The U.S. Treasury has sanctioned a Tren de Aragua network accused of using malware to empty ATMs across the United States. Authorities linked the alleged attacks to $40.73 million in reported losses across more than 1,500 incidents as of August 2025.
The technique, known as jackpotting, makes cash machines dispense money without charging a customer account. Attackers typically survey machines, install malicious software, and activate it remotely.
Recent ATM jackpotting guilty pleas illustrate how criminals combine physical access with software manipulation to attempt cash theft. Analysts from TRM Labs noted that the operation also relied on cryptocurrency transactions to move stolen funds.
TRM Labs said in a report shared with Cyber Security News (CSN) that seven newly sanctioned TRON addresses had received approximately $6.1 million since March 2022.
The September 30, 2026, sanctions target eight individuals and two companies connected to the alleged scheme, plus a separate gang leader involved in illicit gold mining. The report does not identify a malware family or establish when the software first emerged.
Treasury Sanctions Tren de Aragua ATM Jackpotting Network
The Treasury’s Office of Foreign Assets Control added seven TRON addresses to its Specially Designated Nationals and Blocked Persons List. Each address is attributed to one of the designated individuals, connecting the sanctions to identifiable cryptocurrency activity rather than names alone.
The principal target is Anibal Alexander Canelon Aguirre, known as “Prometheus,” whom Treasury describes as the alleged engineer of the malware. He appears on the FBI’s Ten Most Wanted Fugitives list and allegedly helped develop software used to force unauthorized cash withdrawals.
Six alleged associates were also designated: Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo. Each is linked to one of the listed cryptocurrency addresses.
These seven individuals and an eighth designee, Aslhy Javier Galeano Basurto, face charges in Nebraska. Allegations include material support to Tren de Aragua, bank fraud conspiracy, bank burglary conspiracy, and money laundering conspiracy. The defendants remain presumed innocent unless proven guilty.
The action follows earlier ATM hacking conspiracy charges involving alleged gang financing. Treasury says the Justice Department has indicted 98 people in jackpotting schemes since October 21, 2025, while investigators identified extensive direct and indirect connections between defendants and Tren de Aragua.
The two sanctioned companies are Enigma Community, S. de R.L. de C.V., owned by Martinez Pirona, and Soluciones Integrales Toluca, S.A. de C.V., owned by Mejia Castillo. Separately, Treasury designated Juan Gabriel Rivas Nunez, known as “Juancho,” over alleged criminal activities.
Cryptocurrency Exposure
TRM found that all seven listed addresses are deposit addresses hosted at a centralized exchange. Most had been inactive for months, with the latest incoming transaction occurring in July 2026. The address attributed to Cardenas Arzola received approximately $2.1 million, the largest share.
The $6.1 million total should not be treated as confirmed jackpotting proceeds. TRM explicitly cautioned that not all incoming value necessarily relates to the ATM scheme, an important distinction when assessing the network’s financial activity and the scale of its alleged thefts.
The designated addresses also transferred funds to other addresses associated with Tren de Aragua. Those recipients subsequently sent approximately $35 million to a network authorities associate with Jorge Figueira, who faces allegations of laundering approximately $1 billion. He has not been convicted.
The wider pattern echoes cryptocurrency laundering network investigations where exchanges help move illicit value across borders.
TRM recommends screening the seven addresses, reviewing historical transactions, and checking indirect exposure through counterparties one or two transfers away from the sanctioned addresses.
Exchanges may also identify underlying account holders and related accounts because the addresses are exchange hosted.
Financial institutions should assess these connections carefully: foreign institutions knowingly facilitating significant transactions for designated persons could face secondary sanctions under the authority used for this action.
The sanctions also block designated persons’ property under U.S. jurisdiction or U.S. persons’ control, with reporting obligations to OFAC and restrictions on covered transactions.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| TRON address | TJjRAn9kLiyh8h6gjBjaYjkfDkskgZfyW9 | OFAC-designated exchange deposit address attributed to Anibal Alexander Canelon Aguirre. |
| TRON address | TCUmMCHQEbFFdGvfdg2LeS64QfzUKP2AgW | OFAC-designated exchange deposit address attributed to Eric Gabriel Cardenas Arzola. |
| TRON address | THwbVuBBb26abe5TrAsYUpYz9mhWnBppdz | OFAC-designated exchange deposit address attributed to Jose Dario Galeano Bazurto. |
| TRON address | TBEmt7kPSwAv6NJTYKNdBVW524bUfPwJpJ | OFAC-designated exchange deposit address attributed to Anthony Wuiliam Hernandez Guerrero. |
| TRON address | TCifMAMwst3oEJx8GaNfqZw75dkFUa8vjG | OFAC-designated exchange deposit address attributed to Carlos Javier Martinez Armenta. |
| TRON address | TDxZ1XTZCmqkJJW2eJT362z6omRchJyGBX | OFAC-designated exchange deposit address attributed to Oscar Leonardo Martinez Pirona. |
| TRON address | TWJmTGhquvdp1jhBmgeGxBBwefteGZUQYW | OFAC-designated exchange deposit address attributed to Alejandro Mejia Castillo. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

