US Sanctions 10 Over ATM Jackpotting Malware Scheme Tied to Tren de Aragua
What Happened — The U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned ten individuals and companies linked to the Ploutus ATM‑jackpotting malware used by the Venezuelan criminal group Tren de Aragua. The campaign has been traced to at least 1,500 attacks that drained cash from ATMs, resulting in roughly $40 million in losses.
Why It Matters for Trust & Control Assurance
- The operation illustrates how malicious code can be introduced into third‑party hardware (ATMs) and leveraged to siphon assets, a scenario continuous control‑assurance programs are built to detect and document.
- Effective vendor‑risk management and ongoing monitoring of external service providers are essential to prove due‑diligence and maintain a defensible audit trail when illicit activity originates outside the organization.
Who Is Affected – Financial services firms that operate or service ATMs, payment‑network providers, and any organization that outsources critical point‑of‑sale hardware to third parties.
Recommended Actions –
- Map the incident to your third‑party risk‑management controls and verify that all ATM vendors are covered by a formal due‑diligence program.
- Deploy continuous monitoring of vendor‑supplied firmware and network traffic for anomalous commands that could indicate jackpotting attempts.
- Collect and retain evidence of vendor assessments, firmware integrity checks, and incident‑response logs to support audit readiness.
Source: The Record
Technical Notes – The Ploutus malware modifies ATM firmware to issue a “dispense all cash” command after a laptop is physically attached to the machine. The scheme relies on cryptocurrency laundering pipelines that span Mexico, Colombia and other Latin‑American jurisdictions. No specific CVE is associated, but the threat vector is malware installed via physical access.
Source: The Record