The US Department of Justice has indicted 54 alleged members of the Venezuelan Tren de Aragua gang for orchestrating a widespread ATM jackpotting campaign across the United States using a variant of the Ploutus malware. The group is accused of physically tampering with ATMs at banks and credit unions, either by installing malware-laden hard drives or deploying the malware via external devices, enabling them to force machines to dispense large sums of cash. The attacks, which reportedly began in early 2024, targeted dozens of ATMs, with some financial institutions suffering losses exceeding $100,000 and at least one credit union in Nebraska losing approximately $300,000.
Authorities allege that the gang conducted reconnaissance to identify vulnerable ATMs, circumvented security features, and coordinated attacks in groups. The Justice Department estimates that at least $5.4 million was stolen by the indicted individuals, with an additional $1.4 million in attempted but unsuccessful thefts. The Ploutus malware, first observed in Mexico in 2013, specifically targets the cash-dispensing modules of ATMs, and its deployment in the US marks a significant escalation in organized cyber-enabled financial crime. US officials have labeled Tren de Aragua a "ruthless terrorist organization" and emphasized ongoing efforts to dismantle their operations and protect American financial infrastructure.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced charges against 54 individuals accused of participating in a nationwide ATM jackpotting operation tied to Tren de Aragua. The defendants allegedly used physical access and Ploutus malware to compromise ATMs, steal cash, and launder proceeds, with some also charged with providing material support to a terrorist organization.
According to the charging documents and reporting, members of Tren de Aragua began carrying out ATM jackpotting attacks in the United States by physically tampering with machines and installing Ploutus malware. The campaign allegedly stole at least $5.4 million, with additional failed attempts totaling about $1.4 million.
Ploutus, a malware family used to force ATMs to dispense cash, was first identified in Mexico. It later evolved to target multiple ATM platforms and operating systems and to erase evidence of attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.