Treasury Sanctions Tren de Aragua ATM Jackpotting Network
Key Takeaways The U.S. Treasury has sanctioned a network associated with the Tren de Aragua criminal organization for ATM jackpotting activities. The illicit operations have reportedly resulted in...
Key Takeaways
- The U.S. Treasury has sanctioned a network associated with the Tren de Aragua criminal organization for ATM jackpotting activities.
- The illicit operations have reportedly resulted in over $40.7 million in losses across more than 1,500 incidents in the United States as of August 2025.
- Eight individuals, including the alleged malware engineer “Prometheus,” and two companies have been designated in connection with the scheme.
- Seven TRON cryptocurrency addresses, which received approximately $6.1 million, have also been sanctioned, linking financial flows to the criminal enterprise.
- Financial institutions are advised to screen the sanctioned TRON addresses and analyze potential indirect exposure to avoid secondary sanctions.
U.S. Treasury Sanctions Tren de Aragua ATM Jackpotting Network
The U.S. Treasury Department has taken decisive action against a criminal network linked to the Venezuelan gang Tren de Aragua, accusing it of orchestrating widespread ATM jackpotting attacks across the United States. These sophisticated cyber-physical assaults, which force automated teller machines to dispense cash without legitimate transactions, have led to an estimated $40.73 million in losses from over 1,500 reported incidents by August 2025.
Table Of Content
Jackpotting involves attackers gaining physical access to ATMs to install malicious software, which is then often activated remotely to trigger unauthorized cash disbursements. Law enforcement investigations and recent guilty pleas in related cases underscore a recurring pattern where criminals combine physical intrusion with software manipulation to execute these cash thefts effectively.
A recent report by TRM Labs said in a report highlighted the critical role of cryptocurrency in these operations, noting that stolen funds were frequently moved through digital asset transactions. Seven TRON addresses, now subject to U.S. sanctions, have collectively received approximately $6.1 million since March 2022, according to TRM Labs’ analysis shared with Cyber Security News (CSN).
Details of the Sanctions
The sanctions, enacted on September 30, 2026, by the Treasury’s Office of Foreign Assets Control (OFAC), target eight individuals and two companies implicated in the ATM jackpotting scheme. An additional gang leader involved in illicit gold mining was also designated. The official report did not specify the exact malware family utilized or its initial date of emergence.
A key figure in the sanctions is Anibal Alexander Canelon Aguirre, known by the alias “Prometheus.” The Treasury Department identifies him as the alleged architect behind the malware used in these attacks. Aguirre is currently listed on the FBI’s Ten Most Wanted Fugitives list for his alleged role in developing software designed to facilitate unauthorized cash withdrawals.
Six alleged accomplices have also been designated: Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo. Each of these individuals has been linked to one of the newly sanctioned cryptocurrency addresses. These seven individuals, along with an eighth designee, Aslhy Javier Galeano Basurto, are facing charges in Nebraska, including material support to Tren de Aragua, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy. It is important to note that these individuals are presumed innocent until proven guilty.
This latest action builds upon previous charges related to ATM hacking conspiracies and alleged gang financing. Since October 21, 2025, the Justice Department has indicted 98 individuals in connection with jackpotting schemes, with investigators establishing extensive direct and indirect ties between the defendants and Tren de Aragua.
The two companies sanctioned are Enigma Community, S. de R.L. de C.V., owned by Martinez Pirona, and Soluciones Integrales Toluca, S.A. de C.V., owned by Mejia Castillo. Furthermore, Juan Gabriel Rivas Nunez, known as “Juancho,” was separately sanctioned for his alleged involvement in other criminal activities.
Cryptocurrency Exposure
TRM Labs’ investigation revealed that all seven sanctioned TRON addresses are deposit addresses hosted by a centralized exchange. Most of these addresses had been dormant for several months, with the most recent incoming transaction recorded in July 2026. Eric Gabriel Cardenas Arzola’s attributed address received the largest portion, approximately $2.1 million.
It is crucial to understand that the total of $6.1 million received by these addresses is not definitively confirmed as proceeds solely from jackpotting activities. TRM Labs explicitly cautioned that not all incoming funds necessarily relate to the ATM scheme, a distinction vital for accurately assessing the network’s financial scope and the total value of its alleged thefts.
Funds from the designated addresses were also traced to other addresses linked to Tren de Aragua. These secondary recipients subsequently transferred approximately $35 million to a network that authorities associate with Jorge Figueira, who is currently facing allegations of laundering around $1 billion. Figueira has not yet been convicted.
This broader financial pattern mirrors other cryptocurrency laundering network investigations where exchanges are exploited to facilitate the cross-border movement of illicit funds.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| TRON address | TJjRAn9kLiyh8h6gjBjaYjkfDkskgZfyW9 |
OFAC-designated exchange deposit address attributed to Anibal Alexander Canelon Aguirre. |
| TRON address | TCUmMCHQEbFFdGvfdg2LeS64QfzUKP2AgW |
OFAC-designated exchange deposit address attributed to Eric Gabriel Cardenas Arzola. |
| TRON address | THwbVuBBb26abe5TrAsYUpYz9mhWnBppdz |
OFAC-designated exchange deposit address attributed to Jose Dario Galeano Bazurto. |
| TRON address | TBEmt7kPSwAv6NJTYKNdBVW524bUfPwJpJ |
OFAC-designated exchange deposit address attributed to Anthony Wuiliam Hernandez Guerrero. |
| TRON address | TCifMAMwst3oEJx8GaNfqZw75dkFUa8vjG |
OFAC-designated exchange deposit address attributed to Carlos Javier Martinez Armenta. |
| TRON address | TDxZ1XTZCmqkJJW2eJT362z6omRchJyGBX |
OFAC-designated exchange deposit address attributed to Oscar Leonardo Martinez Pirona. |
| TRON address | TWJmTGhquvdp1jhBmgeGxBBwefteGZUQYW |
OFAC-designated exchange deposit address attributed to Alejandro Mejia Castillo. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Financial institutions and cryptocurrency exchanges should immediately screen all transactions against the seven sanctioned TRON addresses:
TJjRAn9kLiyh8h6gjBjaYjkfDkskgZfyW9,TCUmMCHQEbFFdGvfdg2LeS64QfzUKP2AgW,THwbVuBBb26abe5TrAsYUpYz9mhWnBppdz,TBEmt7kPSwAv6NJTYKNdBVW524bUfPwJpJ,TCifMAMwst3oEJx8GaNfqZw75dkFUa8vjG,TDxZ1XTZCmqkJJW2eJT362z6omRchJyGBX, andTWJmTGhquvdp1jhBmgeGxBBwefteGZUQYW. - Review historical transaction data to identify any past interactions with these addresses or associated entities.
- Assess indirect exposure by examining transactions with counterparties that are one or two transfers removed from the sanctioned addresses.
- Be aware that foreign institutions found knowingly facilitating significant transactions for designated persons could face secondary sanctions.
- Report any identified property or transactions involving designated persons to OFAC, as required by law.
- Implement robust anti-money laundering (AML) and know-your-customer (KYC) protocols, especially for accounts dealing with cryptocurrency, to detect and prevent illicit financial flows.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.