Alleged Ploutus ATM malware developer appears in US court
The DOJ says Anibal Canelon Aguirre, alleged developer of Ploutus ATM jackpotting malware, appeared in Nebraska federal court after his arrest off the FBI's Ten Most Wanted list.
The US Department of Justice says Anibal Alexander Canelon Aguirre, a 50-year-old Venezuelan national, appeared in federal court in the District of Nebraska after his arrest. Prosecutors allege he is the developer of the Ploutus malware — one of the longest-running families of ATM "jackpotting" code — and one of the principal leaders of the conspiracy that used it.
The charges
Per the DOJ announcement, Canelon Aguirre — who used the aliases "Prometheus" and "The Engineer" — faces four conspiracy counts:
- Conspiracy to commit bank fraud (max 30 years)
- Conspiracy to commit money laundering (max 20 years)
- Conspiracy to commit bank burglary and fraud in connection with computers (max 5 years)
- Conspiracy to provide material support to terrorists (max 15 years)
The DOJ says the conspiracy "targeted or carried out ATM jackpotting attacks in 47 states, the District of Columbia, and several foreign nations." Canelon Aguirre was added to the FBI's Ten Most Wanted Fugitives list in March 2026 before being apprehended.
BleepingComputer, citing court documents, reports the ring stole more than $5.4 million in at least 63 ATM jackpottings against banks and another 54 against credit unions, plus roughly $1.43 million in attempted attacks, between February 2024 and December 2025. Those figures come from the charging documents rather than the DOJ press release; the DOJ statement itself does not enumerate a dollar total.
What jackpotting is
ATM jackpotting is a physical-plus-malware attack. The operator gains access to the machine's internals — often through a hole drilled near the dispenser or a swapped-out hard drive — connects to the ATM's computer, and loads malware such as Ploutus that issues cash-dispense commands directly, draining the cassettes. Ploutus has circulated in various builds for more than a decade and has historically been triggered by an attached keyboard or an SMS message to a phone wired into the machine.
What to do today
For financial institutions and ATM operators, the arrest changes nothing about the exposure — the technique outlives any one developer.
- Lock down physical access. Jackpotting starts with the ATM's internals. Verify top-hat locks, tamper sensors, and that cash-dispenser firmware enforces authenticated commands.
- Enable and monitor the vendor's anti-malware/whitelisting on the ATM host OS. Ploutus relies on running unauthorized code on the machine's Windows stack.
- Alert on anomalous dispense activity — out-of-pattern full-cassette withdrawals, dispenses without a corresponding authorized transaction, maintenance-mode entries outside service windows.
- Keep ATM fleets off end-of-life Windows builds. Jackpotting malware families lean on unpatched, long-lived embedded systems.
Context
Jackpotting crews have been a steady law-enforcement target for years, and takedowns of named developers are rare wins — but the malware and the physical playbook are commodity knowledge now. The novel element in this case is the terrorism-support count, tying an ATM-fraud conspiracy to the kind of charge more often seen in national-security prosecutions. Expect the dollar figures and the full scope to firm up as the Nebraska case proceeds.