Yaamlabs

Threat intel

Treasury sanctions Tren de Aragua's ATM jackpotting crew

OFAC sanctioned 10 targets behind ATM jackpotting tied to $40.73 million in US losses. How the malware works, the FBI indicators and what to check.

On September 30, 2026, the US Treasury's Office of Foreign Assets Control (OFAC) sanctioned 10 targets behind an ATM jackpotting scheme it calls a key source of revenue for Tren de Aragua (TdA), the Venezuelan gang the State Department designated a Foreign Terrorist Organization in February 2025. Jackpotting means installing malware on a cash machine so that it pays out its cash without debiting any account. Treasury puts reported US losses from these attacks at $40.73 million across more than 1,500 incidents as of August 2025.

The action names eight people, two Mexican companies and seven TRON cryptocurrency addresses, and in the same release Treasury also designated Juan Gabriel Rivas Nunez, a TdA leader it links to illicit gold mining. At its centre is Anibal Alexander Canelon Aguirre, known as "Prometheus" and "The Engineer", whom the FBI accuses of writing the malware. He was captured in Venezuela in mid-September and, according to reports published on October 2, has appeared in federal court in Nebraska and pleaded not guilty. If your organisation runs ATMs or interactive teller machines (ITMs), or moves money for customers, both the attack technique and the sanctions list apply to you.

How it works

An ATM is a Windows PC wired to a cash dispenser, a card reader and a PIN pad. The banking application does not drive that hardware directly. It goes through eXtensions for Financial Services (XFS), a middleware layer that turns "dispense four notes from cassette two" into device commands. In a normal withdrawal, the application only sends that dispense command after the bank has authorised the transaction.

The malware involved here, according to the FBI and the Justice Department, is Ploutus or a variant of it. Ploutus talks to XFS itself, so it can order the dispenser to pay out with no card, no account and no authorisation from the bank. The FBI notes that because the malware works through Windows and XFS, it runs on ATMs from different manufacturers with very little change to the code, and a cash-out can be over in minutes.

Getting it onto the machine is physical work. The FBI's February 19, 2026 FLASH alert (FLASH-20260219-001) says crews most often open the ATM's front panel with generic keys that are widely sold, then either pull the hard drive, copy the malware onto it from a laptop and put it back, or swap in a drive or external device that already carries the malware. Chainalysis and other reporting on the Nebraska case also describe small single-board computers such as Raspberry Pi devices being used in the installation. After a reboot the malware is in place, and Treasury says it is then activated remotely to push the dispense command.

None of this touches a customer account, which is why it can go unnoticed until a cassette reads empty. The FLASH lists sdelete.exe, a Microsoft tool that wipes files beyond recovery, among the files found on compromised machines, so evidence on the disk may be gone by the time someone looks.

What the network did

Treasury says the crews deployed to US ATMs were run from Mexico and Venezuela, and that the cash was passed between TdA members in several countries, with cryptocurrency used to hide where it came from. The seven sanctioned TRON addresses received about $6.1 million since March 2022, according to both TRM Labs and Scorechain. They are deposit addresses at an exchange, so exposure can sit one or two transfers away from them.

The court record adds a narrower figure. Prosecutors in Nebraska say defendants in that case committed or attempted at least 117 attacks on federally insured banks and credit unions since January 2024, with confirmed losses of at least $5.4 million. A grand jury there returned an indictment against 32 people on October 21, 2025, and a second against 22 on December 9, 2025, the same day the warrant for Canelon Aguirre was issued. Treasury says 98 people have been indicted for jackpotting since October 21, 2025; SecurityWeek reports 119, so the count depends on which cases are included.

The problem is wider than one gang. The FBI counts about 1,900 jackpotting incidents reported since 2020, and more than 700 of them, with over $20 million in losses, happened in 2025 alone.

What to do

Close the physical way in

Replace the standard locks on ATMs with ones whose keys cannot be bought online, and fit keypads that raise an alarm if no code is entered when the hatch opens, as the FBI recommends. Add vibration and temperature sensors, check that cameras cover the machine and the vestibule, and keep the footage. Treat a door-open alert outside a scheduled maintenance window as an incident.

Make a swapped drive useless

Turn on full-disk encryption so a drive taken out and written to on a laptop no longer boots cleanly, and use Trusted Platform Module (TPM) based integrity checks at boot. Whitelist USB devices so an unknown keyboard, hub or flash drive is refused, change default credentials on the ATM's Windows accounts, and allow remote connections only from known IP addresses.

Turn on the logs that catch it

The FLASH gives a sequence to alert on: USB storage inserted (event ID 6416, from Audit Removable Storage), files written (4663, from Audit File System with SACLs on the ATM application and vendor middleware folders), a new process (4688, with command-line logging on via ProcessCreationIncludeCmdLine_Enabled = 1), a service installed (4697), and the security log cleared (1102). Ship these off the machine, because an attacker with local control can wipe them.

Check whether a machine was already hit

Compare every executable and library against the vendor-approved gold image, and treat any unsigned or new binary as a compromise. Look specifically for the file names in the FLASH: Newage.exe, Color.exe, Levantaito.exe, NCRApp.exe, Promo.exe, WinMonitor.exe, WinMonitorCheck.exe, Anydesk1.exe and sdelete.exe, plus Restaurar.bat and C.dat. Check HKLM\Software\Microsoft\Windows\CurrentVersion\Run and the Winlogon Userinit value for odd entries, and look for services with names like "ATM Service" or "Dispenser Service" that run as SYSTEM without a vendor signature. Unauthorised AnyDesk or TeamViewer installs are another sign. The full indicator list, with MD5 hashes, is on IC3.

If you find a match, take the ATM out of service, image the disk before anything else, rebuild from the gold image, and report it to the FBI through IC3 with the bank, branch, ATM make and model, and the logs you have.

Screen the sanctions list

Banks, exchanges and payment firms should add the eight individuals, Enigma Community, S. de R.L. de C.V., Soluciones Integrales Toluca, S.A. de C.V. and the seven TRON addresses to screening, and review past transactions for direct or one-hop exposure. Under OFAC's 50 percent rule, any company owned half or more by these targets is blocked too.

The wider lesson

Self-service machines, kiosks and ITMs often sit outside the patching and monitoring that covers office laptops, because they are owned by facilities or a vendor. Jackpotting works because nobody is watching the USB port, the hard drive or the security log on those machines. Putting them on the same asset inventory, logging and baseline checks as the rest of the Windows estate would catch most of the steps in the FBI's list.

Our safeguarding and hardening work covers lock-down of Windows-based kiosks and terminals, and our security operations team can turn the FBI's event sequence into alerts you actually see. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: US Treasury press release, FBI FLASH-20260219-001, US Attorney's Office, District of Nebraska, Chainalysis, TRM Labs, Scorechain, The Record, ABA Banking Journal, SecurityWeek, The Crypto Times, Latin Times, WFMD, Primicias.

Back to the blog, or read this post on the full site.