Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot — Threadlinqs Intelligence
As of 2026-09-01, Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot is a low-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-2275 · Severity: LOW · Status: RESOLVED · Category: MALWARE
Five Venezuelan nationals — Luis Alberto Velasquez-Artigas, Royder Adrian Figuera-Perez, Javier Mejia Jr., Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo — pleaded guilty to
In December 2025, five Venezuelan nationals traveled from Indiana to Kansas with the intent to commit ATM "jackpotting" — physically installing malware on an ATM's internal hardware and then remotely issuing a command to force the machine to dispense cash without a legitimate card transaction. U.S. Attorney Ryan A. Kriegshauser stated the group "specifically target[ed] ATMs they thought were by design more vulnerable to malware." The plan called for one conspirator to physically install the malicious code on the targeted machine while the group later activated a remote command to collect the dispensed cash. Both attempts in this case failed: the installation attempt in Wamego, Kansas tripped the ATM's alarm and caused law enforcement to respond, forcing the group to abandon the site, and the attempt in Manhattan, Kansas never produced dispensed cash. Surveillance cameras captured both incidents, and the five defendants were arrested within days. All five subsequently pleaded guilty to one count of conspiracy to commit bank larceny; Luis Alberto Velasquez-Artigas was sentenced to nine months in prison, while Royder Adrian Figuera-Perez, Javier Mejia Jr., Gabriel Alexjandro Corales-Garcia, and Italo Lizandro Corrales-Carrillo await sentencing. The DOJ announced the guilty pleas on August 31, 2026.
Neither the specific malware family nor any network indicators were disclosed for this incident by prosecutors or reporting outlets, and no cash was ever successfully dispensed. The case is nonetheless one instance of a technique class the FBI has flagged as a fast-growing nationwide problem: an FBI/IC3 FLASH alert (CSA-260219, issued February 19, 2026) reported 1,900 ATM jackpotting incidents since 2020, including more than 700 incidents in 2025 alone causing over $20 million in losses. That alert describes attackers gaining physical entry by "opening an ATM face with widely available generic keys," then either removing the ATM's internal hard drive to copy malware onto it externally before reinstalling it, or swapping in a drive pre-loaded with malware, and rebooting the machine. The malware is designed to "interact directly with the ATM hardware," issuing its own commands to the eXtensions for Financial Services (XFS) middleware layer so it can bypass bank transaction-authorization software entirely and instruct the dispenser to release cash on demand. The alert names Ploutus — first observed in Mexico in 2013 and described by Google-affiliated researchers as one of the most advanced ATM malware families — as a key driver of the broader trend.
Independent technical reporting on the Ploutus family (which the FBI ties to this technique class, though it is not confirmed as the specific malware recovered in the Wamego/Manhattan attempts) documents further tradecraft relevant to the broader campaign this Kansas case belongs to: the malware is commonly packed with the commercial .NET Reactor obfuscator, applying string encryption, function-name obfuscation, method proxying, control-flow-graph obfuscation, and method-body encryption ("Necrobit") that swaps in real method bodies only at JIT-compile time to defeat static and debugger-based analysis; operators activate the malware's hidden menu locally (in one documented variant, by tapping each corner of the touchscreen five times) and issue jackpotting commands via an attached external keyboard or the ATM's own function keys using activation sequences such as "F8F1F2F3F4," while displaying a fake maintenance message on screen to mask the activity from onlookers. A related, separately prosecuted and much larger campaign — two federal indictments (October 21 and December 9, 2025) in the District of Nebraska charging 54 members of Tren de Aragua (TdA), a Venezuelan transnational criminal organization designated a Foreign Terrorist Organization by the U.S. State Department — used a Ploutus variant against the Kalignite multivendor ATM platform (targeting Diebold Nixdorf and other hardware) an
Target sectors: financial services, banking, credit unions, retail banking
Target regions: united states of america, Kansas, Indiana
Timeline
- A federal grand jury in the District of Nebraska returns the first of two indictments (32 defendants) charging Tren de Aragua members in a separate, larger nationwide Ploutus/Kalignite ATM jackpotting scheme — national context for the technique class this Kansas case belongs to.
- The five defendants travel from Indiana to Kansas, in December 2025, intending to install jackpotting malware on ATMs and remotely trigger cash dispensing.
- The group's malware-installation attempt on an ATM in Wamego, Kansas trips the machine's alarm, prompting a law-enforcement response and forcing the group to abandon the site; the attempt fails.
- The group also attempts to jackpot an ATM in Manhattan, Kansas; the machine never dispenses cash and the attempt fails.
- Surveillance-camera footage of both attempted thefts leads to the arrest of all five defendants within days of the incidents.
- A second federal grand jury indictment in the District of Nebraska charges an additional 22 individuals in the Tren de Aragua Ploutus/Kalignite scheme, bringing that separate case's total to 54 defendants charged since October 2025.
- The FBI, via the Internet Crime Complaint Center (IC3), issues FLASH alert CSA-260219 on malware-enabled ATM jackpotting, reporting 1,900 incidents since 2020 (700+ in 2025 alone, over $20 million in 2025 losses) and naming Ploutus as a key driver of the trend, detailing generic-key cabinet entry and hard-drive-based malware installation as the standard method.
- In a separate, unrelated Omaha, Nebraska case, Juan Manuel Gouveia-Aguilera is sentenced to eight years in prison for using Ploutus malware to steal over $3.5 million from ATMs — cited by reporting as related nationwide context, not part of the Kansas defendant group.
- The U.S. Attorney's Office for the District of Kansas announces that all five defendants have pleaded guilty to one count of conspiracy to commit bank larceny; U.S. Attorney Ryan A. Kriegshauser states the group specifically targeted ATMs believed to be more vulnerable to malware.
- Luis Alberto Velasquez-Artigas is sentenced to nine months in prison; the remaining four defendants (Figuera-Perez, Mejia Jr., Corales-Garcia, Corrales-Carrillo) await sentencing.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, LOW, threat intelligence, cybersecurity, T1091, T1106, T1547.004, T1685, T1027, T1140, T1036, T1082, T1657