FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

A major blow to international cybercrime was dealt on October 2 when Anibal Alexander Canelon Aguirre, a Venezuelan national and alleged leader of Tren de Aragua (TdA), a notorious transnational criminal organization, was arrested by the FBI. Canelon Aguirre, also known as ‘Prometheus’ or ‘The Engineer’, has been on the run since March 2026, when he became the first individual added to the FBI’s top 10 most wanted fugitives list for cybercrimes.

Tren de Aragua is a violent organization that engages in various forms of trafficking, robbery, fraud, extortion, and financial crimes targeting US organizations. One of their most notable tactics has been ATM jackpotting, where they exploit vulnerabilities in ATMs to deploy malware that forces the systems to dispense cash without debiting accounts. This scam, also known as “cash-out,” has resulted in significant losses for financial institutions across 47 states, the District of Columbia, and foreign countries.

Canelon Aguirre is believed to be one of the masterminds behind TdA’s ATM jackpotting attacks using the infamous Ploutus malware. This sophisticated tool contains anti-analysis capabilities that hinder forensic analysis and can erase itself from infected systems, making it difficult for investigators to track its activity. To date, 120 defendants have been charged in connection with this conspiracy, with three already sentenced to prison.

The US Treasury sanctioned Canelon Aguirre last week, and he was subsequently indicted in the US in December 2025 on charges of bank burglary, fraud, and money laundering conspiracy. He entered not guilty pleas during his court appearance on October 2, but will remain detained pending trial.

This high-profile arrest marks a significant victory for law enforcement agencies in their efforts to combat international cybercrime. While TdA’s activities have caused significant financial losses, the apprehension of Canelon Aguirre sends a clear message that those responsible for these crimes will be held accountable.

For individuals and organizations, this story serves as a reminder of the importance of robust cybersecurity measures, including regular software updates, secure coding practices, and vigilance against sophisticated malware like Ploutus. As cybercrime continues to evolve, it’s essential for users to stay informed about the latest threats and take proactive steps to protect themselves from financial loss.


Source: SecurityWeek — 2026-10-06