The Treasury Department sanctioned 10 people for their role in a lucrative scheme involving malware that allowed people to drain ATMs of their cash. Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs. U.S. officials have tracked at least 1,500 of the attacks causing $40.7 million in losses. The sanctions tie the ATM jackpotting scheme to Tren de Aragua, a Venezuelan criminal group, and Treasury officials claim it is a “key source of revenue for the organization.” The proceeds of ATM thefts were allegedly transferred to Tren de Aragua members who helped conceal their origin, either through cryptocurrency or by laundering the funds through companies they own in Mexico and other countries. The Justice Department has repeatedly claimed there are “extensive direct and indirect links” between the Ploutus malware used in the ATM jackpotting scheme and Tren de Aragua. Blockchain analysis firm Chainalysis said ATM jackpotting proceeds “flow through the same channels as drug trafficking money.” “Chainalysis analysis found that counterparties of the [Tren de Aragua] wallets had exposure to laundering operations used by Colombian and Mexican drug cartels, as well as a Venezuelan national charged with laundering one billion dollars,” Chainalysis experts said. “The network relied on shared laundering infrastructure, including stablecoins, that services multiple criminal organizations across Latin America.” The sanctions are one of several actions the U.S. government has taken against the ATM jackpotting scheme. At least 98 people have been indicted for their role in the malware scheme and five men pleaded guilty to related charges last month. Prosecutors and the Treasury Department shared videos and photos of men cracking open the top of ATMs, linking a laptop to it and installing the malware. The malware forces the ATM to dispense all of its available cash. FBI officials previously claimed the developer of the Ploutus malware is Anibal Alexander Canelon Aguirre. Aguirre was added to the FBI’s most wanted list and is accused of deploying multiple teams across the U.S. to use the malware against ATMs typically located in remote areas. The Treasury Department said it has photographs of Aguirre with proceeds of ATM jackpotting crimes. Several other associates cited in Wednesday’s sanctions are accused of helping use cryptocurrency to launder the ATM jackpotting funds. Experts and government agencies have warned for nearly a decade about variants of the Ploutus malware, which Google researchers previously said “is one of the most advanced ATM malware families” they've seen. Experts have not found any links between Ploutus and Aguirre or Tren de Aragua.