Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US Treasury Targets ATM Malware Network in Sanctions

US Treasury Targets ATM Malware Network in Sanctions

Posted on October 1, 2026 By CWS

The United States Treasury Department has imposed sanctions on an alleged cybercriminal responsible for crafting malware used in ATM jackpotting incidents. This individual, linked to the Tren de Aragua (TdA) gang, and his network, including two companies in Mexico, have been targeted in this crackdown.

The Hunt for ‘Prometheus’

Identified as Anibal Alexander Canelon Aguirre, or ‘Prometheus’, this individual was placed on the FBI’s Ten Most Wanted Fugitives list in March, marking a first for someone wanted due to cybercrimes. The Treasury Department identifies him as the supposed creator of malware utilized in ATM jackpotting, specifically citing the Ploutus malware often employed by TdA operatives.

The network operates from Mexico and Venezuela, primarily targeting ATMs in the United States. The illicitly obtained funds are then laundered, sometimes through cryptocurrency, and distributed to TdA members across different nations.

Details of the Cyber Attacks

The Treasury Department explains the modus operandi: criminals surveil potential ATMs, then physically breach them to install malware. This malware is remotely activated, bypassing ATM security safeguards, and a command is executed to dispense cash until the ATM is emptied or the operation is halted.

By August 2025, over 1,500 jackpotting attacks were reported in the US, causing more than $40 million in losses, according to the Treasury Department.

Legal Actions and Implications

Aside from ‘Prometheus’, seven of his alleged associates have been sanctioned by the Office of Foreign Assets Control (OFAC). These individuals face charges in Nebraska, including supporting TdA operations, conspiracy for bank fraud and burglary, and money laundering.

Blockchain intelligence firm TRM Labs has identified seven TRON cryptocurrency addresses associated with ‘Prometheus’ and his network. The US has now frozen any assets these individuals and entities possess within the country, prohibiting US citizens from engaging in transactions with them. Foreign financial entities conducting significant transactions on their behalf may face secondary sanctions.

The Department of Justice has charged 119 individuals in connection to this ATM jackpotting scheme. Sentences have been handed down, including 78-month terms for Venezuelans Oddry Arnoldo Cabrera Torrealba and Carlos Javier Padron, and a 96-month sentence for Juan Manuel Gouveia-Aguilera, the longest in federal history for ATM jackpotting involvement.

This extensive operation underscores the US government’s commitment to combating international cybercrime and safeguarding financial systems from sophisticated attacks.

Security Week News Tags:ATM jackpotting, ATM malware, Blockchain, cyber attacks, Cybercrime, Cybersecurity, FBI, financial crime, Justice Department, money laundering, Prometheus, Sanctions, Tren de Aragua, TRON cryptocurrency, US Treasury

Post navigation

Previous Post: MikroTik RouterOS Vulnerability Exposes Critical Risks
Next Post: Over 543,000 GitHub Credentials Remain Vulnerable

Related Posts

Ransomware Attack Disrupts West Pharmaceutical Services Ransomware Attack Disrupts West Pharmaceutical Services Security Week News
Critical Fixes Released for VMware Aria Operations Flaws Critical Fixes Released for VMware Aria Operations Flaws Security Week News
iOS Exploit Kit Coruna Updates Past Exploits iOS Exploit Kit Coruna Updates Past Exploits Security Week News
Israel Leverages Iran’s Surveillance for Strategic Advantage Israel Leverages Iran’s Surveillance for Strategic Advantage Security Week News
China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years China’s Salt Typhoon Hacked Critical Infrastructure Globally for Years Security Week News
Ransomware Attack Exposes Data of 170,000 at Sandhills Medical Ransomware Attack Exposes Data of 170,000 at Sandhills Medical Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TeamViewer Urges Update Due to Critical Security Flaws
  • Armadin Secures $255 Million, Now Valued at $2.5 Billion
  • OpenAI Thwarts AI Model Data Extraction by Moonshot
  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TeamViewer Urges Update Due to Critical Security Flaws
  • Armadin Secures $255 Million, Now Valued at $2.5 Billion
  • OpenAI Thwarts AI Model Data Extraction by Moonshot
  • Over 543,000 GitHub Credentials Remain Vulnerable
  • US Treasury Targets ATM Malware Network in Sanctions

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark