Alleged Ploutus ATM malware developer arrested, appears in US court
According to BleepingComputer, the U.S. Department of Justice has announced the arrest of Anibal Alexander Canelon Aguirre, the alleged developer of Ploutus, an ATM malware family used in jackpotting attacks against banks and credit unions across the United States. Canelon Aguirre has appeared in a U.S. court, and the charges are allegations that have not been proven. This Ploutus ATM malware case matters to any team that runs or secures ATM fleets.
What we know
BleepingComputer reports that Canelon Aguirre, 50, is also known as “Prometheus” and “The Engineer.” He was the first cybercriminal added to the FBI’s Top 10 Most Wanted Fugitives list, in March 2026.
- Court documents allege that he and accomplices used Ploutus to empty ATMs at banks and credit unions between February 2024 and December 2025.
- He was charged in Nebraska in December 2025.
- The Justice Department made the arrest announcement in a press release on a Friday, as reported on October 5, 2026.
- Last week, the U.S. Office of Foreign Assets Control (OFAC) sanctioned eight members of the Tren de Aragua (TdA) gang, including Canelon Aguirre, for their roles in jackpotting attacks on U.S. financial institutions.
The charges are conspiracy to commit bank fraud (maximum 30 years), conspiracy to commit money laundering (maximum 20 years), conspiracy to commit bank burglary and fraud in connection with computers (maximum five years), and conspiracy to provide material support to terrorists (maximum 15 years).
Who is affected
Banks and credit unions that operate ATMs in the United States were the targets. Per the reported court documents, more than $5.4 million was stolen in at least 63 jackpottings against banks and another 54 against credit unions. A further $1,429,738 was stolen or sought in attempted attacks. Losses exceeded $100,000 per incident.
The source does not say which institutions, ATM models or software versions were hit, and no CVE is named. Treat this as a criminal-case update, not a new vulnerability disclosure.
How the Ploutus malware worked
The Justice Department said Ploutus included files with anti-analysis measures, specifically software protection utilities meant to block reverse-engineering and debugging. It also included files that deleted the malware from the system, so that bank employees would not learn it had been deployed on the ATM.
The DOJ says the ring laundered the stolen funds and sent them to accounts controlled by TdA in several countries. The U.S. designated TdA as a transnational criminal organization in July 2024 and as a foreign terrorist organization in February 2025.
What has not been confirmed
- Canelon Aguirre is described as the alleged developer. The court case is ongoing, and no verdict has been reported.
- Where and when the arrest took place was not stated in the source material we reviewed.
- How the attackers gained access to the ATMs, and any indicators of compromise, were not disclosed.
- Whether Ploutus activity will stop after the arrest is unknown.
Why this matters
Analysis, not new facts: one arrest rarely ends a malware family, especially when the alleged ring had several members and the malware’s code may already be in other hands. Financial institutions should assume jackpotting remains a live risk. The self-deletion feature is a detection problem. A clean ATM after the fact does not prove it was never compromised.
What to do
- Review physical security on ATMs: cabinet and hood locks, tamper seals, alarms and camera coverage. Jackpotting generally needs access to the machine’s internals, though the source does not describe the method used here.
- Check ATM cash-out and dispense logs for unexplained dispenses, especially outside business hours, and compare them with host-side transaction records.
- Look for unexpected USB devices, unknown software or services, and unplanned reboots or maintenance-mode events on ATM endpoints. Treat any hit as an incident.
- Confirm that ATM operating systems and software-whitelisting or device-control tools are current, and check the status of your ATM vendor’s advisories.
- Tell your fraud and physical security teams, and report suspected jackpotting to law enforcement.
