Ploutus ATM malware: alleged developer appears in US court
The man US prosecutors say built the Ploutus ATM malware has been arrested and has appeared in a US court, the Department of Justice (DOJ) announced. Ploutus was used in jackpotting attacks, in which criminals force cash machines to dispense money, that drained millions of dollars from US banks and credit unions.
The suspect is Anibal Alexander Canelon Aguirre, 50, who also went by the aliases "Prometheus" and "The Engineer." In March 2026 he became the first cybercriminal ever placed on the FBI's "Top 10 Most Wanted Fugitives" list.
Over 100 ATMs hit in under two years
Court documents say Canelon Aguirre and his co-conspirators used Ploutus to empty ATMs at banks and credit unions between February 2024 and December 2025.
According to prosecutors, a single attack typically cost a victim more than $100,000. In total, the group allegedly stole over $5.4 million in at least 63 jackpotting attacks on banks and 54 on credit unions. Attempted attacks that failed account for another $1,429,738.
Members of the ring laundered the cash and then moved it to accounts in several countries controlled by Tren de Aragua (TdA), a Venezuelan criminal gang.
Built to resist analysis and cover its tracks
The DOJ describes Canelon Aguirre as the developer of Ploutus and one of the main leaders of the jackpotting conspiracy. It also says the malware was designed to make life hard for investigators.
"Ploutus malware consisted of, among other things, files that contained anti-analysis measures to hinder forensic review, specifically software protection utilities to prevent reverse-engineering and debugging," the Justice Department said in a press release on Friday.
Other components of the malware deleted it from the ATM after use. The DOJ said these were meant to hide the attack, "create a false impression, mislead, or otherwise deceive" bank and credit union staff so they would not find out that the malware had been deployed.
Charges include terrorism support
Canelon Aguirre was charged in Nebraska in December 2025. The charges and their maximum penalties are:
- conspiracy to commit bank fraud, up to 30 years in prison
- conspiracy to commit money laundering, up to 20 years
- conspiracy to commit bank burglary and fraud in connection with computers, up to five years
- conspiracy to provide material support to terrorists, up to 15 years
The terrorism charge comes from how the US government now classifies TdA. The Treasury Department designated the gang a transnational criminal organization in July 2024. The State Department then listed it as a foreign terrorist organization in February 2025.
The arrest also follows financial measures from last week. The Treasury's Office of Foreign Assets Control (OFAC), which runs US economic sanctions programs, sanctioned eight TdA members, Canelon Aguirre among them, over their roles in the ATM jackpotting attacks on US financial institutions.
A gang that moved into financial crime
The DOJ says TdA has spread across the Western Hemisphere and now has a presence in the United States. Its activities include drug and firearms trafficking, commercial sex trafficking, kidnapping, robbery, fraud and extortion, as well as murder and other violent crime.
Jackpotting gave the group another source of income. "The investigation has revealed that the conspiracy has targeted or carried out ATM jackpotting attacks in 47 states, the District of Columbia, and several foreign nations," the department said.
This case is one part of a larger effort. Since October 2025, the DOJ has charged 98 suspects in jackpotting schemes tied to TdA. Each faces a maximum sentence of between 20 and 335 years in prison.
The scale of the problem was already clear earlier in the year. In February, after a wave of arrests targeting TdA members, the FBI warned that criminals had stolen more than $20 million through ATM hacking in 2025 alone.
Our Take
For banks and credit unions, this case is a reminder that ATMs are endpoints too, and the anti-forensics features prosecutors describe are the part to note. Malware that blocks reverse-engineering and deletes itself after cashing out means institutions may not know how a machine was compromised, even after the cash is gone. Detection at the time of the attack, and not only investigation afterward, seems to be what matters most here.
The case also shows US authorities treating cybercrime tied to violent gangs as a terrorism and sanctions issue, not only as fraud. A material support charge, OFAC sanctions and a Most Wanted listing together suggest a broader strategy aimed at the money flows behind the group. It fits a wider pattern of US prosecutions of cybercrime operators moving forward this year.
Two things are worth watching next. First, whether court proceedings reveal more technical details about Ploutus that defenders can act on. Second, whether removing its alleged developer actually slows jackpotting activity, or whether others keep using the tooling that already exists.
