Alleged Ploutus Developer Faces Federal Charges After Years as Fugitive
The U.S. Department of Justice (DOJ) announced the arrest and arraignment of Anibal Alexander Canelon Aguirre, a 50-year-old Venezuelan national known by the aliases "Prometheus" and "The Engineer," who prosecutors allege developed and deployed the Ploutus ATM jackpotting malware behind more than $5.4 million in confirmed losses across the United States. Canelon Aguirre appeared on October 2, 2026, before U.S. Magistrate Judge Michael D. Nelson in the District of Nebraska, where he pleaded not guilty to all four federal counts and was ordered held without release pending trial. He is notable as the first-ever cyber fugitive placed on the FBI's Ten Most Wanted Fugitives list (added March 2026), and the tenth name removed from that list since the start of the current administration, according to FBI Director Kash Patel.
Incident Details
| Attribute | Value |
|---|---|
| Suspect | Anibal Alexander Canelon Aguirre (50, Venezuela) |
| Aliases | "Prometheus," "The Engineer" |
| Malware | Ploutus (ATM jackpotting malware family) |
| FBI Status | Added to Ten Most Wanted Fugitives list, March 2026 — first cyber fugitive on the list |
| Reward Offered | Up to $1 million for information leading to arrest |
| Court | U.S. District Court, District of Nebraska |
| Appearance Date | October 2, 2026 |
| Plea | Not guilty on all four counts |
| Confirmed Losses | $5.4 million+ across 117 confirmed jackpottings (63 bank, 54 credit union) |
| Attempted Losses | $1,429,738 additional in failed attempts |
| Operation Window | February 2024 – December 2025 |
| Geographic Reach | 47 states, Washington D.C., and several foreign countries |
| Linked Organization | Tren de Aragua (TdA), U.S.-designated Foreign Terrorist Organization |
| Co-defendants Charged | 98+ since October 2025, part of 119 total indicted in the broader conspiracy |
How the Scheme Worked
Ploutus: A Decade-Old Malware Family, Still Evolving
Ploutus first surfaced in Mexico in 2013, when criminals exploited weak CD-ROM drive locks on NCR ATMs to boot malicious code directly from physical media. Early builds required a money mule to key in an eight-digit activation code supplied by a crew leader via an attached external keyboard. A later variant, Ploutus.B, added the ability to trigger cash dispensing via SMS message sent to a USB-connected phone inside the chassis. By 2017, Ploutus-D — analyzed by FireEye (Mandiant) and described as "one of the most advanced ATM malware families" researchers had seen — targeted Diebold Nixdorf machines running the Kalignite ATM platform, software used across roughly 40 vendors in 80 countries. Google and Kaspersky researchers have tracked the family's losses at over $64 million by 2017, long before the current Nebraska case. Prosecutors allege Canelon Aguirre authored the specific strain used in this conspiracy and maintained it through the 2024–2025 campaign.
Physical Access Remains the Core Requirement
Despite a decade of evolution, jackpotting with Ploutus still depends on physical access to the target machine. According to court filings and Secret Service advisories on related campaigns, crews would:
- Surveil target ATMs, often at credit unions and banks with light physical security
- Open the ATM's service panel or top chassis to test whether alarms triggered a law-enforcement response
- If undetected, either swap the internal hard drive for one preloaded with Ploutus or connect a USB thumb drive carrying the malware payload
- Use an external keyboard (function keys controlled dispensing, navigation, and retrieval of the machine's unique identifiers) or a connected phone to issue commands that bypassed normal transaction authorization and forced the cash dispensing module to release bills
Anti-Forensic Design
Court documents describe the malware as containing anti-analysis measures to hinder forensic review, including commercial software-protection utilities intended to block reverse-engineering and debugging. Additional components were designed to self-delete from the ATM after a successful dispense, destroying evidence before technicians or investigators could image the machine's drive.
Laundering Through Tren de Aragua
Prosecutors allege cash and proceeds were funneled through a laundering network tied to Tren de Aragua (TdA), a Venezuelan prison-gang-turned-transnational-criminal-organization that the U.S. State Department designated a Foreign Terrorist Organization in February 2025. Funds were allegedly moved through accounts and cryptocurrency wallets — U.S. Treasury's blockchain-intelligence partner TRM Labs identified seven TRON addresses tied to Canelon Aguirre and his associates — before reaching TdA-controlled recipients in multiple countries.
The Arrest
The DOJ's Friday announcement did not disclose exactly where Canelon Aguirre was apprehended, though multiple outlets reported he was taken into custody in Venezuela and transferred to U.S. custody for the Nebraska proceeding. His capture followed a sustained, multi-agency manhunt after his March 2026 placement on the FBI's most-wanted list and a parallel U.S. Treasury Office of Foreign Assets Control (OFAC) sanctions action (announced September 30, 2026) that designated him and seven associates, along with two Mexico-based companies — including one identified as Enigma Community, owned by Alejandro Mejia Castillo — for their role in the jackpotting network.
