{"id":9396,"date":"2025-12-22T10:00:29","date_gmt":"2025-12-22T10:00:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/22\/u-s-doj-charged-54-in-connection-with-atm-hacking-attack-by-deploying-ploutus-malware\/"},"modified":"2025-12-22T10:00:29","modified_gmt":"2025-12-22T10:00:29","slug":"u-s-doj-charged-54-in-connection-with-atm-hacking-attack-by-deploying-ploutus-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/22\/u-s-doj-charged-54-in-connection-with-atm-hacking-attack-by-deploying-ploutus-malware\/","title":{"rendered":"U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware"},"content":{"rendered":"<p>    U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The U.S. Department of Justice (DOJ) has charged 54 individuals in a sweeping crackdown on a transnational cyber-physical attack network.<\/p>\n<p>The indictments, announced by U.S. Attorney Lesley A. Woods, allege a massive conspiracy involving \u201c<a href=\"https:\/\/cybersecuritynews.com\/atm-jackpotting-deploying-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">ATM jackpotting<\/a>\u201d to fund Tren de Aragua (TdA), a designated Foreign Terrorist Organization.<\/p>\n<p>The coordinated operation targeted a sophisticated criminal ring that deployed the notorious\u00a0Ploutus malware\u00a0to siphon millions of dollars from ATMs across the United States.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiPISwTy1_Lud-5sN9ua6hNS4ZcOBJuPawLAA-JzxU_l9XqwzQBTQaPKa_bxAaHVLVMT3Bk8Ysks_QYMHEiyPcw6ho_RMVXZYdmOZVDId9wUeSVb57Hvu3XpNoPmW23-VcVF6Lq1Bqc9lpmATTqNvGjc7s0eN9em7WUnLpQlhfVzlhC-K1BzfTIU7t8cU4\/s1600\/Screenshot%25202025-12-22%2520111334%2520%25281%2529.webp?ssl=1\" alt=\" location of alleged jackpotting incidents committed across the United States\"><figcaption class=\"wp-element-caption\">\u00a0location of alleged jackpotting incidents committed across the United States<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-the-ploutus-connection\"><strong>The Ploutus Connection<\/strong><\/h2>\n<p>According to court documents, the attackers utilized a variant of the <a href=\"https:\/\/cybersecuritynews.com\/atm-jackpotting-deploying-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Ploutus malware<\/a> to compromise financial institutions.<\/p>\n<p>Unlike traditional skimming attacks that steal card data, \u201cjackpotting\u201d involves physically intruding into the machine to force it to dispense cash on command.<\/p>\n<p>The indictment outlines a methodical process used by the conspirators:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Reconnaissance:<\/strong>\u00a0Teams scouted target banks and Credit Unions to assess external security measures.<\/li>\n<li>\n<strong>Physical Access<\/strong>:\u00a0Attackers physically opened the ATM\u2019s hood or door.<\/li>\n<li>\n<strong>Deployment:<\/strong>\u00a0The malware was installed by either <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\"><a href=\"https:\/\/cybersecuritynews.com\/new-nova-stealer-attacking-macos-users\/\" target=\"_blank\" rel=\"noopener\">replacing<\/a>\u00a0the ATM\u2019s hard drive with a preloaded drive or by\u00a0<\/span>connecting an external device, such as a USB drive, to the machine.<\/li>\n<li>\n<strong>Execution:<\/strong>\u00a0Ploutus issued <a href=\"https:\/\/cybersecuritynews.com\/fortiddos-os-command-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthorized commands<\/a> to the Cash Dispensing Module, causing the machine to empty its currency.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjtFQmGo_dzeTauV_AnZfqMfUCp_N8TenxcY1T1WaXQmlOtwX9Gxsb4ZFNKhchwuhkbpAehxq9WHyM5DpQriB5PvXf0eRBWUpjIZfqmdoVPyY-f-ADKr9OVACbnzTQEfGOTM83i2EUnViBR2VIn8i78OfhmMMUHayvgUOcwWP_TA0AmSdAs0Wc44pg1WPo\/s1600\/Screenshot%25202025-12-22%2520110954%2520%25281%2529.webp?ssl=1\" alt=\"depict just a few of the alleged ATM burglaries in progress\"><figcaption class=\"wp-element-caption\">A few of the alleged ATM burglaries are in progress<\/figcaption><\/figure>\n<p>The malware was also designed to delete logs to conceal the intrusion.<\/p>\n<p>Federal prosecutors allege the stolen funds were laundered to Venezuela to support TdA leadership. Including the gang\u2019s notorious head, Hector Rusthenford Guerrero Flores (a.k.a. \u201cNi\u00f1o Guerrero\u201d).<\/p>\n<p>Among those charged is Jimena Romina Araya Navarro, a Venezuelan entertainer and alleged TdA leader, accused of providing material support to the organization.<\/p>\n<p>\u201cThe Criminal Division will not tolerate networks of thieves who <a href=\"https:\/\/cybersecuritynews.com\/soundcloud-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">breach<\/a> the security of our financial system,\u201d said Acting Assistant Attorney General Matthew R. Galeotti.<\/p>\n<p>According to court <a href=\"https:\/\/www.justice.gov\/usao-ne\/pr\/tren-de-aragua-members-and-leaders-indicted-multi-million-dollar-atm-jackpotting-scheme\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">documents<\/a>, the 54 defendants face severe charges ranging from bank fraud and computer damage to providing material support to terrorists. If convicted, they face prison terms ranging from 20 to 335 years.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/atm-hackers-charged\/\">U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/atm-hackers-charged\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>U.S. DOJ Charged 54 in Connection With ATM Hacking Attack by Deploying Ploutus Malware The U.S. Department of Justice (DOJ) has charged 54 individuals in a sweeping crackdown on a transnational cyber-physical attack network. The indictments, announced by U.S. Attorney Lesley A. Woods, allege a massive conspiracy involving \u201cATM jackpotting\u201d to fund Tren de Aragua [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,129,63,1112,258],"tags":[130],"class_list":["post-9396","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security","category-cyber-security-news","category-hacking-news","category-malware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9396"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9396"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9396\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}