ThreatPaper
Financial FraudCryptocurrency & Web3MalwareHigh

Tren de Aragua ATM jackpotting: OFAC sanctions network and seven TRON addresses; 'Prometheus' arrested

By Sethu Satheesh · 6 Oct 2026 · 15 min read

Threat Actor: Tren de Aragua (TdA) · Target: U.S. financial institutions (ATM/ITM operators and banks)

Source: home.treasury.gov


Executive Summary

On September 30, 2026, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) designated a Tren de Aragua (TdA) financial network built around ATM "jackpotting" — a cyberattack that uses malware to force cash machines to dispense currency without debiting an account.1 The action added eight individuals and two Mexico-based companies tied to the jackpotting scheme to the Specially Designated Nationals and Blocked Persons List (SDN List), together with a separately designated TdA gold-mining leader, Juan Gabriel Rivas Nunez ("Juancho").12 Seven TRON (TRX) cryptocurrency addresses, each attributed to one of the designated individuals, were added to the SDN List as on-chain identifiers.23

Treasury describes the scheme as a key revenue stream for TdA, a group the U.S. Department of State designated a Foreign Terrorist Organization (FTO) on February 20, 2025 and that OFAC had earlier designated a Transnational Criminal Organization on July 11, 2024.1 According to Treasury, reported losses from alleged TdA ATM jackpotting attacks in the United States totaled $40.73 million across more than 1,500 attacks as of August 2025.1 The lead figure is Anibal Alexander Canelon Aguirre ("Prometheus," "The Engineer"), the alleged engineer of the malware, who was placed on the FBI's Ten Most Wanted Fugitives list in March 2026 — the first cyber fugitive ever added to that list.145

This is both a sanctions action and a criminal prosecution, and the two should not be conflated. Canelon Aguirre and seven co-designees were indicted in the U.S. District Court for the District of Nebraska; Rivas Nunez was indicted in the Southern District of Texas in December 2025.14 The sanctions designation is an executive measure under Executive Orders 13581 and 13224, while guilt on the criminal charges remains to be proven. Two days after the designation, on October 2, 2026, the Justice Department announced that Canelon Aguirre had been apprehended, returned to the United States, and arraigned in Nebraska, where he entered not-guilty pleas and was detained pending trial.4

The case matters on three counts: it is the first time a cyber actor has topped the FBI's most-wanted list, it marries named defendants to blockchain identifiers in a counter-terrorism sanctions action, and it exposes a gap readers routinely misread — the $40.73 million figure counts reported losses from alleged attacks as of August 2025, while the approximately $6.1 million that blockchain-intelligence firm TRM Labs traced to the seven designated wallets is a different measure (total inflows since March 2022, not all of it tied to jackpotting).13

Verification of Claims

  1. Claim: OFAC designated eight individuals, two Mexican companies and seven TRON addresses on September 30, 2026. → Verified → OFAC's press release and its Recent Actions SDN entry list all eight individuals, both entities (Enigma Community, S. de R.L. de C.V. and Soluciones Integrales Toluca, S.A. de C.V.), the separately designated Juan Gabriel Rivas Nunez, and the seven TRX addresses.12

  2. Claim: Anibal Alexander Canelon Aguirre is the engineer of the ATM jackpotting malware. → Partially verified → Treasury calls him the "alleged engineer" of the malware and DOJ alleges he developed the "Ploutus" malware; both frame it as an allegation, and he has pleaded not guilty.14

  3. Claim: TdA jackpotting caused $40.73 million in losses across more than 1,500 attacks. → Partially verified → The figure is Treasury's, expressly scoped as "reported losses from alleged ATM jackpotting attacks" in the United States "as of August 2025"; it is a reported, not independently adjudicated, total and a snapshot more than a year before the designation.1

