HomeSecurityATM Jackpotting gang members convicted for attacks with Ploutus malware

ATM Jackpotting gang members convicted for attacks with Ploutus malware

One of the largest cybercrime casesrelated to ATM Jackpotting attacksin the United Stateshas reached its judicial conclusion, with two Venezuelan nationals sentenced to many years in prison for their participation in an organized network that used the Ploutus malware to automatically empty cash withdrawal machines.

Article Image: ATM Jackpotting Gang Members Sentenced for Ploutus Malware Attacks

US authorities are talking about a well-organized criminal enterprise with international operations, which caused damages exceeding $1.5 million and is linked to a much broader network of financial cybercrime.

Prison sentences for the two defendants

Carlos Javier Padron, 36 , and Oddry Arnoldo Cabrera Torrealba, 37, were found guilty of conspiracy to commit bank fraud and computer fraud, after previously pleading guilty to the charges against them.

The federal court sentenced each to 78 months in prison, while also deciding that the two men must jointly pay $1,537,696 in restitution to the financial institutions affected by the attacks.

See also: FBI reports 1,900 ATM Jackpotting incidents since 2020

How the Ploutus malware worked

According to the evidence in the case file, the two defendants had undertaken the physical installation of a variant of the malware Ploutus on targeted ATMs in various states in the US.

Ploutus is considered one of the most well-known malware designed specifically to attack ATMs. Rather than attempting to steal bank card details or personal data, its goal is to gain direct control of the cash dispensing system.

Once installed in the ATM, attackers can send special commands to the cash dispensing unit, causing the machine to release large amounts of money without a legitimate banking transaction taking place.

At the same time, the malware was designed to erase traces of its presence after the attack was completed, significantly hindering investigations by banks and authorities.

The arrest that exposed the entire network

The two men were arrested in October 2024 by the Lincoln Police Department while carrying out a jackpotting attack on an ATM.

This particular arrest was the starting point of a much larger federal investigation, which revealed that behind the attacks was an extensive criminal network with dozens of accomplices.

See also: 8220 Gang exploits Oracle WebLogic Server vulnerability to spread malware

To date, US authorities have indicted another 96 people for offenses such as bank fraud, money laundering, illegal access to protected information systems, wire fraud and participation in organized criminal activity.

ATM jackpotting - SecNews.gr

Tren de Aragua under the microscope

Investigators claim that several members of the organization had direct or indirect connections to Tren de Aragua, one of Venezuela's most notorious criminal organizations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This particular organization has expanded its activities in recent years to many countries in the Western Hemisphere and, according to law enforcement authorities, is involved in drug trafficking, illegal arms trafficking, kidnappings, extortion, human trafficking, and large-scale financial fraud.

US authorities believe that jackpotting attacks on ATMs have become another source of revenue for the criminal network, now utilizing sophisticated cybercrime techniques instead of traditional robberies.

What is ATM Jackpotting?

Jackpotting attacks are one of the most dangerous forms of financial cybercrime. Unlike phishing attacks or card theft, perpetrators gain physical access to the ATM and install malware directly into its operating system.

Then, through special devices or even mobile phones that communicate with the malware, they activate automatic cash disbursement within seconds.

See also: “8220 Gang” exploits Oracle WebLogic Server for cryptocurrency mining

In recent years, ATM manufacturers have significantly strengthened security measures, however, cybercriminals are constantly evolving their techniques, exploiting older operating systems or inadequate physical protection of the machines.

ATM Jackpotting gang members convicted for attacks with Ploutus malware

Investigations continue

The US Department of Justice described the disruption of the network as particularly important for protecting the banking system, emphasizing that criminal organizations are now increasingly relying on technological attacks to finance their activities.

The case was investigated by the FBI, the Homeland Security Intelligence Service (HSI), and dozens of federal, state, and local law enforcement agencies. Although the two main defendants have already been convicted, investigations into the broader network are ongoing, with authorities estimating that additional arrests may occur in the near future.

This case is yet another reminder that cybercrime is no longer limited to stealing personal data. Today, organized crime groups are leveraging specialized malware to target critical financial infrastructure, causing millions of dollars in damage in a short period of time.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS