Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot
Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM (TL-2026-2275) is a low-severity malware campaign, first published 2026-08-31. It has no confirmed attribution, affects Unspecified (multiple ATM vendors, including Diebold Nixdorf, targeted, maps to 9 MITRE ATT&CK techniques (T1027, T1036, T1082), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-2275
- Threat ID
- TL-2026-2275
- Severity
- LOW
- Status
- RESOLVED
- Category
- MALWARE
- First published
- 2026-08-31
- Last reviewed
- 2026-08-31
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, credit unions, retail banking
- Target regions
- united states of america, Kansas, Indiana
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM
Malware and tooling: Ploutus
Five Venezuelan nationals — Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia Jr., Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo — pleaded guilty to conspiracy to commit bank larceny after driving from Indiana to Kansas in December 2025 to install jackpotting malware on ATMs in Wamego and Manhattan, intending to remotely trigger cash dispensing. Both attempts failed and surveillance footage led to the group's arrest; Velasquez-Artigas was sentenced to nine months, with the other four awaiting sentencing.
How Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM works
In December 2025, five Venezuelan nationals traveled from Indiana to Kansas with the intent to commit ATM "jackpotting" — physically installing malware on an ATM's internal hardware and then remotely issuing a command to force the machine to dispense cash without a legitimate card transaction. U.S. Attorney Ryan A. Kriegshauser stated the group "specifically target[ed] ATMs they thought were by design more vulnerable to malware." The plan called for one conspirator to physically install the malicious code on the targeted machine while the group later activated a remote command to collect the dispensed cash. Both attempts in this case failed: the installation attempt in Wamego, Kansas tripped the ATM's alarm and caused law enforcement to respond, forcing the group to abandon the site, and the attempt in Manhattan, Kansas never produced dispensed cash. Surveillance cameras captured both incidents, and the five defendants were arrested within days. All five subsequently pleaded guilty to one count of conspiracy to commit bank larceny; Luis Alberto Velasquez-Artigas was sentenced to nine months in prison, while Royder Adrian Figuera-Perez, Javier Mejia Jr., Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo await sentencing. The DOJ announced the guilty pleas on August 31, 2026.
Neither the specific malware family nor any network indicators were disclosed for this incident by prosecutors or reporting outlets, and no cash was ever successfully dispensed. The case is nonetheless one instance of a technique class the FBI has flagged as a fast-growing nationwide problem: an FBI/IC3 FLASH alert (CSA-260219, issued February 19, 2026) reported 1,900 ATM jackpotting incidents since 2020, including more than 700 incidents in 2025 alone causing over $20 million in losses. That alert describes attackers gaining physical entry by "opening an ATM face with widely available generic keys," then either removing the ATM's internal hard drive to copy malware onto it externally before reinstalling it, or swapping in a drive pre-loaded with malware, and rebooting the machine. The malware is designed to "interact directly with the ATM hardware," issuing its own commands to the eXtensions for Financial Services (XFS) middleware layer so it can bypass bank transaction-authorization software entirely and instruct the dispenser to release cash on demand. The alert names Ploutus — first observed in Mexico in 2013 and described by Google-affiliated researchers as one of the most advanced ATM malware families — as a key driver of the broader trend.
Independent technical reporting on the Ploutus family (which the FBI ties to this technique class, though it is not confirmed as the specific malware recovered in the Wamego/Manhattan attempts) documents further tradecraft relevant to the broader campaign this Kansas case belongs to: the malware is commonly packed with the commercial .NET Reactor obfuscator, applying string encryption, function-name obfuscation, method proxying, control-flow-graph obfuscation, and method-body encryption ("Necrobit") that swaps in real method bodies only at JIT-compile time to defeat static and debugger-based analysis; operators activate the malware's hidden menu locally (in one documented variant, by tapping each corner of the touchscreen five times) and issue jackpotting commands via an attached external keyboard or the ATM's own function keys using activation sequences such as "F8F1F2F3F4," while displaying a fake maintenance message on screen to mask the activity from onlookers. A related, separately prosecuted and much larger campaign — two federal indictments (October 21 and December 9, 2025) in the District of Nebraska charging 54 members of Tren de Aragua (TdA), a Venezuelan transnational criminal organization designated a Foreign Terrorist Organization by the U.S. State Department — used a Ploutus variant against the Kalignite multivendor ATM platform (targeting Diebold Nixdorf and other hardware) and is documented as gaining cabinet access via lockpicking or master/duplicate keys, deploying the payload via a pre-infected hard drive or USB device, requiring a unique 24-hour activation code entered per machine, achieving persistence by rewriting the `HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit` registry value, and then deleting logs and terminating security-monitoring processes to cover its tracks; that reporting also documents specific artifacts (filenames `AgilisConfigurationUtility.exe` and `Diebold.exe`, service name `DIEBOLDP`, and MD5 hashes `C04A7CB926CCBF829D0A36A91EBF91BD` and `5AF1F92832378772A7E3B07A0CAD4FC5`) and losses exceeding $40 million across 1,500+ confirmed ATM attacks since 2021. Public reporting on the Wamego/Manhattan case does not name a criminal organization or attribute the five Kansas defendants to Tren de Aragua or to any other named group; the two cases share nationality of defendants, general technique (physical malware installation plus a remotely/locally triggered dispense command), and rough timing, but no source establishes a direct organizational or technical link between them, and none of the file/registry/hash artifacts above are confirmed present in the Kansas incident.
