← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

OFAC Sanctions Tren de Aragua for ATM Jackpotting; Threat Actors Use Blockchains for Malware

🔄 Updated 19h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • OFAC sanctioned 10 individuals for Tren de Aragua ATM jackpotting.
  • The scheme stole $40.73 million from U.S. financial institutions.
  • Cryptocurrency was used to launder the jackpotting proceeds.
  • Threat actors use public blockchains (EtherHiding) to hide malware instructions.

OFAC Sanctions Tren de Aragua for ATM Jackpotting

The U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned 10 targets linked to a Tren de Aragua ATM jackpotting scheme. This operation stole at least $40.73 million from U.S. financial institutions. Tren de Aragua is designated as a Foreign Terrorist Organization.

The group used Ploutus malware for jackpotting attacks, forcing ATMs to dispense cash. Reported losses from over 1,500 alleged attacks reached $40.73 million as of August 2025. The network laundered proceeds using cryptocurrency, with seven designated crypto wallet addresses receiving approximately $6.1 million in inflows since March 2022.

Blockchain Used for Malware Concealment

Cyber threat actors are employing public blockchains to hide malware instructions, a method known as EtherHiding or Blockchain Dead Drops (BDD). This technique complicates efforts to seize or take down the malicious code.

Chainalysis reported that North Korean and Iranian-state operators are developing distinct blockchain dead drop techniques. BDDs have increased by 440% since the introduction of Chinese high-capacity open-source AI models.

Implications for Financial Crime and Cybersecurity

The OFAC sanctions demonstrate a focus on disrupting both the perpetrators and financial facilitators of terrorist financing, particularly when cryptocurrency is involved. The use of blockchains for malware concealment presents a new challenge for cybersecurity, as the decentralized nature of these platforms makes traditional takedown methods less effective.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The U.S. Treasury's OFAC sanctioned 10 individuals involved in a Tren de Aragua ATM jackpotting scheme that stole over $40 million from U.S. financial institutions, with proceeds laundered via cryptocurrency. Separately, cyber threat actors are using public blockchains, a technique called EtherHiding or Blockchain Dead Drops, to conceal malware instructions, making takedowns difficult.