Full Report
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
Analysis Summary
# Threat Actor: Tren de Aragua (TdA)
## Attribution & Identity
* **Actor Identification:** A Venezuelan Transnational Criminal Organization (TCO) and designated Foreign Terrorist Organization (FTO).
* **Key Individuals:**
* **Anibal Alexander Canelon Aguirre** (Alias: "Prometheus"): Alleged malware developer and FBI Top Ten Most Wanted fugitive.
* **Associates:** Eric Gabriel Cardenas Arzola, Jose Dario Galeano Bazurto, Anthony Wuiliam Hernandez Guerrero, Carlos Javier Martinez Armenta, Oscar Leonardo Martinez Pirona, and Alejandro Mejia Castillo.
* **Known Associations:** Operates via a network based in Mexico and Venezuela.
## Activity Summary
The group is currently engaged in a massive surge of "ATM jackpotting" attacks across the United States. Since March 2022, the group has reportedly stolen over $40.73 million from U.S. financial institutions through more than 1,500 documented attacks. Recent activities involve the physical compromise of ATMs to install cash-dispensing malware, followed by laundering the proceeds through international networks.
## Tactics, Techniques & Procedures
* **ATM Jackpotting:** Physical access to ATM internals to compromise the hardware.
* **Malware Deployment:** Installation of specialized ATM malware via attached USB keyboards or built-in PIN pads.
* **Evidence Tampering:** Use of malware functions to delete digital footprints and logs after the theft.
* **Money Laundering:** Transferring stolen cash to TdA members in various countries via cryptocurrency and other methods.
* **MITRE ATT&CK Mapping (Inferred):**
* T1200: Hardware Additions
* T1491: Endpoint Denial of Service (via evidence deletion)
* T0853: Physical Attack (ICS/Hardware context)
## Targeting
* **Sectors:** Financial Services (Banks and Credit Unions).
* **Geography:** Primarily the United States (recent specific incidents in Wamego and Manhattan, Kansas); logistical bases in Mexico and Venezuela.
* **Victims:** Over 1,500 ATMs belonging to various U.S. financial institutions.
## Tools & Infrastructure
* **Malware Families:**
* **Ploutus** (Developed/maintained by Aguirre)
* **ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL** (Associated with ATM jackpotting activity)
* **Infrastructure:**
* **Physical:** USB Keyboards and PIN pad access.
* **Financial:** Crypto-asset addresses associated with approximately $6.1 million in inflows since 2022.
## Implications
Tren de Aragua represents an escalating threat to the U.S. financial sector. By evolving from traditional gang activity to sophisticated cyber-physical attacks, they have demonstrated the capability to inflict high-volume financial losses ($40M+). Their designation as a Foreign Terrorist Organization underscores the national security threat posed by their transnational laundering operations.
## Mitigations
* **Physical Security:** Enhance physical locking mechanisms on ATM top hats/enclosures to prevent unauthorized USB or peripheral access.
* **Hardware Integrity:** Implement "trusted boot" and BIOS protection to prevent the execution of unauthorized software from external drives.
* **Software Protection:** Use full-disk encryption and application whitelisting (Allowlisting) to prevent the installation of unsigned malware like Ploutus.
* **Monitoring:** Implement real-time alerts for ATM "out-of-service" status or hardware disconnect events that typically precede a jackpotting attempt.