Tren de Aragua (TdA) is a Venezuelan transnational criminal organization that originated in Venezuela and has expanded operations across the Western Hemisphere. It is associated with violent organized crime including kidnappings, extortion, human smuggling and trafficking, sexual exploitation, money laundering, and drug-related activity. Reporting also links the group to politically significant violence in Chile, including the kidnapping and killing of exiled Venezuelan dissident Ronald Ojeda, allegedly carried out by members in Chile. Known aliases include TdA and Tren de Aragua (TdA). Offshoots and local structures linked to the organization include the Pirates of Aragua in Santiago, Chile. In the cyber-enabled crime space, U.S. authorities have tied Tren de Aragua to a large-scale ATM jackpotting campaign using Ploutus malware against financial institutions across the United States. Prosecutors allege the operation involved reconnaissance of ATM locations, physical intrusion into machines, installation of malware through drive replacement or removable media, anti-forensic cleanup, coordinated cash-out, and laundering of proceeds. The campaign has been described as generating millions of dollars for the organization and demonstrates an ability to combine conventional organized-crime tradecraft with technically enabled attacks on banking infrastructure. The group has shown capabilities spanning reconnaissance, physical initial access, malware-enabled post-compromise activity, cash exfiltration, money laundering, and broader criminal coercion. It has also been linked to kidnappings and extortion operations in South America. While some public claims have portrayed Tren de Aragua as a centrally directed terrorist or state-controlled entity, internal U.S. government reporting cited in the record reflects significant uncertainty about the degree of centralized command and foreign direction of its U.S.-based activity. High-confidence reporting nevertheless supports its status as a Venezuela-origin transnational criminal syndicate with international reach and involvement in both violent and cyber-enabled financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Transnational Venezuelan criminal gang allegedly involved in the kidnapping and killing of Venezuelan dissident Ronald Ojeda in Chile, with prosecutors alleging its leadership accepted payment from Venezuelan officials and tasked members in Chile to execute the operation. The group is also described as running extortion, kidnappings, smuggling routes, and victimizing Venezuelan migrants across the hemisphere.
Referenced as a Venezuelan street gang allegedly controlling the targeted apartment building and supposedly storing weapons there, though the article states this intelligence was never released or substantiated.
Referenced comparatively as a criminal organization with decentralized structure relevant to analysis of organization and attribution in violent non-state groups.
Linked to a large-scale ATM “jackpotting” operation in the United States, using Ploutus malware to force ATMs to dispense cash without bank authorization; members reportedly gained physical access to ATMs, staged malware on hard drives, and executed rapid cash-out events.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.