The U.S. Treasury Department sanctioned eight alleged Tren de Aragua (TdA) members, two Mexico-based companies, and seven TRON cryptocurrency addresses over an ATM-jackpotting operation that allegedly stole more than $40 million from U.S. banks. Treasury said the Mexico- and Venezuela-based network used custom malware to force ATMs and interactive teller machines to dispense cash without debiting accounts, causing reported losses of $40.73 million in more than 1,500 attacks through August 2025. Among those designated is alleged malware developer and FBI Top Ten fugitive Anibal Alexander Canelon Aguirre, known as “Prometheus,” as well as alleged senior TdA leader Juan Gabriel Rivas Nunez.
Authorities said the group laundered cash-out proceeds through complex cryptocurrency channels to TdA leadership. The seven sanctioned exchange-hosted TRON deposit addresses received approximately $6.1 million from March 2022 and transferred funds onward to TdA-linked wallets. The designations, issued under Executive Orders 13581 and 13224, block U.S.-linked property interests and create secondary-sanctions exposure for foreign financial institutions that knowingly facilitate significant transactions for the listed parties. The Justice Department has indicted 98 people in the alleged nationwide conspiracy since October 2025 on charges including bank fraud, bank burglary, money laundering, and material support.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
OFAC sanctioned eight individuals, two Mexico-based companies, and seven TRON addresses for their alleged involvement in a TdA ATM-jackpotting and money-laundering network. The action identified alleged malware developer Anibal Alexander Canelon Aguirre, alias Prometheus, as its primary target and also sanctioned alleged senior TdA leader Juan Gabriel Rivas Nunez.
The FBI added Aníbal Alexander Canelón Aguirre, also known as Prometheus, to its Ten Most Wanted Fugitives list. The FBI described him as its first alleged cybercriminal on the list and offered up to $1 million for information leading directly to his arrest.
Juan Gabriel Rivas Nunez, also known as Juancho, was indicted in the Southern District of Texas on an alleged charge of providing material support to Tren de Aragua.
The Department of Justice began indicting suspects in an alleged cross-country TdA-linked ATM-jackpotting conspiracy. Authorities had indicted 98 individuals on charges including material support, bank fraud, bank burglary, and money laundering.
The U.S. Department of State designated TdA as a Foreign Terrorist Organization.
OFAC designated Tren de Aragua (TdA) as a Transnational Criminal Organization.
The seven TRON deposit addresses later sanctioned by OFAC collectively began receiving cryptocurrency inflows in March 2022. TRM Labs identified roughly $6.1 million in inflows to the addresses, though it noted that not all funds were necessarily related to ATM jackpotting.
Treasury stated that Jose Dario Galeano Bazurto, later identified as an alleged associate in the TdA-linked scheme, was detained in the United States on suspicion of manipulating ATMs.
Treasury reported that alleged TdA-linked malware attacks made U.S. ATMs and interactive teller machines dispense cash without account debits. The attacks had caused $40.73 million in reported losses across more than 1,500 incidents as of August 2025.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
occrp.org
Open sourcethedefiant.io
Open sourcechainalysis.com
Open sourcefoxbusiness.com
Open sourcetrmlabs.com
Open sourcefbi.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.