  4. Claim: The seven designated TRON addresses received about $6.1 million. → Partially verified → TRM Labs reports approximately $6.1 million in total inflows to the seven addresses since March 2022 and states that "not all of that value is necessarily tied to the jackpotting scheme"; it is distinct from Treasury's $40.73 million loss figure.3

  5. Claim: Canelon Aguirre was apprehended and arraigned in Nebraska. → Verified → DOJ announced on October 2, 2026 that he made his initial appearance before a U.S. Magistrate Judge, entered not-guilty pleas to four counts, and was detained pending trial.4

Timeline

Date Actor Event Source
July 11, 2024 OFAC TdA designated a Transnational Criminal Organization 1
October 2024 Lincoln (NE) Police Padron and Cabrera Torrealba arrested at a jackpotting site in Nebraska 6
February 20, 2025 U.S. Dept. of State TdA designated a Foreign Terrorist Organization 1
June 24, 2025 OFAC Prior OFAC action targeting TdA leadership and support networks 1
July 17, 2025 OFAC Further OFAC action against TdA 1
October 21, 2025 DOJ Start of the period over which DOJ counts 98 jackpotting indictments 1
December 3, 2025 OFAC Further OFAC action against TdA 1
December 9, 2025 USDC-NE Federal arrest warrant issued for Canelon Aguirre 5
December 2025 USDC-NE / SDTX Canelon Aguirre indicted in Nebraska; Rivas Nunez indicted in Southern District of Texas 14
March 13, 2026 FBI Canelon Aguirre added to the Ten Most Wanted Fugitives list (first cyber fugitive) 5
June 11, 2026 USDC-NE Oddry Arnoldo Cabrera Torrealba sentenced to 78 months 6
June 25, 2026 USDC-NE Carlos Javier Padron sentenced to 78 months 6
June 26, 2026 DOJ Press release detailing sentencings and TdA links (98 indicted to date) 6
September 30, 2026 OFAC Network, two companies and seven TRON addresses designated; Juancho designated 12
October 2, 2026 DOJ Canelon Aguirre apprehended, arraigned, pleads not guilty, detained 4

Operation Anatomy

Surveillance and physical access

Treasury describes a multi-phase operation: criminal facilitators first surveil potential victim ATMs, then physically break into the machines to install malware.1 The FBI states the conspiracy deployed "numerous crews" into the United States and that the activity dates to at least January 2024.5

Malware deployment — Ploutus

DOJ names the malware family as Ploutus, a strain purpose-built for ATM jackpotting.4 Co-conspirators deployed a Ploutus variant onto ATMs in person; once installed and activated, the malware let the operators issue commands to the machine's cash-dispensing module (T1657).46

Remote activation and forced dispense

The malware is activated remotely, bypassing the ATM's security controls, after which a dispense command forces the machine to pay out until it runs empty or the operation is disrupted.14 No account is debited — the loss falls on the financial institution.1

Anti-forensics and self-deletion

DOJ's description of Ploutus details anti-analysis measures: software-protection utilities to prevent reverse-engineering and debugging (T1622, T1027.002), and routines that delete the malware from the ATM after use to conceal its deployment from the bank (T1070.004).46

Laundering and movement of proceeds

Dispensed cash is collected and laundered, including through cryptocurrency, then transferred to TdA members in multiple countries.1 TRM Labs found the seven designated TRON addresses are exchange-hosted deposit addresses that received funds from many sources and, in turn, sent value onward to other TdA-associated addresses — which ultimately moved roughly $35 million to a network U.S. authorities affiliate with Jorge Figueira, a Venezuelan national charged (not convicted) with laundering about $1 billion.3

Loading diagram...

