,730,000
Potential exposure of ATM transaction logs, customer PIN data temporarily stored in memory, and financial institution operational data. Evidence of transactions deleted by malware to cover tracks of cash theft operations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate ATM network communications and prevent lateral movement between financial systems
- • Deploy egress security controls with policy enforcement to detect and block unauthorized cryptocurrency transactions and money laundering activities
- • Establish multicloud visibility and control systems to monitor anomalous interactions across distributed ATM networks and detect coordinated attack patterns
- • Enable encrypted traffic monitoring with high-performance encryption to secure financial data in transit between ATMs and banking infrastructure
- • Implement threat detection and anomaly response capabilities to baseline normal ATM behavior and alert on malware deployment or jackpotting attempts



