NEWS

Alleged Ploutus ATM Malware Developer Appears in US Court After Arrest

FBI's first-ever cyber fugitive, accused Ploutus malware developer "Prometheus," pleaded not guilty in Nebraska over a $5.4M ATM jackpotting spree.

Dylan H.

News Desk

October 5, 2026
8 min read
Alleged Ploutus ATM Malware Developer Appears in US Court After Arrest

Alleged Ploutus Developer Faces Federal Charges After Years as Fugitive

The U.S. Department of Justice (DOJ) announced the arrest and arraignment of Anibal Alexander Canelon Aguirre, a 50-year-old Venezuelan national known by the aliases "Prometheus" and "The Engineer," who prosecutors allege developed and deployed the Ploutus ATM jackpotting malware behind more than $5.4 million in confirmed losses across the United States. Canelon Aguirre appeared on October 2, 2026, before U.S. Magistrate Judge Michael D. Nelson in the District of Nebraska, where he pleaded not guilty to all four federal counts and was ordered held without release pending trial. He is notable as the first-ever cyber fugitive placed on the FBI's Ten Most Wanted Fugitives list (added March 2026), and the tenth name removed from that list since the start of the current administration, according to FBI Director Kash Patel.


Incident Details

AttributeValue
SuspectAnibal Alexander Canelon Aguirre (50, Venezuela)
Aliases"Prometheus," "The Engineer"
MalwarePloutus (ATM jackpotting malware family)
FBI StatusAdded to Ten Most Wanted Fugitives list, March 2026 — first cyber fugitive on the list
Reward OfferedUp to $1 million for information leading to arrest
CourtU.S. District Court, District of Nebraska
Appearance DateOctober 2, 2026
PleaNot guilty on all four counts
Confirmed Losses$5.4 million+ across 117 confirmed jackpottings (63 bank, 54 credit union)
Attempted Losses$1,429,738 additional in failed attempts
Operation WindowFebruary 2024 – December 2025
Geographic Reach47 states, Washington D.C., and several foreign countries
Linked OrganizationTren de Aragua (TdA), U.S.-designated Foreign Terrorist Organization
Co-defendants Charged98+ since October 2025, part of 119 total indicted in the broader conspiracy

How the Scheme Worked

Ploutus: A Decade-Old Malware Family, Still Evolving

Ploutus first surfaced in Mexico in 2013, when criminals exploited weak CD-ROM drive locks on NCR ATMs to boot malicious code directly from physical media. Early builds required a money mule to key in an eight-digit activation code supplied by a crew leader via an attached external keyboard. A later variant, Ploutus.B, added the ability to trigger cash dispensing via SMS message sent to a USB-connected phone inside the chassis. By 2017, Ploutus-D — analyzed by FireEye (Mandiant) and described as "one of the most advanced ATM malware families" researchers had seen — targeted Diebold Nixdorf machines running the Kalignite ATM platform, software used across roughly 40 vendors in 80 countries. Google and Kaspersky researchers have tracked the family's losses at over $64 million by 2017, long before the current Nebraska case. Prosecutors allege Canelon Aguirre authored the specific strain used in this conspiracy and maintained it through the 2024–2025 campaign.

Physical Access Remains the Core Requirement

Despite a decade of evolution, jackpotting with Ploutus still depends on physical access to the target machine. According to court filings and Secret Service advisories on related campaigns, crews would:

  1. Surveil target ATMs, often at credit unions and banks with light physical security
  2. Open the ATM's service panel or top chassis to test whether alarms triggered a law-enforcement response
  3. If undetected, either swap the internal hard drive for one preloaded with Ploutus or connect a USB thumb drive carrying the malware payload
  4. Use an external keyboard (function keys controlled dispensing, navigation, and retrieval of the machine's unique identifiers) or a connected phone to issue commands that bypassed normal transaction authorization and forced the cash dispensing module to release bills

Anti-Forensic Design

Court documents describe the malware as containing anti-analysis measures to hinder forensic review, including commercial software-protection utilities intended to block reverse-engineering and debugging. Additional components were designed to self-delete from the ATM after a successful dispense, destroying evidence before technicians or investigators could image the machine's drive.

Laundering Through Tren de Aragua

Prosecutors allege cash and proceeds were funneled through a laundering network tied to Tren de Aragua (TdA), a Venezuelan prison-gang-turned-transnational-criminal-organization that the U.S. State Department designated a Foreign Terrorist Organization in February 2025. Funds were allegedly moved through accounts and cryptocurrency wallets — U.S. Treasury's blockchain-intelligence partner TRM Labs identified seven TRON addresses tied to Canelon Aguirre and his associates — before reaching TdA-controlled recipients in multiple countries.