Accused

Attribution and naming basis: Every person named here is identified because OFAC added them to the SDN List on September 30, 2026 and because U.S. prosecutors have charged them by name in federal indictments.124 Criminal charges are allegations; all charged defendants are presumed innocent unless and until proven guilty. The threat actor is the organization, Tren de Aragua, a designated FTO and TCO.1

Anibal Alexander Canelon Aguirre (aliases "Prometheus," "The Engineer"; DOB May 15, 1976; Venezuela) is the alleged engineer and developer of the Ploutus malware and an alleged principal leader of the conspiracy.14 He was added to the FBI's Ten Most Wanted Fugitives list on March 13, 2026 — described by the FBI as the first cyber fugitive and the 540th individual ever listed — with a reward of up to $1,000,000.45 A federal arrest warrant issued in the District of Nebraska on December 9, 2025, and he was indicted there in December 2025 on four counts, with the following statutory maxima stated by DOJ:45

  • Count I — Conspiracy to Commit Bank Fraud: up to 30 years.
  • Count II — Conspiracy to Commit Bank Burglary and Fraud in Connection with Computers: up to 5 years.
  • Count III — Conspiracy to Commit Money Laundering: up to 20 years.
  • Count IV — Conspiracy to Provide Material Support to Terrorists: up to 15 years.

He made his initial appearance on October 2, 2026, entered not-guilty pleas, and remains detained in the District of Nebraska pending trial.4

Co-designated associates indicted in the District of Nebraska. Carlos Javier Martinez Armenta, Alejandro Mejia Castillo, Jose Dario Galeano Bazurto, Eric Gabriel Cardenas Arzola, Oscar Leonardo Martinez Pirona, Anthony Wuiliam Hernandez Guerrero, and Aslhy Javier Galeano Basurto are, per Treasury, charged in the USDC-NE with providing material support to TdA, bank fraud conspiracy, bank burglary conspiracy, and/or money laundering conspiracy.13 Treasury states Martinez Armenta transacted directly with Hector Rusthenford Guerrero Flores ("Nino Guerrero"), the now-deceased head of TdA, and that Martinez Pirona transacted with Venezuelan entertainer Jimena Romina Araya Navarro, previously designated by OFAC for supporting TdA.1 Galeano Basurto was previously detained in the United States in 2017 on suspicion of manipulating ATMs.1

Designated companies. Enigma Community, S. de R.L. de C.V. (Tlalnepantla de Baz, Mexico) was designated as owned or controlled by Martinez Pirona; Soluciones Integrales Toluca, S.A. de C.V. (Toluca, Mexico) as owned or controlled by Mejia Castillo.12

Juan Gabriel Rivas Nunez (aliases "Juancho," "Negro Juancho," Wilson Stalyn/Starling Aponte Rodriguez; DOB October 2, 1981; Venezuela) is described by Treasury as a high-ranking TdA leader directing gold mining, narcotics exporting, and violent crime across multiple South American countries.12 He was indicted in the Southern District of Texas in December 2025 for providing material support to TdA.1

Already convicted (context). Separately from the September 30 designations, three defendants have been sentenced in the District of Nebraska for roles in the conspiracy: Carlos Javier Padron (78 months) and Oddry Arnoldo Cabrera Torrealba (78 months), who each pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer and were ordered to jointly pay $1,537,696 in restitution; and Juan Manuel Gouveia Aguilera (96 months).46

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1657 Financial Theft
T1622 Debugger Evasion
T1027.002 Obfuscated Files or Information: Software Packing
T1070.004 Indicator Removal: File Deletion

OPSEC: The malware self-deletes after use to hinder detection and forensic review, and ships with anti-debugging and software-protection measures.4 Proceeds are laundered through cryptocurrency, with value settled largely in USDT on TRON and routed through exchange-hosted deposit addresses that obscure the end beneficiaries.3

