[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSaod91NHPhP3xG4NIirFDsjoo21hGKEifleaGHdwRws":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"097b93d0-9ac4-4e15-bccc-cf31287f20e1","Treasury Blacklists Most-Wanted ATM Malware Developer and His Network","treasury-blacklists-most-wanted-atm-malware-developer-and-his-network-5c3d1e","The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted ATM Malware Developer and His Network appeared first on SecurityWeek.","The US Treasury Department has sanctioned Anibal Alexander Canelon Aguirre, known as 'Prometheus,' the alleged developer of the Ploutus ATM jackpotting malware, along with seven associates and two Mexico-based companies. Aguirre was recently added to the FBI's Ten Most Wanted Fugitives list for cybercrimes. The sanctions aim to disrupt the financial network supporting Tren de Aragua's ATM jackpotting schemes, which have caused over $40 million in losses across the US. The operation typically involves physically accessing ATMs, installing malware, and remotely triggering cash dispensing.","US Treasury sanctions ATM malware developer and network linked to Tren de Aragua.","The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies. Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus. Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries. Treasury describes the attacks as follows: “Typically, after surveilling potential victim ATMs, criminal facilitators break into victim ATMs and install malware. The malware is then activated remotely, which allows criminal facilitators to bypass the ATM’s security systems. Finally, criminal facilitators push a dispense command, forcing the ATM to dispense its currency until the machine runs out of cash or until the operation is otherwise disrupted.” As of August 2025, reported losses from jackpotting attacks across the US totaled more than $40 million, from more than 1,500 attacks, according to the Treasury Department. In addition to Prometheus, the Office of Foreign Assets Control (OFAC) designated seven of his alleged associates. All of them have been indicted in Nebraska on charges that include providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy.Advertisement. Scroll to continue reading. According to blockchain intelligence firm TRM Labs, the designations include seven TRON cryptocurrency addresses linked to Prometheus and six of his associates. The US has now blocked any property the blacklisted individuals and entities hold in the country, and US persons are generally prohibited from dealing with them. Foreign financial institutions that conduct significant transactions on their behalf risk secondary sanctions. The Justice Department has indicted 119 people in connection with the ATM jackpotting conspiracy. Several defendants have already been sentenced. In June, Venezuelan nationals Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron each received 78 months in prison. In August, Juan Manuel Gouveia-Aguilera was sentenced to 96 months in prison, which the DOJ said is the longest federal sentence imposed for a role in ATM jackpotting. Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon Related: Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog Latest News Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion ValuationZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityGoogle Launches Gemini 4 Argon With Guardrail-Free Access for Vetted DefendersFTC is Investigating OpenAI and Anthropic Over Possible Risks to ConsumersGoogle: AI Is Changing the Pace and Profile of Vulnerability DiscoveryWatchGuard Patches Critical Fireware OS Code Injection Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveQuantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Ftreasury-blacklists-most-wanted-atm-malware-developer-and-his-network\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F01\u002FATM-hacking.jpg","2026-10-01T10:51:39+00:00","2026-10-01T12:00:19.249389+00:00",8,[18,21,23,26,29,31],{"name":19,"type":20},"Tren de Aragua","threat_actor",{"name":22,"type":20},"Prometheus",{"name":24,"type":25},"Ploutus","product",{"name":27,"type":28},"FBI","vendor",{"name":30,"type":28},"US Treasury Department",{"name":32,"type":28},"TRM Labs","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":33,"icon":35,"name":36,"slug":37},null,"Nation-state","nation-state",[39,41,46,51],{"category":40},{"id":33,"icon":35,"name":36,"slug":37},{"category":42},{"id":43,"icon":35,"name":44,"slug":45},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":45,"value":24,"context":58},"Malware used in ATM jackpotting attacks."]