Threat reportMalwareTL-2026-2939
Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre ('Prometheus'/'The Engineer') Appears in US Court; Tren de Aragua ATM Jackpotting Campaign
Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre (TL-2026-2939), also tracked as ATM jackpotting, is a high-severity malware campaign, first published 2026-10-05. It is attributed to Tren de Aragua (Venezuela) with high confidence, affects Diebold Nixdorf Opteva 500/700 series ATMs and other Windows-based, maps to 7 MITRE ATT&CK techniques (T1027, T1059.003, T1070.004), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 7MITRE ATT&CK
- Actors
- 1Tren de Aragua
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-2939
- Threat ID
- TL-2026-2939
- Also known as
- ATM jackpotting, Ploutus jackpotting campaign
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Tren de Aragua
- Attribution confidence
- HIGH
- Nation-state nexus
- Venezuela
- Motivation
- FINANCIAL
- Target sectors
- finance, banking, credit unions
- Target regions
- North America, united states of america
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre
Malware and tooling: AnyDesk, Ploutus, Ploutus-D, Prometheus, AnyDesk
How Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre works
Anibal Alexander Canelon Aguirre, alias 'Prometheus' and 'The Engineer', alleged developer of the Ploutus ATM malware and an FBI Ten Most Wanted Fugitive since March 2026, has appeared in US court after arrest. He is charged in the District of Nebraska in connection with Tren de Aragua (TdA) ATM jackpotting that stole over $5.4 million across 63 bank ATM attacks between February 2024 and December 2025.
Anibal Alexander Canelon Aguirre (reported as 49 in earlier coverage, 50 in the October 2026 BleepingComputer report) is alleged to have created and supported the Ploutus ATM malware used in a nationwide 'jackpotting' conspiracy linked to the Venezuelan gang Tren de Aragua (TdA). TdA was designated a transnational criminal organization in July 2024 and a foreign terrorist organization in February 2025; prosecutors allege the proceeds funded the group. A federal arrest warrant was issued on 2025-12-09, the FBI offered up to $1 million for information, and he was added to the FBI Ten Most Wanted list in March 2026. He is charged with conspiracy to commit bank fraud, conspiracy to commit bank burglary and computer fraud (intentional damage to a protected computer), conspiracy to commit money laundering, and conspiracy to provide material support to terrorists. OFAC sanctioned eight TdA members including Canelon Aguirre.
The scheme sent crews to ATMs in 47 US states and the District of Columbia. Per DOJ/BleepingComputer figures, about $5.4 million was stolen in 63 bank ATM jackpottings, with 54 attacks on credit unions, roughly $1.43 million in attempted but failed attacks, and a total reported above $6.8 million. A single Nebraska credit union loss reached about $300,000. 98 TdA-linked suspects have been charged since October 2025 per the October 2026 report (87 in the Nebraska indictments by January 2026, and at least 119 people charged across related cases per The Record), with maximum sentences cited from 20 to 335 years. Sentenced defendants include Juan Manuel Gouveia-Aguilera (8 years, about $3.5M in losses).
Attack chain per DOJ/FBI reporting: crews obtain physical access to the ATM cabinet with generic master keys or lock-picking, then either swap in a hard drive preloaded with Ploutus, remove and infect the existing drive, or copy the malware over via USB/removable media. Ploutus abuses the XFS (eXtensions for Financial Services) layer that mediates between Windows and ATM hardware (dispenser, PIN pad), allowing the operator to command cash dispensing without a customer account debit; cash-outs complete in minutes. The malware includes anti-analysis/anti-debugging protection utilities and self-deletion capability to hinder forensics. Ploutus has been tracked since 2013 (Mexico, first reported by Symantec); the Ploutus-D variant (FireEye) targets the Kalignite multivendor platform, and Diebold Nixdorf Opteva 500/700 ATMs were targeted in earlier campaigns. FBI FLASH-20260219-001 (2026-02-19) reported 700+ jackpotting incidents and $20M+ in losses in 2025 (about 1,900 incidents since 2020) and published host IOCs (file names, scripts, MD5 hashes). No CVEs are cited; the attack relies on physical access and weak ATM hardening. The MD5 values in the FLASH could not be retrieved as readable text in this run and are therefore not included.
