The alleged mastermind behind Tren de Aragua’s multimillion‑dollar ATM jackpotting operation, Anibal Alexander Canelon Aguirre, has been captured and returned to the United States to face federal charges, ending his tenure as the first cybercriminal on the FBI’s Ten Most Wanted Fugitives list.[2][3][4] The Justice Department said Aguirre, known by aliases “Prometheus” and “The Engineer,” was apprehended overseas and has now appeared in a Nebraska courtroom on charges tied to a large‑scale ATM jackpotting scheme targeting U.S. financial institutions.[2][3][4] Prosecutors and investigators allege that since at least 2024, Aguirre led an international conspiracy to steal millions of dollars from banks by forcing compromised ATMs to dispense cash without debiting any customer account.[4][12][13]
According to U.S. authorities, Aguirre served as a key architect of sophisticated malware designed to drain ATMs of cash across the United States, providing critical technical support to Tren de Aragua, a violent transnational criminal organization that grew out of a Venezuelan prison and has expanded across Latin America.[3][13][14] Treasury officials describe him as the “engineer” of customized malware used in jackpotting attacks and say he has been photographed posing with proceeds from the crime, underscoring his central role in both the technical and financial sides of the operation.[1][13][14] Investigators and court filings explain that ATM “jackpotting” attacks exploit vulnerabilities in ATM hardware and software, often through malicious code that forces machines into diagnostic or test modes to pour out cash while bypassing normal account authorization.[2][3][4]
The case against Aguirre is unfolding alongside a broader financial crackdown. In late September, the U.S. Department of the Treasury sanctioned a Tren de Aragua–linked network that allegedly used malware to loot tens of millions of dollars from ATMs across the country, identifying Aguirre as the principal target and key engineer of the scheme.[1][10][14] Treasury and law enforcement sources say criminals based in Mexico and Venezuela dispatched crews into the United States to carry out coordinated jackpotting runs, then laundered the proceeds through shell companies and cryptocurrency wallets.[1][7][14] Officials have publicly tied the network to roughly $40 million in losses and more than a thousand attacks on ATMs, highlighting the scale of the operation and the challenge facing banks and payment providers.[9][14][15] Chainalysis and other analysts have further detailed how wallets associated with the sanctioned actors helped move and obscure the stolen funds, tightening the net around Tren de Aragua’s global financial infrastructure.[7][8]
So far, U.S. government statements on the case have emphasized bespoke malware and operational tradecraft rather than specific CVE identifiers or vendor‑specific flaws, suggesting the campaign relied heavily on a mix of physical access, social engineering, and abuse of legitimate ATM management tools rather than a single, easily patched vulnerability.[1][2][3] Officials describe attackers installing or activating malicious code on targeted ATMs, sometimes via direct connection to internal ports or through compromised remote‑access channels, then triggering payout sequences while blocking transaction logs from reflecting the fraudulent withdrawals.[2][3][4] That blend of physical compromise and malware makes jackpotting particularly difficult to detect in real time, because the machines appear to be in maintenance or diagnostic modes rather than under active criminal control.[2][4]
For financial institutions, the arrest of Aguirre and the sanctions on Tren de Aragua’s network are a significant win, but they do not eliminate the risk of copycat attacks or reuse of the malware by other gangs. Defenders should treat the case as a warning to review ATM fleets for outdated operating systems, weak or unused secure‑boot configurations, and exposed maintenance interfaces that allow direct access to internal components. Banks and service providers can harden endpoints by enforcing strict physical controls around ATMs, rotating keys and credentials used for remote management, and ensuring that only cryptographically signed and vetted firmware or software updates can run on terminals. Centralized logging and real‑time monitoring for unusual ATM behavior—such as prolonged test modes, repeated high‑value withdrawals without corresponding account debits, or unexplained outages—remain essential to spotting jackpotting attempts before crews walk away with large sums.
The joint law‑enforcement and sanctions campaign against Aguirre and his associates also carries practical implications for security and compliance teams. Institutions should incorporate newly designated individuals and entities into screening and transaction‑monitoring systems, updating sanctions lists, watchlists, and risk models to flag activity tied to Tren de Aragua’s financial network.[1][7][10] Coordinating closely with law enforcement and sharing indicators related to ATM jackpotting malware, suspicious maintenance visits, and anomalous cash‑dispensing patterns can strengthen collective defenses and reduce the window of opportunity for future attacks. Even with Aguirre in custody, the technical tools and criminal infrastructure he helped build are likely to persist, making continuous vigilance and proactive hardening of ATM and payment systems critical for banks trying to stay ahead of the next wave of jackpotting campaigns.[2][3][8]
References
- Treasury Sanctions Financial Network of Foreign Terrorist …
- Apprehended Venezuelan Tren de Aragua Leader on FBI’s …
- www.justice.gov › usao-ne › prDistrict of Nebraska | Apprehended Venezuelan Tren de Aragua …
- Tren de Aragua cyber fugitive faces ATM jackpotting charges …
- OFAC Sanctions 7 Crypto Wallets Tied to FBI Most Wanted …
- OFAC Sanctions Tren de Aragua Crypto-Laundering Network
- Treasury exposes terror network Tren de Aragua’s $40M US ATM …
- Treasury Sanctions Tren de Aragua ATM Jackpotting Network …
- Kash Patel says FBI captured all 10 most wanted, including in …
- The US Blacklists Alleged Venezuelan Cyber Crime Mastermind
- U.S. sanctions Tren de Aragua network tied to multimillion-dollar ATM scheme
- ground.news › article › treasury-exposes-terrorTreasury Sanctions Tren de Aragua Network in $40.7 Million …
