Alleged Ploutus ATM malware developer appears in US court after arrest
A Venezuelan man added to the FBI's most wanted list in March has appeared before a Nebraska court over an ATM jackpotting campaign that drained more than $5.4 million.
At a glance
- Anibal Alexander Canelon Aguirre, 50, known as "Prometheus" and "The Engineer", appeared in a Nebraska federal court
- Prosecutors tie him to over 117 jackpotting incidents at 63 banks and 54 credit unions
- The charges carry maximum terms of 30, 20, 15 and 5 years, including material support to terrorists
- He was already sanctioned by OFAC as a member of the Tren de Aragua gang
The man US prosecutors accuse of developing the Ploutus ATM malware has appeared before a federal court in Nebraska following his arrest, BleepingComputer reported on 5 October 2026. Anibal Alexander Canelon Aguirre, a 50-year-old Venezuelan national known by the aliases "Prometheus" and "The Engineer", had been added to the FBI's Top 10 Most Wanted Fugitives list in March 2026.
What happened
According to BleepingComputer, Canelon Aguirre was charged in Nebraska in December 2025 and appeared in court there after being apprehended. The publication reports four conspiracy counts against him: conspiracy to commit bank fraud, carrying a maximum of 30 years; conspiracy to commit money laundering, up to 20 years; conspiracy to commit bank burglary and computer fraud, up to five years; and conspiracy to provide material support to terrorists, up to 15 years.
That last count is unusual in a financially motivated cybercrime case. BleepingComputer reports that proceeds from the scheme were laundered into accounts controlled by Tren de Aragua, the Venezuelan criminal organisation that the US government has designated as a terrorist group. Canelon Aguirre had already been sanctioned by the Treasury's Office of Foreign Assets Control as a member of that organisation.
Technical details
Ploutus is a long-running family of ATM malware used in "jackpotting" attacks, in which an operator with physical access to a cash machine forces it to dispense its entire cash cassette. According to BleepingComputer's account of the court filings, the version attributed to Canelon Aguirre carried anti-analysis measures intended to hinder forensic review, used software protection utilities to resist reverse-engineering, and included functions to delete the malware from the system afterwards in order to conceal that it had been deployed.
Those self-removal routines are part of why jackpotting investigations are difficult: by the time an operator reports an unexplained cash shortfall, the code that caused it may no longer be on the machine.
Who is affected
BleepingComputer reports that the campaign involved more than 117 jackpotting incidents between February 2024 and December 2025, spread across 63 banks and 54 credit unions. More than $5.4 million was stolen, with a further $1.43 million targeted in attempts that did not succeed. The figures come from the US case against him.
What to do
For financial institutions, jackpotting remains primarily a physical and monitoring problem rather than a network one. The standard controls still apply: restrict access to the ATM top box and its ports, replace default locks and keys on the upper enclosure, enforce full disk encryption and secure boot on the ATM platform, and keep the terminal software current.
On the detection side, the fact that this malware family removes itself argues for off-device logging. Dispense commands, cassette status and maintenance-mode entries should be forwarded to a central system in near real time, so that an anomalous dispense sequence is visible even if the terminal itself is later wiped. Reconciliation gaps between the switch's dispense records and physical cash counts are often the first reliable signal.
Sources
- Alleged dev of Ploutus ATM malware appears in US court after arrest — BleepingComputer
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