Technical Indicators

threat_actor: Tren de Aragua (TdA)
malware_family: >
  Ploutus — ATM/ITM jackpotting malware; forces the cash-dispensing module to
  pay out without debiting an account, then deletes itself to conceal use.
sanctioned_tron_addresses:  # OFAC SDN List, added 2026-09-30; attributed by OFAC and TRM Labs
  - 'TJjRAn9kLiyh8h6gjBjaYjkfDkskgZfyW9'  # Anibal Alexander Canelon Aguirre ("Prometheus")
  - 'TCUmMCHQEbFFdGvfdg2LeS64QfzUKP2AgW'  # Eric Gabriel Cardenas Arzola (largest share, ~$2.1M)
  - 'THwbVuBBb26abe5TrAsYUpYz9mhWnBppdz'  # Jose Dario Galeano Bazurto
  - 'TBEmt7kPSwAv6NJTYKNdBVW524bUfPwJpJ'  # Anthony Wuiliam Hernandez Guerrero
  - 'TCifMAMwst3oEJx8GaNfqZw75dkFUa8vjG'  # Carlos Javier Martinez Armenta
  - 'TDxZ1XTZCmqkJJW2eJT362z6omRchJyGBX'  # Oscar Leonardo Martinez Pirona
  - 'TWJmTGhquvdp1jhBmgeGxBBwefteGZUQYW'  # Alejandro Mejia Castillo
network: >
  TRON (TRX); TRM reports settled value largely in USDT. All seven are
  exchange-hosted deposit addresses, so screen direct and indirect (1-2 hop)
  exposure; the holding exchange can likely identify the account holders.
host_artifacts:
  - Ploutus malware files deleted post-execution to conceal deployment (anti-forensics)
  - anti-debugging and software-protection packing to hinder reverse-engineering
file_hashes: none disclosed
ip_addresses: none disclosed
domains: none disclosed
note: >
  OFAC and DOJ did not publish Ploutus sample hashes or C2 infrastructure.
  Crypto addresses are reproduced verbatim as published on the OFAC SDN List and
  by TRM Labs; they are not network indicators and are not defanged, since any
  alteration would make them unusable for screening.

Sanctions. OFAC designated the network on September 30, 2026 pursuant to Executive Order 13581 (as amended) and Executive Order 13224 (as amended).1 All property and interests in property of the designated persons within U.S. jurisdiction are blocked and must be reported; entities owned 50 percent or more by blocked persons are also blocked.1 Because the designations invoke E.O. 13224, foreign financial institutions that knowingly facilitate "any significant transaction" for the designated persons risk secondary sanctions, including restrictions on U.S. correspondent or payable-through accounts.13 The action builds on OFAC's July 11, 2024 TCO designation, State's February 20, 2025 FTO designation, and OFAC actions on June 24, July 17, and December 3, 2025.1

Criminal prosecution. The jackpotting conspiracy is prosecuted in the U.S. District Court for the District of Nebraska in conjunction with DOJ's Computer Crime and Intellectual Property Section and Joint Task Force Vulcan, with the FBI and HSI as lead investigative agencies.46 DOJ stated on October 2, 2026 that 120 defendants had been charged in the District of Nebraska for roles in the conspiracy, that attacks had been targeted or carried out in 47 states, the District of Columbia, and several foreign nations, and that three defendants had been sentenced.4 Treasury, citing the period since October 21, 2025, put the count at 98 individuals indicted in ATM jackpotting schemes as of its September 30 release.1 Rivas Nunez was charged in the Southern District of Texas in December 2025.1

Manhunt. The FBI listed Canelon Aguirre on its Ten Most Wanted Fugitives list on March 13, 2026 with a reward of up to $1,000,000; DOJ announced his apprehension and return to the United States on October 2, 2026.45 As of October 6, 2026, the FBI's public wanted poster for him had not yet been updated to reflect the arrest.5

