Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
US Treasury sanctioned alleged Ploutus ATM-malware developer Anibal Canelon Aguirre and associates tied to Tren de Aragua.
The US Treasury’s OFAC sanctioned Anibal Alexander Canelon Aguirre, known as Prometheus, whom it calls the engineer of malware used in ATM jackpotting attacks linked to Tren de Aragua. OFAC also designated seven alleged associates and two Mexico-based companies; the network, based in Mexico and Venezuela, targets US ATMs. Treasury said more than 1,500 jackpotting attacks had caused over $40 million in US losses as of August 2025. The Justice Department has indicted 119 people, and several defendants have received federal sentences of 78 to 96 months.
- Prometheus is the first FBI Ten Most Wanted fugitive sought for cybercrimes.
- Crews break into ATMs, install malware, then remotely force cash dispenses.
- OFAC named seven TRON addresses tied to Prometheus and six associates.
- US persons generally cannot deal with the designated individuals or entities.
- DOJ has indicted 119 people; one defendant received a 96-month sentence.
Full article422 words · extracted from securityweek.com · click to collapse
The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies.
Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus.
Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries.
Treasury describes the attacks as follows: “Typically, after surveilling potential victim ATMs, criminal facilitators break into victim ATMs and install malware. The malware is then activated remotely, which allows criminal facilitators to bypass the ATM’s security systems. Finally, criminal facilitators push a dispense command, forcing the ATM to dispense its currency until the machine runs out of cash or until the operation is otherwise disrupted.”
As of August 2025, reported losses from jackpotting attacks across the US totaled more than $40 million, from more than 1,500 attacks, according to the Treasury Department.
In addition to Prometheus, the Office of Foreign Assets Control (OFAC) designated seven of his alleged associates. All of them have been indicted in Nebraska on charges that include providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy.
Advertisement. Scroll to continue reading.
According to blockchain intelligence firm TRM Labs, the designations include seven TRON cryptocurrency addresses linked to Prometheus and six of his associates.
The US has now blocked any property the blacklisted individuals and entities hold in the country, and US persons are generally prohibited from dealing with them. Foreign financial institutions that conduct significant transactions on their behalf risk secondary sanctions.
The Justice Department has indicted 119 people in connection with the ATM jackpotting conspiracy. Several defendants have already been sentenced. In June, Venezuelan nationals Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron each received 78 months in prison.
In August, Juan Manuel Gouveia-Aguilera was sentenced to 96 months in prison, which the DOJ said is the longest federal sentence imposed for a role in ATM jackpotting.
Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward
Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related: Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court