Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

https://www.securityweek.com/wp-content/uploads/2026/01/ATM-hacking.jpg

The US Treasury Department has sanctioned the alleged developer of malware used in ATM jackpotting attacks linked to Tren de Aragua (TdA), along with members of his network and two Mexico-based companies.

Anibal Alexander Canelon Aguirre, known as ‘Prometheus,’ was added in March to the FBI’s Ten Most Wanted Fugitives list, becoming the first person on the list wanted for cybercrimes. Treasury describes him as “the alleged engineer of the malware used in ATM jackpotting attacks.” TdA typically uses the malware named Ploutus.

Canelon Aguirre’s network is based in Mexico and Venezuela but targets ATMs in the United States. The stolen cash is laundered, including through cryptocurrency, and moved to TdA members in various countries.

Treasury describes the attacks as follows: “Typically, after surveilling potential victim ATMs, criminal facilitators break into victim ATMs and install malware. The malware is then activated remotely, which allows criminal facilitators to bypass the...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE