Threat reportMalwareTL-2026-2939

Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre ('Prometheus'/'The Engineer') Appears in US Court; Tren de Aragua ATM Jackpotting Campaign

highMONITORING

Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre (TL-2026-2939), also tracked as ATM jackpotting, is a high-severity malware campaign, first published 2026-10-05. It is attributed to Tren de Aragua (Venezuela) with high confidence, affects Diebold Nixdorf Opteva 500/700 series ATMs and other Windows-based, maps to 7 MITRE ATT&CK techniques (T1027, T1059.003, T1070.004), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
7MITRE ATT&CK
Actors
1Tren de Aragua
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-2939

Threat ID
TL-2026-2939
Also known as
ATM jackpotting, Ploutus jackpotting campaign
Severity
HIGH
Status
MONITORING
Category
MALWARE
First published
Last reviewed
Attribution
Tren de Aragua
Attribution confidence
HIGH
Nation-state nexus
Venezuela
Motivation
FINANCIAL
Target sectors
finance, banking, credit unions
Target regions
North America, united states of america
Detection rules
9
Indicators of compromise
22

Malware and tooling in Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre

Malware and tooling: AnyDesk, Ploutus, Ploutus-D, Prometheus, AnyDesk

How Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre works

Anibal Alexander Canelon Aguirre, alias 'Prometheus' and 'The Engineer', alleged developer of the Ploutus ATM malware and an FBI Ten Most Wanted Fugitive since March 2026, has appeared in US court after arrest. He is charged in the District of Nebraska in connection with Tren de Aragua (TdA) ATM jackpotting that stole over $5.4 million across 63 bank ATM attacks between February 2024 and December 2025.

Anibal Alexander Canelon Aguirre (reported as 49 in earlier coverage, 50 in the October 2026 BleepingComputer report) is alleged to have created and supported the Ploutus ATM malware used in a nationwide 'jackpotting' conspiracy linked to the Venezuelan gang Tren de Aragua (TdA). TdA was designated a transnational criminal organization in July 2024 and a foreign terrorist organization in February 2025; prosecutors allege the proceeds funded the group. A federal arrest warrant was issued on 2025-12-09, the FBI offered up to $1 million for information, and he was added to the FBI Ten Most Wanted list in March 2026. He is charged with conspiracy to commit bank fraud, conspiracy to commit bank burglary and computer fraud (intentional damage to a protected computer), conspiracy to commit money laundering, and conspiracy to provide material support to terrorists. OFAC sanctioned eight TdA members including Canelon Aguirre.

The scheme sent crews to ATMs in 47 US states and the District of Columbia. Per DOJ/BleepingComputer figures, about $5.4 million was stolen in 63 bank ATM jackpottings, with 54 attacks on credit unions, roughly $1.43 million in attempted but failed attacks, and a total reported above $6.8 million. A single Nebraska credit union loss reached about $300,000. 98 TdA-linked suspects have been charged since October 2025 per the October 2026 report (87 in the Nebraska indictments by January 2026, and at least 119 people charged across related cases per The Record), with maximum sentences cited from 20 to 335 years. Sentenced defendants include Juan Manuel Gouveia-Aguilera (8 years, about $3.5M in losses).

Attack chain per DOJ/FBI reporting: crews obtain physical access to the ATM cabinet with generic master keys or lock-picking, then either swap in a hard drive preloaded with Ploutus, remove and infect the existing drive, or copy the malware over via USB/removable media. Ploutus abuses the XFS (eXtensions for Financial Services) layer that mediates between Windows and ATM hardware (dispenser, PIN pad), allowing the operator to command cash dispensing without a customer account debit; cash-outs complete in minutes. The malware includes anti-analysis/anti-debugging protection utilities and self-deletion capability to hinder forensics. Ploutus has been tracked since 2013 (Mexico, first reported by Symantec); the Ploutus-D variant (FireEye) targets the Kalignite multivendor platform, and Diebold Nixdorf Opteva 500/700 ATMs were targeted in earlier campaigns. FBI FLASH-20260219-001 (2026-02-19) reported 700+ jackpotting incidents and $20M+ in losses in 2025 (about 1,900 incidents since 2020) and published host IOCs (file names, scripts, MD5 hashes). No CVEs are cited; the attack relies on physical access and weak ATM hardening. The MD5 values in the FLASH could not be retrieved as readable text in this run and are therefore not included.

MITRE ATT&CK techniques used in TL-2026-2939

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 File Deletion; T1622 Debugger Evasion

Execution

T1059.003 Windows Command Shell

Initial Access

T1091 Replication Through Removable Media

Command and Control

T1219 Remote Access Tools

Impact

T1657 Financial Theft

Affected products and versions in Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre

  • Diebold Nixdorf — Opteva 500/700 series ATMs and other Windows-based ATMs
    Vulnerable versions: Windows XP and later based ATM software stacks
  • KAL — Kalignite multivendor ATM platform
    Vulnerable versions: Ploutus-D targeted

Remediation for Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre

Immediate actions

  • Hunt ATM fleets for the FBI FLASH-20260219-001 file names (Newage.exe, Color.exe, Levantaito.exe, NCRApp.exe, sdelete.exe, Promo.exe, WinMonitor.exe, WinMonitorCheck.exe, Anydesk1.exe) and scripts (C.dat, Restaurar.bat, Restauraropteva.bat, Logcontrol.txt, Logc.txt, Borrar_beta.txt)
  • Alert on ATM cabinet/hood open events, hard drive removal and unexpected dispenser activity outside customer transactions
  • Review ATM physical keys and replace generic/default locks

Workarounds

  • Disable or remove remote access tooling on ATMs not required for support
  • Retain ATM forensic images before reimaging, since Ploutus can self-delete

Longer-term hardening

  • Enable full-disk encryption and secure/measured boot on ATM hard drives, and disable booting from removable media
  • Enforce application allowlisting on ATM endpoints and block USB mass storage
  • Monitor XFS/dispenser command activity for commands not tied to an authorized host transaction
  • Migrate ATMs off unsupported Windows XP/legacy builds

Timeline of Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre

  • Ploutus ATM malware first detected in Mexico (year-level date; reported by Symantec), originally driven by external keyboard or SMS commands
  • Start of the Tren de Aragua Ploutus ATM jackpotting activity charged in the Nebraska indictments (February 2024; FBI cites activity since at least January 2024)
  • Tren de Aragua designated a transnational criminal organization (month-level date)
  • Tren de Aragua designated a foreign terrorist organization (month-level date)
  • First Nebraska grand jury indictment of 32 individuals in the ATM jackpotting scheme
  • Federal arrest warrant issued for Anibal Canelon Aguirre; FBI offers up to $1 million reward
  • DOJ announces Nebraska grand jury indictment of 54 people for Ploutus-enabled ATM jackpotting
  • Additional indictment charges 31 more defendants, totaling 87 charged
  • FBI FLASH-20260219-001 published with Ploutus host IOCs; 700+ incidents and $20M+ losses reported for 2025
  • Canelon Aguirre added to the FBI Ten Most Wanted Fugitives list (March 2026, month-level date)
  • BleepingComputer reports Canelon Aguirre has appeared in US court after arrest; 98 TdA-linked suspects charged since October 2025

Sources cited for Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre

Detection coverage for TL-2026-2939

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2939 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats