Ploutus ATM Cash-Out Case Brings Alleged Malware Engineer Before a US Court

Alleged Ploutus developer Anibal Canelon Aguirre arrested over $5.4M ATM jackpotting scheme targeting banks across 47 states and linked to TdA.

Ploutus ATM Cash-Out Case Brings Alleged Malware Engineer Before a US Court
Malware

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Arrest puts the alleged developer at the center of the case

Anibal Alexander Canelon Aguirre, 50, has been arrested and appeared before a U.S. court over an alleged ATM-jackpotting conspiracy built around the Ploutus malware. The date of his arrest and details of the court appearance were not specified in the report describing the case.

U.S. authorities identify Canelon Aguirre, also known as “Prometheus” and “The Engineer,” as Ploutus’s alleged developer and a principal leader of the operation. Those descriptions come from the Department of Justice and court documents cited by the report. They remain allegations rather than a judicial finding of guilt.

The reported campaign affected ATMs operated by banks and credit unions from February 2024 through December 2025. Investigators allege that Canelon Aguirre and his associates used Ploutus to force machines to dispense their cash reserves, a class of attack commonly described as ATM jackpotting.

The case combines three distinct elements: the Ploutus malware family, the people accused of developing and deploying it, and the alleged movement of criminal proceeds to accounts controlled by Tren de Aragua, or TdA. The reported financial connection does not establish that TdA developed Ploutus or directly operated the malware.

Court documents describe a wide and costly campaign

According to figures cited from court records, the alleged conspiracy stole more than $5.4 million. The operation involved at least 63 jackpotting incidents targeting banks and another 54 targeting credit unions.

Reported losses exceeded $100,000 per incident. The documents also assign a value of $1,429,738 to attempted attacks, separate from the amount said to have been successfully stolen.

Investigators reportedly found that the conspiracy either targeted or conducted jackpotting attacks across 47 U.S. states, the District of Columbia, and several foreign countries. That geographic footprint indicates an operation extending well beyond one financial institution or regional ATM network.

The alleged participants are also accused of laundering the proceeds and transferring money into TdA-controlled accounts in multiple countries. This financial trail is the reported basis for connecting the jackpotting conspiracy to the organization.

Separately, the FBI warned that criminals stole more than $20 million in 2025 during a broader increase in ATM-hacking attacks. That figure covers the wider surge described by the FBI. It should not be treated as the loss total for the specific Ploutus conspiracy attributed to Canelon Aguirre and his associates.

Ploutus combined cash dispensing with anti-analysis and cleanup functions

The technical reporting describes Ploutus primarily through its effects and supporting files. Once present on an ATM, the malware was used to empty the machine by triggering unauthorized cash dispensing.

The initial-access route is not identified in the supplied reporting. There is no basis to connect the incidents to a particular remote service, credential compromise, physical access method, or software vulnerability.

DOJ statements cited in the report describe malware files protected by utilities intended to frustrate forensic examination. Those protections were designed to make reverse-engineering and debugging more difficult, potentially slowing efforts to understand the code and reconstruct its execution.

Other files served a different purpose: removing Ploutus from the compromised ATM. According to the DOJ’s description, this cleanup capability was intended to hide the malware’s deployment and mislead employees investigating the affected machine.

These functions matter because malware removal is not necessarily evidence that an ATM has remained uncompromised. In this case, deletion was reportedly part of the operation itself. A machine inspected after the cash-out could therefore contain fewer obvious artifacts than it did during execution.

The report provides no file hashes, network indicators, filenames, or affected ATM models. It also does not identify a vendor patch or model-specific remediation. Consequently, the available technical description supports behavioral investigation, but not a hash-based or network-signature detection rule.

The TdA connection concerns proceeds and the alleged conspiracy

The DOJ has linked the operation to Tren de Aragua through the alleged laundering and transfer of stolen funds. It also said TdA’s financial crimes include jackpotting attacks against U.S. financial institutions.

That attribution should remain narrowly framed. Canelon Aguirre is accused of developing Ploutus and leading the conspiracy, while TdA-controlled accounts allegedly received proceeds. The reporting does not establish that TdA created the malware or personally conducted every ATM intrusion associated with the case.

The U.S. Treasury Department designated TdA as a transnational criminal organization in July 2024. The Department of State subsequently designated it as a foreign terrorist organization in February 2025.

The Office of Foreign Assets Control also sanctioned eight TdA members, including Canelon Aguirre, for alleged roles in jackpotting attacks against U.S. financial institutions. Those sanctions are financial and legal measures. They do not substitute for technical remediation on ATM systems.

The report further states that Canelon Aguirre became the first cybercriminal placed on the FBI’s “Top 10 Most Wanted Fugitives” list in March 2026. This characterization is attributed to the report.

Charges carry maximum terms of up to 30 years

Canelon Aguirre was charged in Nebraska in December 2025 with four conspiracy offenses. The most serious maximum penalty attached to the listed charges is 30 years.

The charges and their potential sentences are:

  • conspiracy to commit bank fraud, with a maximum sentence of 30 years;
  • conspiracy to commit money laundering, with a maximum sentence of 20 years;
  • conspiracy to commit bank burglary and fraud involving computers, carrying a potential five-year sentence; and
  • conspiracy to provide material support to terrorists, with a maximum sentence of 15 years.

These are statutory maximums associated with the charges, not sentences already imposed.

The case forms part of a larger enforcement effort. According to the report, the DOJ has charged 98 suspects since October 2025 in ATM-jackpotting schemes linked to TdA. Those defendants reportedly face maximum sentences ranging from 20 to 335 years each, depending on their individual charges.

ATM defenders should preserve evidence before cleanup destroys context

Without supplied hashes or network indicators, defenders must focus on the behavior described in the case. ATM operators and financial institutions should investigate unauthorized software execution, unexplained cash-dispensing activity, and unexpected deletion of software from ATM systems.

Potential anti-analysis protections also deserve attention during triage. If an unfamiliar executable resists debugging or appears wrapped in software-protection technology, investigators should not assume it is benign solely because its contents are difficult to inspect.

Evidence preservation is particularly important. Because Ploutus reportedly included components intended to remove the malware, routine recovery steps or premature reimaging could eliminate artifacts needed to establish what ran on the machine.

Institutions should preserve relevant forensic material promptly when jackpotting is suspected and correlate software changes with cash-loss records and unauthorized dispensing activity. These are defensive priorities derived from the behavior described by authorities, not vendor-provided signatures or malware-specific detection rules.

No technical patch is identified in the reporting. The immediate defensive task is therefore to detect abnormal execution and dispensing, contain affected ATMs, and retain evidence before the alleged cleanup functions further reduce visibility.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →