Tren de Aragua (TdA) is a financially motivated transnational criminal organization originating in Venezuela. Its activities include drug trafficking, migrant smuggling, human trafficking, extortion, sexual exploitation, money laundering, and murder-for-hire. The United States designated it a Transnational Criminal Organization in July 2024 and a Foreign Terrorist Organization in February 2025. TdA-linked networks conduct malware-enabled ATM jackpotting against U.S. banks and credit unions. A network operating from Venezuela and Mexico is associated with Anibal Alexander Canelon Aguirre, also known as Prometheus. Operations involve surveying ATMs, gaining physical access to internal components, and installing malware by modifying or replacing hard drives. Ploutus malware enables attackers to bypass normal transaction authorization and command cash dispensers without debiting customer accounts. Operational roles are divided among surveillance, malware-installation, and cash-collection crews; malware self-deletion helps conceal evidence. Stolen cash is laundered through international financial networks, including cryptocurrency transactions, and transferred to members and associates. U.S. authorities linked TdA members to more than 1,500 alleged ATM jackpotting attacks and $40.73 million in reported losses through August 2025. In September 2026, the U.S. Treasury sanctioned individuals and Mexico-based companies associated with the alleged network. These operations target ATM systems and cash holdings rather than requiring theft of customer credentials.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Venezuelan criminal organization linked to malware-enabled ATM jackpotting against U.S. banks and credit unions. Its associated network operates from Mexico and Venezuela, launders stolen cash, and transfers proceeds to TdA members internationally. OFAC estimates that TdA members stole $40.73 million through more than 1,500 alleged ATM jackpotting attacks as of August 2025. The sanctions target alleged Ploutus developer Anibal Alexander Canelon Aguirre, known as Prometheus, and associates.
Conducted a large-scale ATM jackpotting operation: malware was installed on selected ATMs and remotely triggered to dispense cash without debiting accounts. U.S. authorities attribute more than 1,500 U.S. attacks and $40.73 million in losses to the group through August 2025. Proceeds were laundered through cryptocurrency and transferred to members in multiple countries.
Allegedly conducted malware-enabled ATM jackpotting operations in the United States, using physical access to install software that caused ATMs to dispense cash without debiting customer accounts. The network allegedly used cryptocurrency transactions and exchange-hosted TRON deposit addresses to move funds, and its members face allegations including bank fraud, bank burglary, money laundering, and material support to the group.
Allegedly conducted ATM jackpotting operations in the United States, combining physical access to cash machines, malware installation, remote activation for unauthorized withdrawals, and cryptocurrency transactions to move alleged proceeds.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.