US authorities have arrested and arraigned a 50-year-old Venezuelan member of the Tren de Aragua (TdA) criminal cartel, Anibal Alexander Canelon Aguirre, on charges related to a “jackpotting” scheme that compromised ATMs with malware and caused them to dispense tens of thousands of dollars in cash. He allegedly then laundered the proceeds through Venezuelan, Mexican, and Colombian cryptocurrency networks, including the decentralized finance trading platform known as TRON.
The group, which is involved in drug trafficking, smuggling, kidnapping and ransoms, human trafficking, extortion, and other financially motivated activities, began as a prison gang but has evolved into a multinational criminal enterprise based mainly in Venezuela and Mexico. Cybercrime, experts say, is increasingly part of the cartel mix in general as a convenient and stealthy way of amassing capital to fund other nefarious activities.
“Tren de Aragua is using ATM malware as a terrorist financing tool, then moving the cash onto TRON so it looks like ordinary exchange deposits,” Ari Redbord, global head of policy at TRM Labs, a blockchain analysis firm, tells Dark Reading. “That is the same playbook we keep seeing from foreign terrorist organizations (FTOs) with on-chain infrastructure.”
A Cartel’s Cybercrime Leader
Canelon Aguirre — also known as “Prometheus” and “The Engineer” — is a leader in the cartel, and the principal architect of the Ploutus-D malware used to compromise and control the ATMs targeted in the scheme, according to the US Attorney’s Office for the District of Nebraska, which is spearheading prosecution of the group. Over the past two years, TdA hit cash machines in Latin and North America, with more than $5.1 million stolen from 117 banks and credit unions in the United States in 2024 and 2025, according to the original indictment of Canelon Aguirre and other members of the group. The TdA group is based in Mexico and Venezuela, but mostly targeted banks and credit unions in the United States.
“We are going after the entire jackpotting network, from ringleaders and malware developers to crews in the US,” Eugene Kowel, a special agent in charge with the FBI’s Omaha office, said in a statement announcing Canelon Aguirre’s capture and arraignment. “We will continue to follow the money and surge resources to arrest and apprehend TdA members and leadership.”
ATM jackpotting has been a major problem in much of Latin America, but the scheme has increasingly moved to target US financial institutions, costing $20 million in 2025. Criminal groups physically implant malware into cash machines, giving them the ability to remotely control the devices and dispense thousands of dollars to money mules, who then use the cash to buy cryptocurrency and launder the proceeds.
The US indictment attributes $5.1 million stolen between February 2024 and December 2025 to TdA, but the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) says the problem is more widespread: More than 1,500 jackpotting incidents resulted in $40.7 million stolen as of August 2025.
Tren de Aragua has made significant use of cryptocurrency for laundering the stolen cash, utilizing infrastructure created by criminal organizations in Colombia, Mexico, and Venezuela, according to a breakdown by Chainalysis, a blockchain-intelligence firm.
“The on-chain insights show us that criminal organizations are leveraging common infrastructure for laundering,” Kaitlin Martin, a senior intelligence analyst at Chainalysis, said in the company’s analysis of the group.
Designated a Terrorist Org, Captured at Sea
The Trump administration designated Tren de Aragua an FTO in February 2025, and since then, has charged 120 members, at least 73 of which are in custody, according to the US officials.
“The District of Nebraska … was the first district in the country to develop the investigation and prosecution into a larger conspiracy case, to follow the money back to Tren de Aragua and Venezuelan actors, and the first to present material support charges concerning this matter,” United States Attorney Lesley A. Woods said in a statement sent to Dark Reading. “Because the prosecution team had the evidence to indict these targets and developed expertise over time in how the crime is committed, they continued to present new defendants to their grand jury for consideration and indictment.”
In March, the FBI put Canelon Aguirre on its “Ten Most Wanted Fugitives” list — the first cybercriminal to make the list, according to authorities. The US Coast Guard captured Canelon Aguirre at sea in September, the US Attorney’s Office for the District of Nebraska confirmed.
Money flowed from Tren de Aragua to seven cryptocurrency wallets that have since been sanctioned. Source: TRM Labs
The laundering of stolen cash underscores the degree to which criminal organizations rely on cryptocurrency infrastructure. The 10 entities sanctioned by OFAC in September included seven TRON addresses, a popular decentralized cryptocurrency network. Analyzing those addresses, Chainalysis found that TdA routed money through cryptocurrency wallets that “have been used by a wide variety of illicit actors involved in drug trafficking, smuggling, and other illicit enterprises.”
The addresses also sent approximately $35 million to a network associated with a Venezuelan national, Jorge Figueira, according to an analysis by blockchain-intelligence firm TRM Labs. Figueria has been charged by the United States with laundering approximately $1 billion in illicit funds.
Malware Allows ATM Jackpotting
The Ploutus family of malware was first detected in Mexico in 2013, created to compromise and allow emptying of cash machines without an ATM card. A 2017 analysis of Ploutus-D — the “D” designates that it targets ATM models sold by Diebold — attempts to obfuscate it operations, kill security processes, dispense cash, and delete traces of itself to make analysis more difficult, according to a 2017 analysis by Google’s Mandiant.
Member of Tren de Aragua physically opened ATMs to install Ploutus malware, using the compromise to force the machines to dispense cash. Source: US DOJ
The malware also uses the Kalignite multi-ATM platform that allows it to be used on more than 40 ATM vendors’ machines and other operating systems.
The US Attorney’s Office for the District of Nebraska decline to comment on the evidence that supports their assertion that Canelon Aguirre is “the developer of the Ploutus malware.” The US Attorney indicted him on four counts, including conspiracy to commit bank fraud and to provide material support to terrorists.