Impact Assessment
| Impact Area | Description |
|---|---|
| Financial Sector | $5.4M+ in confirmed direct losses from this conspiracy alone; U.S. Treasury puts nationwide jackpotting losses since 2021 at over $40 million across 1,500+ attacks |
| Credit Unions & Community Banks | Disproportionately targeted — 54 of 117 confirmed hits struck credit union ATMs, institutions that often lack the physical hardening of larger bank branches |
| National Security | Proceeds allegedly routed to a U.S.-designated Foreign Terrorist Organization, elevating the case from financial crime to counterterrorism-adjacent prosecution |
| Law Enforcement Precedent | First cybercrime case to produce an FBI Ten Most Wanted fugitive, and one of the largest coordinated ATM-malware indictments to date (119 defendants) |
| Forensic Response | Anti-forensic, self-deleting malware components complicate incident response and evidence recovery for affected institutions |
| Ongoing Exposure | Kalignite's broad vendor footprint (~40 vendors, 80 countries) means Ploutus-derived code remains a viable threat template beyond this specific crew |
Recommendations
For Financial Institutions and ATM Operators
- Harden physical access controls on ATM chassis, including tamper-evident seals, service-panel alarms tied directly to monitoring centers, and anti-endoscope port covers
- Disable or lock down unused USB and service ports on ATM controllers; audit which machines still expose externally accessible interfaces
- Enforce application allow-listing and code-signing verification on ATM operating environments (including Kalignite and similar platforms) to block unauthorized executable injection
- Deploy ATM-specific endpoint detection capable of flagging unauthorized dispense-module commands independent of the core application
- Review response-time SLAs for physical alarm events — jackpotting crews specifically test whether alarms draw a law-enforcement response before proceeding
For Security Teams
- Treat ATM fleets as a distinct asset class in threat modeling, separate from standard branch IT, given their unique physical/cyber hybrid attack surface
- Preserve forensic images immediately after any suspected jackpotting event — Ploutus variants are built to self-delete, so delayed response can destroy the only available evidence
- Monitor for anomalous after-hours service access and correlate with dispense logs and cash-reconciliation discrepancies
- Share indicators of compromise with sector-specific ISACs (e.g., FS-ISAC) given the cross-institution, organized nature of this campaign
For Consumers and Credit Union Members
- Use ATMs located inside bank lobbies or well-monitored, well-lit locations rather than free-standing or low-traffic units
- Monitor account statements regularly — while jackpotting targets the machine's cash supply rather than individual accounts directly, affected institutions may face temporary service disruptions or fee adjustments during investigations
- Report visibly tampered or damaged ATM panels to the operating institution immediately rather than attempting a transaction
Key Takeaways
- Anibal Alexander Canelon Aguirre, aka "Prometheus," pleaded not guilty in Nebraska federal court on October 2, 2026, becoming the first cyber fugitive ever captured off the FBI's Ten Most Wanted list.
- Prosecutors allege he developed the Ploutus malware strain used to steal over $5.4 million across 117 confirmed ATM jackpottings between February 2024 and December 2025, plus nearly $1.43 million in failed attempts.
- Ploutus has a 13-year history, evolving from CD-ROM-booted code in 2013 Mexico to a Kalignite-targeting, anti-forensic, self-deleting toolkit used against Diebold Nixdorf and other platforms today.
- The scheme is tied to Tren de Aragua, a U.S.-designated Foreign Terrorist Organization, elevating the prosecution to include material support for terrorism charges alongside bank fraud and money laundering counts.
- This arrest is part of a much larger enforcement wave — 119 individuals indicted, 98+ charged since October 2025, and parallel Treasury OFAC sanctions against Canelon Aguirre, seven associates, and two Mexico-based companies.
- Jackpotting still fundamentally requires physical access to the ATM, meaning tamper detection, port lockdown, and rapid alarm response remain the most effective defenses institutions can deploy today.
Sources
- BleepingComputer: Alleged dev of Ploutus ATM malware appears in US court after arrest
- The Record: DOJ charges gang for ATM hacks using Ploutus malware
- U.S. Department of Justice, District of Nebraska: Apprehended Venezuelan Tren de Aragua leader on FBI's Top 10 Most Wanted list appears in court
- SecurityWeek: Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
- Newsweek: FBI Arrests First Ever Cyber Fugitive on Top 10 Most Wanted List
- UPI: FBI Top 10 fugitive accused of ATM cyberattacks appears in U.S. court
- The Hacker News: U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware