A Major Player in ATM Jackpotting Scams Brought to Justice
In a significant development that highlights the ongoing efforts of law enforcement agencies to combat cybercrime, the alleged developer of Ploutus malware has been arrested and appeared in a US court. Anibal Alexander Canelon Aguirre, also known as “Prometheus” and “The Engineer,” is accused of creating the malware used in ATM jackpotting attacks that have drained millions of dollars from bank and credit union ATMs across the United States.
According to court documents, between February 2024 and December 2025, Canelon Aguirre and his accomplices deployed Ploutus malware, which allowed them to empty ATMs in coordinated attacks. The financial losses from these incidents were staggering, with over $5.4 million stolen in at least 63 ATM jackpotting operations targeting banks and another 54 targeting credit unions. The attackers also attempted to steal an additional $1.4 million.
The Ploutus malware was designed to evade detection by containing anti-analysis measures, such as software protection utilities that prevented reverse-engineering and debugging. This made it difficult for forensic experts to track the malware’s activity and identify its authors. However, law enforcement agencies were able to gather evidence and build a case against Canelon Aguirre.
The alleged developer of Ploutus malware is also accused of laundering the stolen funds and transferring them to accounts controlled by the Tren de Aragua (TdA) Venezuelan gang in various countries. The US Treasury Department designated TdA as a transnational criminal organization in July 2024, and the Department of State designated it as a foreign terrorist organization in February 2025.
The arrest of Canelon Aguirre is a significant blow to the TdA gang’s operations, which have been linked to various crimes, including drug trafficking, firearms trafficking, commercial sex trafficking, kidnapping, robbery, theft, fraud, and extortion. Since October 2025, the Justice Department has charged 98 suspects involved in ATM jackpotting schemes linked to the TdA gang, who now face maximum sentences ranging from 20 to 335 years in prison each.
The wave of arrests targeting members of the TdA criminal organization has been accompanied by a warning from the FBI that criminals have stolen more than $20 million in 2025 in a massive surge of ATM hacking attacks. This highlights the ongoing threat posed by cybercrime and the need for financial institutions to remain vigilant in protecting themselves against such attacks.
For individuals and organizations handling large amounts of cash, it’s essential to be aware of the risks associated with ATM jackpotting scams. While this case is a significant success story, it underscores the need for continued vigilance and investment in cybersecurity measures to prevent similar attacks from occurring in the future.
Source: Bleeping Computer — 2026-10-05