Ploutus ATM malware developer arrest hits FBI top-10

The FBI has arrested Venezuelan national Anibal Alexander Canelon Aguirre, alleged developer of the Ploutus ATM malware and a senior figure in Tren de Aragua’s ATM jackpotting operations, marking the first time a cybercrime suspect has appeared on the bureau’s Ten Most Wanted Fugitives list.[1][5][9]

According to the U.S. Department of Justice, Canelon Aguirre, also known as “Prometheus” and “The Engineer,” was captured and brought to Nebraska, where he appeared before a federal magistrate judge on October 2, 2026 to face four counts tied to a multimillion‑dollar ATM hacking conspiracy.[5][10][14] Prosecutors say he has been charged with conspiracy to commit bank fraud, conspiracy to commit bank burglary and intentionally damage a protected computer, conspiracy to commit money laundering, and conspiracy to provide material support to terrorists, and he has pleaded not guilty while remaining detained pending trial.[7][12][14]

Investigators allege that between early 2024 and late 2025, Canelon Aguirre and accomplices deployed Ploutus, a specialized ATM malware family, to compromise bank and credit‑union ATMs across multiple U.S. states and force the machines to dispense cash without any legitimate customer transaction.[6][9][12] Court filings and law‑enforcement statements describe crews that physically accessed ATMs, installed malware via connected devices, and then triggered “jackpotting” runs that siphoned millions of dollars from financial institutions in coordinated operations.[6][11][14] The scheme relied on a mix of cyber and physical tradecraft, highlighting that ATM fleets remain attractive targets when they run outdated operating systems and lack strong controls on local access and maintenance interfaces.[6][9][13]

U.S. authorities say the jackpotting conspiracy helped finance Tren de Aragua, a violent transnational criminal organization that emerged from a Venezuelan prison and has spread across South America and into the United States.[9][12][14] Before his arrest, Canelon Aguirre was added to the FBI’s Ten Most Wanted Fugitives list in March 2026, becoming the first alleged cybercriminal to receive that designation, and was subsequently sanctioned by the U.S. Treasury alongside associates and related entities for his role as the “engineer” of Ploutus‑based attacks.[1][4][9] Reporting from multiple outlets notes that the designation reflects growing concern that sophisticated financial‑crime malware is now tightly woven into the business models of traditional organized‑crime groups.[1][9][15]

Law‑enforcement documents focus on the malware’s use and impact rather than specific software flaws, and public advisories to date have not tied the Ploutus campaign to any single disclosed CVE or published CVSS score, underscoring that the operation is driven primarily by abuse of legitimate ATM functionality and weak local security controls.[6][9][10] Researchers and officials instead emphasize how Ploutus variants interact directly with ATM software and hardware, often after the attackers obtain administrator‑level access to the machine, to reprogram dispensing logic and bypass normal withdrawal limits.[6][8][13]

For banks, credit unions, and ATM service providers, the case is a reminder that defending against jackpotting hinges on hardening both the physical and logical layers of their fleets.[6][9][10] Security teams are urged to ensure ATM operating systems and vendor applications are fully supported and patched, restrict and monitor use of USB and other local ports, enforce strong authentication for maintenance and remote‑management tools, and deploy telemetry capable of flagging anomalous cash‑out patterns in near real time.[6][9][11] Cooperation with law‑enforcement and threat‑intelligence sharing groups remains critical, as the arrest of an alleged key developer like Canelon Aguirre may disrupt current operations but is unlikely to eliminate demand for ATM malware within the broader criminal ecosystem.[1][9][14]

References

  1. FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
  2. Treasury Blacklists Most-Wanted ATM Malware Developer …
  3. Apprehended Venezuelan Tren de Aragua Leader on FBI’s …
  4. Alleged dev of Ploutus ATM malware appears in US court after arrest
  5. www.justice.gov › usao-ne › prDistrict of Nebraska | Apprehended Venezuelan Tren de Aragua …
  6. Ploutus – Mallory.ai
  7. The US Blacklists Alleged Venezuelan Cyber Crime Mastermind
  8. FBI announces capture of first cyber fugitive on 10 most wanted list after international cybercrime investigation | Digital Watch Observatory
  9. FBI Top 10 fugitive accused of ATM cyberattacks appears in U.S. court
  10. FBI seeks Venezuelan man accused of leading international ATM …
  11. Alleged ATM malware creator appears in Nebraska court after arrest
  12. FBI Most Wanted Fugitive ‘Prometheus’ Is Captured
  13. FBI Captures Top 10 ATM Jackpotting Suspect – STL.News

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply