FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

A notorious cybercrime mastermind has been brought to justice by the FBI, marking a significant victory in the ongoing battle against ATM jackpotting and other financial crimes. Anibal Alexander Canelon Aguirre, also known as “Prometheus” and “The Engineer”, was arrested on October 2nd and charged with his role in the violent transnational criminal organization Tren de Aragua (TdA), which has been linked to multiple high-profile ATM attacks across 47 US states and foreign countries.

Canelon Aguirre is accused of being a key player in the development of Ploutus, a sophisticated malware used by TdA to exploit vulnerabilities in ATMs and force them to dispense cash without debiting accounts. This type of attack, known as ATM jackpotting, has been a growing concern for financial institutions and law enforcement agencies worldwide. The malware was designed with anti-analysis capabilities, making it difficult for forensic experts to track its activities.

The TdA organization is believed to have engaged in various types of financial crimes, including ATM jackpotting, bank burglary, fraud, and money laundering conspiracy. To date, 120 defendants have been charged with their roles in the conspiracy, and three individuals have already received prison sentences. The arrest of Canelon Aguirre marks a significant milestone in the investigation, which is one of the largest and most complex cases of its kind.

The US Treasury had previously sanctioned Canelon Aguirre last week, highlighting his involvement in TdA’s malicious activities. He was also indicted in December 2025 along with 21 other individuals on charges related to bank burglary, fraud, and money laundering conspiracy. Canelon Aguirre will remain detained pending trial, after entering not guilty pleas.

The success of this operation demonstrates the collaborative efforts between law enforcement agencies and financial institutions to combat cybercrime. It also serves as a reminder that those who engage in such activities will be held accountable for their actions. As the cybersecurity landscape continues to evolve, it is essential for organizations to remain vigilant and take proactive measures to protect themselves against these types of threats.

For individuals and businesses, this case highlights the importance of staying informed about emerging threats and implementing robust security measures to prevent ATM jackpotting and other financial crimes. This includes regularly updating software and systems, conducting thorough risk assessments, and educating employees on how to identify and report suspicious activity. By staying proactive and working together with law enforcement agencies, we can reduce the impact of these types of attacks and keep our financial institutions secure.


Source: SecurityWeek — 2026-10-06