MITRE ATT&CK techniques used in TL-2026-2939
Defense Evasion
T1027 Obfuscated Files or Information; T1070.004 File Deletion; T1622 Debugger Evasion
Execution
T1059.003 Windows Command Shell
Initial Access
T1091 Replication Through Removable Media
Command and Control
Impact
Affected products and versions in Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre
- Diebold Nixdorf — Opteva 500/700 series ATMs and other Windows-based ATMs
Vulnerable versions: Windows XP and later based ATM software stacks - KAL — Kalignite multivendor ATM platform
Vulnerable versions: Ploutus-D targeted
Remediation for Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre
Immediate actions
- Hunt ATM fleets for the FBI FLASH-20260219-001 file names (Newage.exe, Color.exe, Levantaito.exe, NCRApp.exe, sdelete.exe, Promo.exe, WinMonitor.exe, WinMonitorCheck.exe, Anydesk1.exe) and scripts (C.dat, Restaurar.bat, Restauraropteva.bat, Logcontrol.txt, Logc.txt, Borrar_beta.txt)
- Alert on ATM cabinet/hood open events, hard drive removal and unexpected dispenser activity outside customer transactions
- Review ATM physical keys and replace generic/default locks
Workarounds
- Disable or remove remote access tooling on ATMs not required for support
- Retain ATM forensic images before reimaging, since Ploutus can self-delete
Longer-term hardening
- Enable full-disk encryption and secure/measured boot on ATM hard drives, and disable booting from removable media
- Enforce application allowlisting on ATM endpoints and block USB mass storage
- Monitor XFS/dispenser command activity for commands not tied to an authorized host transaction
- Migrate ATMs off unsupported Windows XP/legacy builds
Timeline of Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre
- Ploutus ATM malware first detected in Mexico (year-level date; reported by Symantec), originally driven by external keyboard or SMS commands
- Start of the Tren de Aragua Ploutus ATM jackpotting activity charged in the Nebraska indictments (February 2024; FBI cites activity since at least January 2024)
- Tren de Aragua designated a transnational criminal organization (month-level date)
- Tren de Aragua designated a foreign terrorist organization (month-level date)
- First Nebraska grand jury indictment of 32 individuals in the ATM jackpotting scheme
- Federal arrest warrant issued for Anibal Canelon Aguirre; FBI offers up to $1 million reward
- DOJ announces Nebraska grand jury indictment of 54 people for Ploutus-enabled ATM jackpotting
- Additional indictment charges 31 more defendants, totaling 87 charged
- FBI FLASH-20260219-001 published with Ploutus host IOCs; 700+ incidents and $20M+ losses reported for 2025
- Canelon Aguirre added to the FBI Ten Most Wanted Fugitives list (March 2026, month-level date)
- BleepingComputer reports Canelon Aguirre has appeared in US court after arrest; 98 TdA-linked suspects charged since October 2025
Sources cited for Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre
- BleepingComputer: Suspected dev of Ploutus ATM malware appears in US court after arrest
- FBI FLASH-20260219-001: ATM Jackpotting (IC3)
- TechCrunch: FBI says ATM jackpotting attacks are on the rise
- Security Affairs: FBI warns of surge in ATM Jackpotting, $20 Million lost in 2025
- The Record: Kansas ATM jackpotting guilty pleas
- KTIV: Nebraska grand jury indicts dozens more, totaling 87 charged defendants
- KNOP: Federal grand jury in Nebraska indicts 54 people in ATM jackpotting scheme
- Rescana: DOJ charges 54 in Ploutus ATM jackpotting attacks (Diebold Nixdorf, Kalignite)
- BankInfoSecurity: First ATM jackpotting attacks hit US (Ploutus-D / Kalignite)
Detection coverage for TL-2026-2939
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2939 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.