Impact Assessment

  • Confirmed: OFAC designated eight individuals, two Mexican companies, and Juan Gabriel Rivas Nunez, and added seven TRON addresses to the SDN List on September 30, 2026.12
  • Confirmed: Three defendants have been sentenced in the District of Nebraska — Padron (78 months), Cabrera Torrealba (78 months), and Gouveia Aguilera (96 months); Padron and Cabrera Torrealba were ordered to pay $1,537,696 in restitution to victim banks.46
  • Reported (Treasury): $40.73 million in reported losses from alleged TdA jackpotting attacks in the United States across more than 1,500 attacks, as of August 2025.1
  • Reported (TRM Labs): approximately $6.1 million in total inflows to the seven designated addresses since March 2022 (not all tied to the scheme; the Cardenas Arzola address accounts for about $2.1 million), with onward flows of roughly $35 million to a Jorge Figueira-affiliated network.3
  • Reported (DOJ): jackpotting attacks targeted or carried out in 47 states, the District of Columbia, and several foreign nations; 120 defendants charged in the District of Nebraska as of October 2, 2026.4
  • Unknown: how much of the $40.73 million reported-loss figure is attributable specifically to the designated individuals, and how much value is ultimately recovered or forfeited.

Lessons and Defensive Recommendations

For SOC/defenders at banks and ATM/ITM operators:

  • Treat unexpected cash-dispense events with no corresponding authorized transaction as a jackpotting indicator; alert on dispense commands issued outside the normal transaction switch.
  • Harden the physical top-box of ATMs/ITMs and alarm on enclosure-open events, since the documented access vector is a physical break-in followed by local malware installation.1
  • Hunt for Ploutus-style anti-forensic behavior: binaries that delete themselves after execution and use software-protection packing or anti-debugging to resist analysis.4

For compliance, VASPs, and exchanges:

  • Screen directly against the seven designated TRON addresses and review historical exposure; because they are exchange-hosted deposit addresses, the holding exchange can likely identify the underlying account holders and related accounts.3
  • Extend screening to indirect exposure within one or two hops, as the designated addresses sent funds onward to other TdA-associated addresses.3

For leadership:

  • Do not conflate a sanctions designation with a conviction, or Treasury's $40.73 million reported-loss figure with the roughly $6.1 million of on-chain inflows traced to the wallets — they count different things over different periods.13
  • Recognize that ATM jackpotting is being treated by DOJ and Treasury as a terrorist-financing stream, which raises material-support and secondary-sanctions exposure for any institution in the payment or custody path.16

Sources

Footnotes

  1. U.S. Department of the Treasury — Treasury Sanctions Financial Network of Foreign Terrorist Organization, Tren de Aragua, After Theft of Millions from U.S. Banks — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42

  2. OFAC — Counter Terrorism and Transnational Criminal Organizations Designations; Belarus, Counter Narcotics, and Libya Designations Removals (Recent Actions, SDN List updates) — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  3. TRM Labs — Treasury Sanctions Tren de Aragua ATM Jackpotting Network, Including Seven TRON Addresses — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11

  4. U.S. Department of Justice — Apprehended Venezuelan Tren de Aragua Leader on FBI's 10 Most Wanted Fugitives List Appears in Nebraska Court Following Homeland Security Task Force Investigation — October 2, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24

  5. Federal Bureau of Investigation — Ten Most Wanted Fugitives: Anibal Alexander Canelon Aguirre — accessed October 6, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  6. U.S. Department of Justice — Two Illegal Aliens Sentenced in International ATM "Jackpotting" Conspiracy with Ties to Tren de Aragua — June 26, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10

Topics: #tren-de-aragua#ofac#atm-jackpotting#ploutus#tron#sdn-list#prometheus#fbi-ten-most-wanted#money-laundering#sanctions
Original Incident Report →

Related Research

LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.

RansomwareFinancial FraudBotnet & DDoS

Nobody was hacked. A Chinese CDN company bought the polyfill.io domain, and every site that had ever pasted the script tag started serving whatever the new owner wanted. Four months later it was redirecting phones to betting scams.

Financial FraudSupply Chain Attack

Russia's FSB-linked Star Blizzard used a new delivery technique, RedFlick, in 13 phishing campaigns affecting 100+ US and UK organizations to deploy its CosmicPulse backdoor in 2026.

State-SponsoredSocial EngineeringMalware