Actor Profile
This threat actor is a coordinated Venezuelan criminal group consisting of five nationals who conducted ATM jackpotting operations targeting financial institutions in the United States. The group's motivation was financial gain through direct theft of cash from automated teller machines. The defendants—Luis Alberto Velasquez-Artigas (27), Royder Adrian Figuera-Perez (29), Javier Mejia Jr. (27), Gabriel Alexjandro Corales-Garcia (33), and Italo Lizandro Corrales-Carrillo (26)—operated as a conspiracy to commit bank larceny. Their strategy specifically targeted ATMs believed to be more vulnerable to malware exploitation by design. All five pleaded guilty to conspiracy to commit bank larceny, with arrests occurring in December 2025 following failed jackpotting attempts in Kansas.
TTPs (Tactics, Techniques, Procedures)
The group employed physical access techniques to compromise ATM infrastructure. Their primary TTP involved gaining physical access to ATM internal computers to install malware capable of controlling cash dispensers (T1200: Hardware Additions). Once malware was deployed, operators used either attached USB keyboards or the built-in PIN pad to issue commands to internal cash dispensers, forcing the machines to empty money storage cassettes (T1059: Command and Scripting Interpreter). The attacks required physical presence at target locations and direct manipulation of ATM hardware. Surveillance footage captured their operational tradecraft during failed attempts in Wamego and Manhattan, Kansas, where alarm triggers and unsuccessful malware installation prevented cash theft.
Targets & Patterns
The group exclusively targeted financial services infrastructure, specifically automated teller machines in the United States. Their victim selection criteria focused on ATMs assessed as more vulnerable to malware attacks by design, suggesting pre-operational reconnaissance to identify softer targets. Geographic targeting included Kansas (Wamego and Manhattan), indicating potential regional focus or opportunistic selection based on perceived security weaknesses. The financial services sector remains the primary victim vertical, with attacks designed to directly extract cash rather than compromise customer data or conduct fraud. This targeting pattern aligns with broader ATM jackpotting trends affecting US financial institutions, where criminals seek immediate monetary return through physical theft rather than cyber-enabled financial crime.
Historical Context
This group's activities occurred during a significant surge in ATM jackpotting incidents across the United States. The FBI reported in February that criminals stole over $20 million in the previous year through such attacks. The arrests of these five defendants followed a broader law enforcement campaign targeting Tren de Aragua, a Venezuelan criminal organization linked to massive ATM jackpotting schemes deploying Ploutus malware. The Justice Department charged 87 Tren de Aragua members facing sentences ranging from 20 to 335 years. While this specific five-person group's connection to Tren de Aragua is not explicitly stated, the timing, nationality, and operational methodology suggest they operated within the same threat landscape. In January, two other Venezuelan nationals convicted of jackpotting were sentenced to deportation after imprisonment. Historical ATM jackpotting campaigns have leveraged malware families including ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.
Defensive Recommendations
- Deploy physical security controls including tamper-evident seals, intrusion detection sensors, and real-time alarm systems on ATM cabinets to detect unauthorized physical access attempts (addresses T1200: Hardware Additions)
- Implement application whitelisting and endpoint detection on ATM operating systems to prevent unauthorized malware installation and execution of cash dispenser commands
- Upgrade ATM firmware and operating systems to current versions with enhanced security features, as recommended by US Attorney's Office guidance on jackpotting prevention technology
- Install and monitor surveillance cameras with real-time alerting capabilities at ATM locations to capture operational tradecraft and enable rapid law enforcement response
- Restrict USB port access and disable unnecessary peripheral connections on ATM internal computers to prevent attackers from using external keyboards or devices to control cash dispensers
- Establish 24/7 monitoring of ATM alarm systems with immediate law enforcement notification protocols to intercept attacks in progress, as demonstrated by the successful Wamego incident response
---
# Geopolitical Context
Geopolitical Context
The prosecution of five Venezuelan nationals for ATM jackpotting attacks reflects a broader pattern of transnational cybercrime emanating from Venezuela, where economic collapse and political instability have created conditions conducive to organized criminal activity. The case appears linked to a wider Justice Department effort targeting 87 members of the Tren de Aragua criminal organization, which has been attributed to deploying Ploutus malware in a scheme that netted over $20 million in 2025. While these actors operate as criminal enterprises rather than state-sponsored groups, their activities underscore how fragile state capacity in Venezuela has enabled sophisticated criminal networks to project operations across borders. The targeting of financial infrastructure—specifically ATMs identified as vulnerable to malware—demonstrates tactical sophistication and operational coordination consistent with organized crime rather than opportunistic fraud.
State Actor Alignment
This activity is attributed to Venezuelan criminal actors, specifically members or associates of the Tren de Aragua organization, operating independently of state direction. There is no indication of Venezuelan government sponsorship or coordination. However, the scale and persistence of these operations may reflect limited law enforcement capacity or political will within Venezuela to disrupt transnational criminal networks. US federal prosecutors have pursued aggressive enforcement, with 87 Tren de Aragua members now facing charges and maximum sentences ranging from 20 to 335 years. The Justice Department's coordinated response, including deportation of convicted individuals, signals a policy priority to dismantle these networks through criminal prosecution rather than sanctions or diplomatic measures typically reserved for state-sponsored cyber activity.
Business Impacty pro region
For the United States, this campaign highlights persistent vulnerabilities in legacy ATM infrastructure and the challenge of defending widely distributed physical assets against malware-based attacks. The FBI's February warning of over $20 million in losses underscores the financial impact on US banking institutions. For Europe and other regions with aging ATM fleets, the case serves as a cautionary example: criminal networks are actively identifying and exploiting design vulnerabilities in older machines. The transnational nature of the threat—Venezuelan nationals operating across multiple US states—illustrates how migration flows and criminal diaspora networks can facilitate cross-border cybercrime. Financial institutions globally may face pressure to accelerate hardware upgrades and deploy anti-jackpotting technologies, particularly as these techniques and malware families (ATMii, Ploutus, GreenDispenser) proliferate in criminal forums.
Forecast
If Venezuelan economic and political conditions remain unstable, transnational criminal networks originating from the region are likely to continue targeting financial infrastructure in the United States and potentially expand operations to other jurisdictions with vulnerable ATM deployments. If US law enforcement sustains its current enforcement posture—evidenced by 87 pending prosecutions—some operational disruption of Tren de Aragua and affiliated groups is probable, though this may displace rather than eliminate the threat. If financial institutions fail to invest in anti-jackpotting countermeasures and hardware upgrades, as encouraged by federal prosecutors, ATM jackpotting incidents may persist at elevated levels. Conversely, if banks accelerate deployment of updated security technologies, the economic viability of these attacks may decline, potentially shifting criminal focus to alternative cash-out methods or targets.
