Tren de Aragua (TdA) is a Venezuelan transnational criminal organization that originated as a prison gang in the mid-2000s and expanded across the Western Hemisphere, including into the United States. Its activities include financial fraud, money laundering, drug trafficking, human trafficking, migrant smuggling, extortion, and violent crime. The United States designated the organization as a Transnational Criminal Organization in July 2024 and a Foreign Terrorist Organization in February 2025. TdA-linked criminal networks conduct malware-enabled ATM jackpotting against U.S. banks and credit unions to generate revenue. An associated network operates from Venezuela and Mexico, deploying crews to survey target ATMs, gain physical access, install malware, and collect cash. Convicted participants in the broader conspiracy installed a variant of Ploutus that issued commands directly to ATM cash-dispensing modules, forcing unauthorized cash withdrawals without debiting customer accounts. The malware incorporates anti-analysis protections and deletion functionality intended to hinder forensic investigation and conceal its deployment. Operations combine on-site access with remote malware activation and cash-dispensing commands. Jackpotting proceeds are laundered through transfers among members and associates, cryptocurrency transactions, and associated businesses, including companies in Mexico. These financial channels move proceeds internationally to support the organization. U.S. investigations have established direct and indirect connections between TdA and participants in the ATM-jackpotting conspiracy, with multiple participants convicted and sentenced. The organization’s involvement in these schemes does not establish that it originally developed the Ploutus malware family.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Venezuelan transnational criminal organization allegedly linked to a U.S. ATM-jackpotting operation using Ploutus malware. U.S. authorities allege that the operation supported the group's criminal activities and that its members helped launder stolen funds. The article attributes 117 attacks and more than $5.4 million in proceeds during February 2024–December 2025 to alleged malware architect Anibal Alexander Canelon Aguirre and his associates, rather than definitively attributing every attack to Tren de Aragua. Researchers have not verified Aguirre's alleged authorship of Ploutus.
A transnational criminal organization accused of using Ploutus malware for ATM jackpotting across 47 US states, the District of Columbia, and unspecified foreign countries. The malware forces ATMs to dispense cash without debiting accounts. The article reports the arrest of Anibal Alexander Canelon Aguirre, an alleged leader of its jackpotting operations and developer of Ploutus; he pleaded not guilty and remains detained pending trial.
A Venezuelan transnational organized crime group allegedly funded through a multimillion-dollar ATM jackpotting scheme. Anibal Alexander Canelón Aguirre, the alleged mastermind, was arrested and pleaded not guilty to charges involving computer-enabled bank fraud, money laundering, and material support to a designated terrorist organization. The article establishes an alleged financing connection, not that the group directly conducted every attack.
Venezuelan criminal organization linked to a Ploutus-based ATM jackpotting conspiracy targeting U.S. banks and credit unions. Authorities allege that participants stole more than $5.4 million between February 2024 and December 2025 and laundered proceeds into TdA-controlled accounts. The broader conspiracy reportedly targeted or conducted attacks in 47 U.S. states, the District of Columbia, and unspecified foreign countries. Alleged Ploutus developer and conspiracy leader Anibal Alexander Canelon Aguirre was arrested and identified among eight sanctioned TdA members.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.