Skip to content

OFAC sanctions Ploutus ATM-malware network behind $40M theft

OFAC sanctioned 10 targets in a Tren de Aragua ATM 'jackpotting' network — including Ploutus developer 'Prometheus' — after $40.73M was stolen across 1,500+ US attacks.

Published 3 min read

The US Treasury's Office of Foreign Assets Control (OFAC) sanctioned 10 targets tied to a Tren de Aragua (TdA) ATM "jackpotting" operation that it says has drained $40.73 million from US financial institutions across more than 1,500 attacks as of August 2025. The action, announced September 30, names the alleged malware developer and seven cryptocurrency deposit addresses used to launder the proceeds.

Who and what was designated

Per the State Department's designation notice and OFAC's recent actions, the central figure is Anibal Alexander Canelon Aguirre, alias "Prometheus," an FBI Ten Most Wanted fugitive whom investigators tie to the malware used in the attacks — identified in court filings as Ploutus, a long-running ATM "jackpotting" family that forces cash machines to dispense their contents on command.

Also designated: a second named launderer, Juan Gabriel Rivas Nunez ("Juancho"), associates indicted in Nebraska, two Mexico-based companies, and seven TRON (TRX) deposit addresses. OFAC says the TRON addresses received roughly $6.1 million from March 2022 onward before moving funds to TdA-linked wallets.

How the scheme works

Ploutus is installed with physical access: operators surveil a target ATM, open it, and connect to the machine's internals to load the malware, which is then triggered remotely to bypass the dispenser's controls. The stolen cash is converted to cryptocurrency and routed through the now-sanctioned addresses. This is physical-access malware, not a remote CVE — the defensive story is ATM hardening and transaction monitoring, not patching.

What to do today

  1. Screen against the updated SDN list. The new entries — including the seven TRON addresses — are enforceable now. Payment processors, exchanges, and any business with OFAC obligations should pull the latest SDN data and re-run screening.
  2. Block and report the crypto indicators. Treat the sanctioned TRON addresses as blocklist entries; flag historical exposure for compliance review.
  3. If you operate ATMs or ITMs: revisit physical access controls, top-hat/dispenser tamper alarms, and anomaly detection on out-of-pattern dispense events. Ploutus-class attacks depend on unmonitored physical access.

Context

This is a financial-crime action with a cyber core: the sanctions target the malware author and the laundering rails rather than a nation-state intelligence service, but the mechanics — bespoke malware, crypto cash-out, cross-border infrastructure — are the same ones defenders track elsewhere. It also continues Treasury's pattern of pairing indictments with crypto-address designations to make the laundering layer the pressure point, the same playbook seen in this year's joint EU–UK sanctions on Russian state operators. Sanctions don't stop a fugitive from coding, but they do strand the money — and the seven TRON addresses are the part of this network that can't simply be rebuilt overnight.

Related stories