Ploutus ATM Malware Suspect Arrested After $5.4 Million Jackpotting Spree
The U.S. Department of Justice announced the arrest of the suspected developer of the Ploutus malware, which was used to steal millions of dollars from ATMs in jackpotting attacks across the United States.
Anibal Alexander Canelon Aguirre, 50, also known as “Prometheus” and “The Engineer,” became the first cybercriminal added to the FBI’s “Ten Most Wanted Fugitives” list in March 2026.
Ploutus malware used in ATM jackpotting attacks
According to court documents, Canelon Aguirre and his accomplices deployed Ploutus malware to empty automated teller machines at banks and credit unions from February 2024 through December 2025.
Each attack caused more than $100,000 in financial losses. In total, the group allegedly stole more than $5.4 million in at least 63 ATM jackpotting attacks against banks and 54 attacks against credit unions. An additional $1,429,738 was stolen in attempted attacks.
Members of the criminal organization allegedly laundered the stolen funds and transferred them to accounts controlled by the Venezuelan gang Tren de Aragua (TdA) in several countries.

Suspected Ploutus developer used anti-analysis features
“Canelon Aguirre is the developer of the Ploutus malware and is alleged to be one of the key leaders of the ATM jackpot conspiracy,” the Department of Justice said in a press release.
According to the DOJ, Ploutus contained anti-analysis features designed to hinder forensic investigations. The malware included software protections that prevented reverse engineering and debugging.
Other files associated with the malware were designed to remove it from infected systems and mislead financial institution employees about its deployment on ATMs.
Federal charges against Canelon Aguirre
Canelon Aguirre was indicted in Nebraska in December 2025 on several charges, including:
- Conspiracy to commit bank fraud, which carries a potential sentence of up to 30 years in prison.
- Conspiracy to commit money laundering, which carries a potential sentence of up to 20 years in prison.
- Conspiracy to commit bank robbery and computer-related fraud, which carries a potential sentence of up to five years in prison.
- Conspiracy to provide material support to terrorists, which carries a potential sentence of up to 30 years in prison.

Tren de Aragua linked to ATM jackpot attacks
The U.S. Treasury designated TdA as a transnational criminal organization in July 2024. The State Department designated the gang as a foreign terrorist organization in February 2025.
Last week, the U.S. Office of Foreign Assets Control sanctioned eight TdA members, including Canelon Aguirre, for their alleged involvement in jackpotting attacks targeting U.S. financial institutions.
“TdA has expanded its criminal network throughout the Western Hemisphere and established a presence in the United States,” the Department of Justice said.
The department said TdA’s criminal activities include drug and gun trafficking, commercial sex trafficking, kidnapping, robbery, theft, fraud and extortion. Members also allegedly commit murders, assaults and other acts of violence to advance the organization’s criminal activities.
“TdA has also developed additional sources of revenue through financial crimes targeting financial institutions across the United States, including stealing millions of dollars in cash through ATM jackpots,” the DOJ said.
The investigation found that the conspiracy targeted 47 states, the District of Columbia and several foreign countries with ATM jackpotting attacks.
98 suspects indicted in ATM jackpotting schemes
Since October 2025, the Department of Justice has indicted 98 suspects involved in ATM jackpotting schemes associated with TdA. The suspects face maximum sentences ranging from 20 to 335 years in prison.
Following a series of arrests targeting members of the TdA crime organization, the FBI warned in February that a surge in ATM hacking attacks could enable criminals to steal more than $20 million in 2025.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



