The US Treasury has sanctioned Anibal Alexander Canelon Aguirre, the alleged developer of Ploutus used in Tren de Aragua ATM jackpotting, along with seven associates and two Mexico-based companies. Treasury says he was also added to the FBI’s Ten Most Wanted list, making him the first person on it wanted for cybercrimes.
Treasury describes the attack chain as a break-in, malware install, remote trigger, and cash dispense. Criminals first plant the malware inside an ATM, then activate it later so the machine follows its normal control path and spits out cash while its own security checks are bypassed; the stolen money is then laundered through cryptocurrency and cross-border entities.
For banks, ATM operators, and sanctions teams, the change is that the case now reaches beyond cash-out crews and laundering fronts to the malware author and his network. If those links are real, the enforcement pressure can land on the tooling and facilitators that keep jackpotting running, not only on the ATMs that get hit.
US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.