Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Industries
- FinanceGovernment
- Reported by
- 1 outlet
The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies.
Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus.
Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries.
Treasury describes the attacks as follows: “Typically, after surveilling potential victim ATMs, criminal facilitators break into victim ATMs and install malware. The malware is then activated remotely, which allows criminal facilitators to bypass the ATM’s security systems. Finally, criminal facilitators push a dispense command, forcing the ATM to dispense its currency until the machine runs out of cash or until the operation is otherwise disrupted.”
As of August 2025, reported losses from jackpotting attacks across the US totaled more than $40 million, from more than 1,500 attacks, according to the Treasury Department.
In addition to Prometheus, the Office of Foreign Assets Control (OFAC) designated seven of his alleged associates. All of them have been indicted in Nebraska on charges that include providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy.
Advertisement. Scroll to continue reading.
According to blockchain intelligence firm TRM Labs, the designations include seven TRON cryptocurrency addresses linked to Prometheus and six of his associates.
The US has now blocked any property the blacklisted individuals and entities hold in the country, and US persons are generally prohibited from dealing with them. Foreign financial institutions that conduct significant transactions on their behalf risk secondary sanctions.
The Justice Department has indicted 119 people in connection with the ATM jackpotting conspiracy. Several defendants have already been sentenced. In June, Venezuelan nationals Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron each received 78 months in prison.
In August, Juan Manuel Gouveia-Aguilera was sentenced to 96 months in prison, which the DOJ said is the longest federal sentence imposed for a role in ATM jackpotting.
Related: ShinyHunters Defiant After FBI Calls on Members to Come Forward
Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related: Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Originally published by SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-01 10:51 UTC
Related stories
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
The Hacker News · 2026-10-02
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
The Hacker News · 2026-10-01
- CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
Infosecurity Magazine · 2026-10-01
- ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
SANS Internet Storm Center · 2026-10-01