MITRE ATT&CK techniques used in TL-2026-2275
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Discovery
T1082 System Information Discovery
Initial Access
T1091 Replication Through Removable Media
Execution
Persistence
T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL
Impact
defense-impairment
Affected products and versions in Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM
- Unspecified (multiple ATM vendors, including Diebold Nixdorf, targeted nationwide by this technique class) — Automated Teller Machines — Windows-based cash-dispensing terminals running XFS/Kalignite multivendor middleware
Vulnerable versions: Windows XP/7/8/10-based ATM platforms lacking hardware-tamper detection and cabinet-lock hardening
Fixed in: Not applicable — mitigation is physical/operational hardening, not a software patch, per FBI CSA-260219
Remediation for Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM
Patches
- Migrate legacy ATMs off end-of-life Windows XP/7/8 to supported, currently patched operating systems and ensure XFS middleware/firmware receives vendor security updates
Immediate actions
- Install vibration/temperature threat sensors and security cameras on ATM enclosures to detect tampering before malware installation completes
- Replace standard/generic ATM cabinet locks with unique, non-generic locks to raise the difficulty of physical access
- Audit ATM devices and change default or vendor-default credentials on ATM software and management interfaces
- Configure ATMs for automatic shutdown or lockout upon detected tampering or compromise
- Restrict access to internal ATM ports (USB, keyboard, network) and monitor for unauthorized hardware/peripheral changes
Workarounds
- Increase physical security presence and monitoring at free-standing or low-traffic ATM locations
- Ingest FBI/IC3 CSA-260219 indicators and mitigations for early detection of jackpotting activity
Longer-term hardening
- Deploy endpoint detection and response (EDR) tooling on ATM operating systems
- Enforce application and device allowlisting on ATM software stacks, and require signed software/firmware, to block unauthorized executables
- Maintain comprehensive ATM access and transaction logging for forensic review, with tamper-evident/centralized log shipping to resist on-host log deletion
- Segment ATM networks from other financial-institution IT/OT networks
- Configure real-time alerting for unusual cash-dispensing events, repeated failed service attempts, alarm activations, and unauthorized ATM cabinet access
Timeline of Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM
- A federal grand jury in the District of Nebraska returns the first of two indictments (32 defendants) charging Tren de Aragua members in a separate, larger nationwide Ploutus/Kalignite ATM jackpotting scheme — national context for the technique class this Kansas case belongs to.
- Surveillance-camera footage of both attempted thefts leads to the arrest of all five defendants within days of the incidents.
- The group also attempts to jackpot an ATM in Manhattan, Kansas; the machine never dispenses cash and the attempt fails.
- The group's malware-installation attempt on an ATM in Wamego, Kansas trips the machine's alarm, prompting a law-enforcement response and forcing the group to abandon the site; the attempt fails.
- The five defendants travel from Indiana to Kansas, in December 2025, intending to install jackpotting malware on ATMs and remotely trigger cash dispensing.
- A second federal grand jury indictment in the District of Nebraska charges an additional 22 individuals in the Tren de Aragua Ploutus/Kalignite scheme, bringing that separate case's total to 54 defendants charged since October 2025.
- The FBI, via the Internet Crime Complaint Center (IC3), issues FLASH alert CSA-260219 on malware-enabled ATM jackpotting, reporting 1,900 incidents since 2020 (700+ in 2025 alone, over $20 million in 2025 losses) and naming Ploutus as a key driver of the trend, detailing generic-key cabinet entry and hard-drive-based malware installation as the standard method.
- In a separate, unrelated Omaha, Nebraska case, Juan Manuel Gouveia-Aguilera is sentenced to eight years in prison for using Ploutus malware to steal over $3.5 million from ATMs — cited by reporting as related nationwide context, not part of the Kansas defendant group.
- Luis Alberto Velasquez-Artigas is sentenced to nine months in prison; the remaining four defendants (Figuera-Perez, Mejia Jr., Corales-Garcia, Corrales-Carrillo) await sentencing.
- The U.S. Attorney's Office for the District of Kansas announces that all five defendants have pleaded guilty to one count of conspiracy to commit bank larceny; U.S. Attorney Ryan A. Kriegshauser states the group specifically targeted ATMs believed to be more vulnerable to malware.
Sources cited for Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM
- Hackers Plead Guilty to ATM Jackpotting Attacks
- Five plead guilty in latest federal ATM jackpotting case
- FBI investigation leads five Venezuelan nationals to plead guilty to attempting to jackpot Kansas ATMs
- Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt
- Five Venezuelan Nationals Plead Guilty After Kansas ATM Jackpotting Attempts, FBI Reports 1,900 US Incidents Since 2020
- Group pleads guilty after failed ATM 'jackpotting' scheme in Kansas
- Five men plead guilty in Kansas ATM 'jackpotting' plot
- Federal Charges in ATM 'Jackpotting' Case
- Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft
- FBI Reports 1,900 ATM Jackpotting Incidents Since 2020, $20M Lost in 2025
- FBI/IC3 CSA-260219: Increase in Malware Enabled ATM Jackpotting Incidents
- U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware
- Tren de Aragua ATM Jackpotting: Ploutus Malware Exploits Kalignite Platform in $40M US Attack
- Ploutus (ATM malware profile)
- Automated Deobfuscation of Ploutus ATM Malware
More in malware
- Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain
- Access-Code-Gated Phishing Chain Delivers Vidar Infostealer via DocuSign Impersonation
- ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2
- Gigabud Android Banking Trojan Clones Banking Apps via Hidden Work Profile (Vwork/GoldFactory)
- LegionLoader Malware Distributed via Fake Cloudflare CAPTCHA Using the ClickFix Technique
Detection coverage for TL-2026-2275
As of 2026-08-31, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2275 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.