The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies.
Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus .
Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries.
Treasury describes the attacks as follows: “Typically, after surveilling potential victim ATMs, criminal facilitators break into victim ATMs and install malware. The malware is then activated remotely, which allows criminal facilitators to bypass the ATM’s security systems. Finally, criminal facilitators push a dispense command, forcing the ATM to dispense its currency until the machine runs out of cash or until the operation is otherwise disrupted.”
As of August 2025, reported losses from jackpotting attacks across the US totaled more than $40 million, from more than 1,500 attacks, according to the Treasury Department.
In addition to Prometheus, the Office of Foreign Assets Control (OFAC) designated seven of his alleged associates. All of them have been indicted in Nebraska on charges that include providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy.
According to blockchain intelligence firm TRM Labs , the designations include seven TRON cryptocurrency addresses linked to Prometheus and six of his associates.
The US has now blocked any property the blacklisted individuals and entities hold in the country, and US persons are generally prohibited from dealing with them. Foreign financial institutions that conduct significant transactions on their behalf risk secondary sanctions.
The Justice Department has indicted 119 people in connection with the ATM jackpotting conspiracy. Several defendants have already been sentenced. In June, Venezuelan nationals Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron each received 78 months in prison.
In August, Juan Manuel Gouveia-Aguilera was sentenced to 96 months in prison, which the DOJ said is the longest federal sentence imposed for a role in ATM jackpotting.
Related : ShinyHunters Defiant After FBI Calls on Members to Come Forward
Related : Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Related : Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Pentagon Personnel Agency Data Breach Impacts 3 Million People
OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’
Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
Zammad Zero-Days Exploited in AI-Powered DIVD Hack
500,000 Active Credentials Left Exposed on GitHub
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
Webinar: Securing AI Agents, MCPs, and AI Automations
Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.
Virtual Event: Zero Trust & Identity Strategies Summit 2026
Join as we decipher the world of zero trust and war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
