Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US Treasury Department has sanctioned Anibal Alexander Canelon Aguirre, aka 'Prometheus,' the alleged developer of ATM jackpotting malware linked to the Tren de Aragua criminal network. The malware, known as Ploutus, enables attackers to remotely force ATMs to dispense cash illicitly. The network operates primarily from Mexico and Venezuela, targeting ATMs in the United States, with reported losses exceeding $40 million from over 1,500 attacks as of August 2025. Several associates and entities linked to this network have also been sanctioned and indicted. The US government has taken extensive legal and financial actions against the individuals and their cryptocurrency addresses to disrupt their operations.
AI Analysis
Technical Summary
Anibal Alexander Canelon Aguirre, identified as 'Prometheus,' is sanctioned by the US Treasury for allegedly engineering malware used in ATM jackpotting attacks associated with the Tren de Aragua (TdA) criminal group. The malware, Ploutus, is installed physically on victim ATMs after break-ins and remotely activated to bypass security and dispense cash. The network operates from Mexico and Venezuela, targeting US ATMs, laundering stolen funds including via cryptocurrency. The Treasury has designated multiple individuals, companies, and cryptocurrency addresses linked to this network, blocking their US assets and prohibiting transactions with US persons. The DOJ has indicted 119 individuals related to the conspiracy, with several already sentenced to prison terms.
Potential Impact
The malware enables attackers to forcibly dispense cash from ATMs, resulting in significant financial losses exceeding $40 million in the US from over 1,500 jackpotting incidents. The criminal network's operations span multiple countries and involve laundering stolen funds through cryptocurrency, complicating law enforcement efforts. The sanctions and indictments disrupt the network's ability to operate financially and legally within the US jurisdiction.
Mitigation Recommendations
The US government has imposed sanctions blocking property and prohibiting transactions with the blacklisted individuals, entities, and associated cryptocurrency addresses. Law enforcement continues to pursue indictments and prosecutions against network members. Organizations should ensure physical security of ATMs to prevent unauthorized access and monitor for signs of tampering. There is no direct software patch or fix for the malware itself, as the attack requires physical installation. Vigilance and cooperation with law enforcement remain key mitigations.
Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
Description
The US Treasury Department has sanctioned Anibal Alexander Canelon Aguirre, aka 'Prometheus,' the alleged developer of ATM jackpotting malware linked to the Tren de Aragua criminal network. The malware, known as Ploutus, enables attackers to remotely force ATMs to dispense cash illicitly. The network operates primarily from Mexico and Venezuela, targeting ATMs in the United States, with reported losses exceeding $40 million from over 1,500 attacks as of August 2025. Several associates and entities linked to this network have also been sanctioned and indicted. The US government has taken extensive legal and financial actions against the individuals and their cryptocurrency addresses to disrupt their operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Anibal Alexander Canelon Aguirre, identified as 'Prometheus,' is sanctioned by the US Treasury for allegedly engineering malware used in ATM jackpotting attacks associated with the Tren de Aragua (TdA) criminal group. The malware, Ploutus, is installed physically on victim ATMs after break-ins and remotely activated to bypass security and dispense cash. The network operates from Mexico and Venezuela, targeting US ATMs, laundering stolen funds including via cryptocurrency. The Treasury has designated multiple individuals, companies, and cryptocurrency addresses linked to this network, blocking their US assets and prohibiting transactions with US persons. The DOJ has indicted 119 individuals related to the conspiracy, with several already sentenced to prison terms.
Potential Impact
The malware enables attackers to forcibly dispense cash from ATMs, resulting in significant financial losses exceeding $40 million in the US from over 1,500 jackpotting incidents. The criminal network's operations span multiple countries and involve laundering stolen funds through cryptocurrency, complicating law enforcement efforts. The sanctions and indictments disrupt the network's ability to operate financially and legally within the US jurisdiction.
Defensive Guidance
The US government has imposed sanctions blocking property and prohibiting transactions with the blacklisted individuals, entities, and associated cryptocurrency addresses. Law enforcement continues to pursue indictments and prosecutions against network members. Organizations should ensure physical security of ATMs to prevent unauthorized access and monitor for signs of tampering. There is no direct software patch or fix for the malware itself, as the attack requires physical installation. Vigilance and cooperation with law enforcement remain key mitigations.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/treasury-blacklists-most-wanted-atm-malware-developer-and-his-network/","fetched":true,"fetchedAt":"2026-10-01T14:43:10.503Z","wordCount":1110}
Threat ID: 6abe717fb45efb4220452612
Added to database: 10/01/2026, 14:43:11 UTC
Last enriched: 10/01/2026, 14:43:56 UTC
Last updated: 10/01/2026, 14:48:41 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.