The US has announced new sanctions for a network that allegedly forced ATMs to dispense cash through malware. The method, known as jackpotting, is linked by the US Treasury Department to Tren de Aragua (TdA), while the announcement also describes the route of the stolen money.

The Office of Foreign Assets Control (OFAC) announced that it has imposed sanctions on 10 targets of the Tren de Aragua network. The announcement clarifies that the targets include individuals and companies, while also separately naming a high-ranking leader of the organization for other activity.
At the center of the announcement is Venezuelan Anibal Alexander Canelon Aguirre, known as “Prometheus.” OFAC claims he designed the malware used in the attacks and says he is wanted by the FBI. The agency details the individuals and companies added to the sanctions list.
How malware attacks work
In this technique, attackers gain access to the inside of an ATM and install malicious software. The installation allows for remote activation and bypass of security mechanisms, allowing the machine to dispense banknotes without charging a customer's account.
According to OFAC's description, the teams first locate and monitor potential target machines. People on site open the ATM and install the software. Once activated, the perpetrators send a cash withdrawal command and continue until the machine is empty or the business is disrupted.
After the money was issued, the network allegedly transferred the proceeds between members and associates of Tren de Aragua to conceal their origin. OFAC says that cryptocurrency transactions were also used in this process. These allegations are part of the justification for the sanctions and the broader investigation by US authorities.
See also: How to protect banks from ATM Jackpotting?
The sanctions cover individuals and companies of Tren de Aragua
OFAC says the 10 targets of the Tren de Aragua network include Aguirre, his associates and two Mexico-based businesses, Enigma Community and Soluciones Integrales Toluca. The agency also announced separate sanctions on Juan Gabriel Rivas Nunez, known as “Juancho,” whom it describes as a TdA leader who allegedly directs operations in South American countries.
US authorities claim the network has siphoned millions of dollars from financial institutions. OFAC reports that, as of August 2025, recorded losses from alleged jackpotting attacks in the US amounted to $40.73 million, across more than 1,500 incidents.
The Treasury Department's announcement states that 98 people have been charged with participating in jackpotting cases as of October 21, 2025. In a previous update in February, the U.S. Department of Justice announced that the number of people charged had reached 93. The numbers refer to criminal prosecutions, not convictions.

The indictment charges the defendants with offenses including bank fraud, bank robbery, money laundering and unauthorized access to protected computers. The Justice Department emphasizes that the charges are allegations and that the defendants are presumed innocent until proven guilty in court.
See also: Kansas jackpotting attempts: Five convictions for ATMs
What remains unclear about malware
OFAC attributes Aguirre’s role as an engineer of the software allegedly used in the Tren de Aragua network attacks, but the statement did not name a specific malware family or publish a technical analysis. The distinction is important, as claims about the identity of an attacker and the technical performance of a tool are not the same kind of evidence.
Recorded Future News notes that experts have not identified a connection between the Ploutus malware family and Aguirre or Tren de Aragua. The publication reports that authorities attribute the network's use of malware for jackpotting, but notes that no public ties have been identified between the Ploutus family and the individuals named.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

OFAC says that the assets of the targeted individuals and companies located in the United States or under the control of U.S. persons are frozen. At the same time, transactions with the specified individuals are generally prohibited, unless there is a relevant license or exemption. The sanctions have economic and legal impact, but do not constitute a criminal conviction.
For banks, the case highlights that attacks on ATMs can combine physical access and remote activation of malware. The announcement also highlights how cash theft can be linked to cross-border money laundering.
See also: ATM Jackpotting gang members convicted of Ploutus attacks
The sanctions announcement adds a new financial dimension to the investigation into jackpotting attacks in the U.S. The outcome of the criminal cases and the technical evidence presented in court will determine how strongly the allegations about the operation, financing and performance of the activity at Tren de Aragua are substantiated.