The Arrest

The DOJ's Friday announcement did not disclose exactly where Canelon Aguirre was apprehended, though multiple outlets reported he was taken into custody in Venezuela and transferred to U.S. custody for the Nebraska proceeding. His capture followed a sustained, multi-agency manhunt after his March 2026 placement on the FBI's most-wanted list and a parallel U.S. Treasury Office of Foreign Assets Control (OFAC) sanctions action (announced September 30, 2026) that designated him and seven associates, along with two Mexico-based companies — including one identified as Enigma Community, owned by Alejandro Mejia Castillo — for their role in the jackpotting network.


Impact Assessment

Impact AreaDescription
Financial Sector$5.4M+ in confirmed direct losses from this conspiracy alone; U.S. Treasury puts nationwide jackpotting losses since 2021 at over $40 million across 1,500+ attacks
Credit Unions & Community BanksDisproportionately targeted — 54 of 117 confirmed hits struck credit union ATMs, institutions that often lack the physical hardening of larger bank branches
National SecurityProceeds allegedly routed to a U.S.-designated Foreign Terrorist Organization, elevating the case from financial crime to counterterrorism-adjacent prosecution
Law Enforcement PrecedentFirst cybercrime case to produce an FBI Ten Most Wanted fugitive, and one of the largest coordinated ATM-malware indictments to date (119 defendants)
Forensic ResponseAnti-forensic, self-deleting malware components complicate incident response and evidence recovery for affected institutions
Ongoing ExposureKalignite's broad vendor footprint (~40 vendors, 80 countries) means Ploutus-derived code remains a viable threat template beyond this specific crew

Recommendations

For Financial Institutions and ATM Operators

  • Harden physical access controls on ATM chassis, including tamper-evident seals, service-panel alarms tied directly to monitoring centers, and anti-endoscope port covers
  • Disable or lock down unused USB and service ports on ATM controllers; audit which machines still expose externally accessible interfaces
  • Enforce application allow-listing and code-signing verification on ATM operating environments (including Kalignite and similar platforms) to block unauthorized executable injection
  • Deploy ATM-specific endpoint detection capable of flagging unauthorized dispense-module commands independent of the core application
  • Review response-time SLAs for physical alarm events — jackpotting crews specifically test whether alarms draw a law-enforcement response before proceeding

For Security Teams

  • Treat ATM fleets as a distinct asset class in threat modeling, separate from standard branch IT, given their unique physical/cyber hybrid attack surface
  • Preserve forensic images immediately after any suspected jackpotting event — Ploutus variants are built to self-delete, so delayed response can destroy the only available evidence
  • Monitor for anomalous after-hours service access and correlate with dispense logs and cash-reconciliation discrepancies
  • Share indicators of compromise with sector-specific ISACs (e.g., FS-ISAC) given the cross-institution, organized nature of this campaign

For Consumers and Credit Union Members

  • Use ATMs located inside bank lobbies or well-monitored, well-lit locations rather than free-standing or low-traffic units
  • Monitor account statements regularly — while jackpotting targets the machine's cash supply rather than individual accounts directly, affected institutions may face temporary service disruptions or fee adjustments during investigations
  • Report visibly tampered or damaged ATM panels to the operating institution immediately rather than attempting a transaction

Key Takeaways

  1. Anibal Alexander Canelon Aguirre, aka "Prometheus," pleaded not guilty in Nebraska federal court on October 2, 2026, becoming the first cyber fugitive ever captured off the FBI's Ten Most Wanted list.
  2. Prosecutors allege he developed the Ploutus malware strain used to steal over $5.4 million across 117 confirmed ATM jackpottings between February 2024 and December 2025, plus nearly $1.43 million in failed attempts.
  3. Ploutus has a 13-year history, evolving from CD-ROM-booted code in 2013 Mexico to a Kalignite-targeting, anti-forensic, self-deleting toolkit used against Diebold Nixdorf and other platforms today.
  4. The scheme is tied to Tren de Aragua, a U.S.-designated Foreign Terrorist Organization, elevating the prosecution to include material support for terrorism charges alongside bank fraud and money laundering counts.
  5. This arrest is part of a much larger enforcement wave — 119 individuals indicted, 98+ charged since October 2025, and parallel Treasury OFAC sanctions against Canelon Aguirre, seven associates, and two Mexico-based companies.
  6. Jackpotting still fundamentally requires physical access to the ATM, meaning tamper detection, port lockdown, and rapid alarm response remain the most effective defenses institutions can deploy today.

Sources