Ploutus Malware Scheme Linked to Tren de Aragua Drained $40.7 Million From US ATMs

Elayne Johnson  - VPNs Expert
Last updated: October 2, 2026
Human Written
Share
US Authorities Link Tren de Aragua to $40 7 Million ATM Theft Scheme
Radar Rundown
  • U.S. authorities link Tren de Aragua to an alleged ATM jackpotting scheme involving more than 1,500 machines.

  • Investigators say Ploutus malware helped attackers force ATMs to dispense about $40.73 million.

  • Authorities sanctioned Anibal ‘Prometheus’ Aguirre and linked crypto addresses over alleged roles in the operation.

A Tren de Aragua-linked network allegedly used malware to drain more than $40.7 million from ATMs across the United States. According to the authorities in the United States, the operation focused on 1,500 cash machines involving a process called ATM jackpotting.

Reportedly, the U.S. Treasury Department has sanctioned a number of individuals and organizations related to the operation. The investigators were able to discover some portion of the stolen money via operations involving cryptocurrency associated with the network.

Ploutus malware turned ATMs into cash dispensers

The alleged operation relied on a malware variant called Ploutus. The malware can send unauthorized commands to an ATM’s cash dispensing system. That capability allows criminals to force a machine to release cash without a normal customer transaction. The attackers do not need to steal a customer’s card or PIN to trigger the withdrawals.

According to the U.S. Department of Justice, crews first inspected targeted ATMs. They looked for machines that they could physically access without immediately triggering security responses.

The attackers then opened parts of the machines and installed Ploutus. Investigators say they sometimes removed the original hard drive and replaced it with another drive containing the malware. In other cases, the crews used an external device to introduce the malicious software. Once the malware gained control, other members of the network could help coordinate the cash withdrawals.

Ploutus also included an anti-forensics feature. The malware could remove itself after the operation, making it harder for investigators to identify the intrusion. The DOJ says the attackers divided the stolen money among participants. The operation therefore combined technical access, physical intrusion, cash collection, and money laundering.

More than 1,500 ATM attacks linked to the scheme

The scale of the alleged operation has drawn attention from U.S. law enforcement agencies. Investigators have linked the network to at least 1,500 ATM jackpotting incidents. Those attacks produced reported losses of about $40.73 million. The figures cover incidents recorded through August 2025, according to Chainalysis.

ATM jackpotting differs from ordinary card fraud. Instead of attacking the account of a customer, criminals target the machine itself. The attackers must first gain physical access or another form of control. They then use malware to manipulate the cash dispensing functions of the ATM.

The FBI has issued a warning about the increase of jackpotting attacks. The agency has noted over 700 incidents in 2025, and losses amounted approximately $20 million in that year only. 

This statistic demonstrates why ATM security should include more than just the protection of customer accounts. Safeguarding the terminals that dispense cash also entails protecting the hardware and software, removable storage devices, and any physical access points to those terminals.

The other aspect of the Tren de Aragua case is that investigators believe that the attackers had been working as a coherent international network. This means each member performed their specific tasks regarding the ATM installations, cash collection, and wire transfers.

The most wanted list of FBI includes alleged malware mastermind

U.S. authorities have identified Anibal Alexander Canelon Aguirre, also known as ‘Prometheus,’ as a central figure in the alleged operation. The FBI placed Aguirre on its Ten Most Wanted Fugitives list earlier this year. The Treasury describes him as the alleged engineer behind the malware used in the ATM jackpotting scheme.

Authorities accuse him of leading an international conspiracy that sent crews into the United States. Those crews allegedly targeted financial institutions and generated millions of dollars through ATM thefts.

The treasury also sanctioned several associates connected to Aguirre. The action covers individuals and companies that authorities say helped support the wider operation. The case still involves accusations and legal charges. Indictments are based on accusations, and the defendants have the right to be presumed innocent until proven otherwise in a court of law.

Crypto used to move the stolen money

Investigators say the network did not rely only on physical cash to move its proceeds. Cryptocurrency also played a role in the alleged laundering operation. Chainalysis examined blockchain activity connected to the network. Its analysis found that the group used crypto wallets and stablecoins to move criminal proceeds.

The treasury has sanctioned seven cryptocurrency addresses associated with Aguirre and his associates. The sanctions target wallets that authorities connected to the alleged laundering activity.

The blockchain evidence also points to links with other laundering networks. Chainalysis found that counterparties connected to the TdA wallets had exposure to laundering operations in Mexico, Colombia, and Venezuela.

The use of cryptocurrency gave the network another channel for moving money across borders. Cryptocurrency has also featured in other major cybercrime investigations, including the Snowflake data theft campaign affecting millions.

However, blockchain transactions can also leave records that investigators can analyze. That aspect has helped authorities trace parts of the alleged financial operation. Chainalysis says its investigation identified links between the wallets, laundering networks, and the wider ATM theft scheme.

The latest sanctions show that U.S. authorities are targeting both the people behind the ATM attacks and the financial channels that handle their proceeds. The investigation also highlights how malware, physical access, and cryptocurrency can combine in a single criminal operation.

Share this article

About the Author

Elayne is a passionate tech blogger and digital security enthusiast. She has extraordinary writing and communication skills, assisting her in performing her tasks very well. She keeps educating herself about new trends in cybersecurity and educates others about it. Elayne loves learning about tech, VPNs, security, and online anonymity. In her free time, she enjoys trying new tech gadgets, watching movies, and using social media.

More from Elayne Johnson

Comments

No comments.