Skip to main content
Emerging ThreatsMalware & Ransomware

US Arrests Alleged Developer of Ploutus ATM Malware

Law enforcement officer stands beside seized, disassembled ATM machine.

More than $5.4 million was stolen in at least 63 ATM jackpotting attacks against banks — and another 54 attacks hit credit unions — according to a U.S. Department of Justice account of a criminal ring that used the Ploutus malware to empty machines across the country.

Anibal Alexander Canelon Aguirre: arrest, court appearance, and charges

The Justice Department announced the arrest of 50-year-old Anibal Alexander Canelon Aguirre, also known as "Prometheus" and "The Engineer," and said he appeared in U.S. court after the arrest. In March 2026 he became the first cybercriminal added to the FBI's "Top 10 Most Wanted Fugitives" list.

Canelon Aguirre was charged in Nebraska in December 2025 with multiple offenses: conspiracy to commit bank fraud (maximum 30 years); conspiracy to commit money laundering (maximum 20 years); conspiracy to commit bank burglary and fraud in connection with computers (up to five years); and conspiracy to provide material support to terrorists (maximum 15 years).

Ploutus malware: anti‑analysis features and deletion routines

The Justice Department described Ploutus as the software central to the jackpotting campaign that ran between February 2024 and December 2025. DOJ said the malware was used to "empty bank and credit union automated teller machines (ATMs) in jackpotting attacks" and that individual incidents produced financial losses surpassing $100,000. The department quantified the criminal proceeds as more than $5.4 million stolen in at least 63 bank-targeted ATM jackpottings and 54 credit-union-targeted jackpottings, plus an additional $1,429,738 in attempted attacks.

DOJ’s press release set out the malware’s technical intent in precise terms: "Canelon Aguirre is alleged to be the developer of the Ploutus malware and one of the principal leaders of ATM jackpotting conspiracy. Ploutus malware consisted of, among other things, files that contained anti-analysis measures to hinder forensic review, specifically software protection utilities to prevent reverse-engineering and debugging."

The department added that the code included active concealment measures: "The malware also contained other files that served the function of deleting the malware from the system in an effort to conceal, create a false impression, mislead, or otherwise deceive employees of the financial institution from learning about the deployment of the malware on the ATM."

Tren de Aragua (TdA): designations and sanctions

DOJ linked the jackpotting conspiracy to the Tren de Aragua (TdA) Venezuelan gang and said members of the criminal ring laundered proceeds and transferred funds to accounts controlled by TdA in various countries. The U.S. Treasury Department designated TdA as a transnational criminal organization in July 2024, and the Department of State designated it as a foreign terrorist organization in February 2025.

Last week the U.S. Office of Foreign Assets Control (OFAC) sanctioned eight TdA members, including Canelon Aguirre, for their roles in jackpotting attacks targeting U.S. financial institutions. In its Friday press release DOJ described TdA’s activities in blunt terms: "TdA has expanded its criminal network throughout the Western Hemisphere and established a presence in the United States. TdA's criminal activities range from drug trafficking and firearms trafficking to commercial sex trafficking, kidnapping, robbery, theft, fraud, and extortion. TdA members also commit murder, assault, and other violent acts to advance the organization's criminal activities."

Scale of the conspiracy and law enforcement response

DOJ said the investigation found the conspiracy "has targeted or carried out ATM jackpotting attacks in 47 states, the District of Columbia, and several foreign nations." Since October 2025 the department has charged 98 suspects involved in ATM jackpotting schemes linked to TdA; those defendants now face individual maximum sentences ranging from 20 to 335 years in prison, according to DOJ.

The arrest and court appearance of Canelon Aguirre come amid a broader, high‑profile enforcement push. The FBI warned in February of a massive surge in ATM hacking attacks and said criminals had stolen more than $20 million in 2025 alone as the wave accelerated.

What this means for technologists, policymakers, and banks and credit unions

  • Technologists and security teams: DOJ’s description emphasizes anti‑analysis measures and deletion routines in Ploutus — concrete technical features defenders will need to account for when examining compromised ATM software or conducting forensic reviews.
  • Policymakers and regulators: Treasury and State designations of TdA, together with recent OFAC sanctions and the Nebraska criminal case, underscore a blended legal strategy that combines criminal prosecution with financial and foreign‑policy tools to disrupt transnational criminal financing.
  • Banks and credit unions: the record in this investigation — 63 bank incidents, 54 credit‑union incidents, losses routinely exceeding $100,000 per incident, and attacks across 47 states and D.C. — highlights the scale of direct cash loss and the cross‑border money‑laundering paths used to move proceeds to TdA accounts.

Canelon Aguirre’s court appearance in the United States brings the developer allegation into the formal prosecutorial phase in Nebraska and follows OFAC designation and a wider set of criminal charges against nearly 100 suspects. The DOJ account ties a specific malware strain and distinct concealment techniques to a transnational criminal organization now subject to U.S. criminal, financial, and foreign‑policy pressures; the scene is set for prosecutions and further enforcement actions as courts and agencies proceed.

Original BleepingComputer story