# Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre ('Prometheus'/'The Engineer') Appears in US Court; Tren de Aragua ATM Jackpotting Campaign

> Anibal Alexander Canelon Aguirre, alias 'Prometheus' and 'The Engineer', alleged developer of the Ploutus ATM malware and an FBI Ten Most Wanted Fugitive since March 2026, has appeared in US court after arrest. He is charged in the District of Nebraska in connection with Tren de Aragua (TdA) ATM jackpotting that stole over $5.4 million across 63 bank ATM attacks between February 2024 and December 2025.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2939
- **ID:** TL-2026-2939
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** MONITORING
- **Actor:** Tren de Aragua (Venezuela)
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Anibal Alexander Canelon Aguirre (reported as 49 in earlier coverage, 50 in the October 2026 BleepingComputer report) is alleged to have created and supported the Ploutus ATM malware used in a nationwide 'jackpotting' conspiracy linked to the Venezuelan gang Tren de Aragua (TdA). TdA was designated a transnational criminal organization in July 2024 and a foreign terrorist organization in February 2025; prosecutors allege the proceeds funded the group. A federal arrest warrant was issued on 2025-12-09, the FBI offered up to $1 million for information, and he was added to the FBI Ten Most Wanted list in March 2026. He is charged with conspiracy to commit bank fraud, conspiracy to commit bank burglary and computer fraud (intentional damage to a protected computer), conspiracy to commit money laundering, and conspiracy to provide material support to terrorists. OFAC sanctioned eight TdA members including Canelon Aguirre.

The scheme sent crews to ATMs in 47 US states and the District of Columbia. Per DOJ/BleepingComputer figures, about $5.4 million was stolen in 63 bank ATM jackpottings, with 54 attacks on credit unions, roughly $1.43 million in attempted but failed attacks, and a total reported above $6.8 million. A single Nebraska credit union loss reached about $300,000. 98 TdA-linked suspects have been charged since October 2025 per the October 2026 report (87 in the Nebraska indictments by January 2026, and at least 119 people charged across related cases per The Record), with maximum sentences cited from 20 to 335 years. Sentenced defendants include Juan Manuel Gouveia-Aguilera (8 years, about $3.5M in losses).

Attack chain per DOJ/FBI reporting: crews obtain physical access to the ATM cabinet with generic master keys or lock-picking, then either swap in a hard drive preloaded with Ploutus, remove and infect the existing drive, or copy the malware over via USB/removable media. Ploutus abuses the XFS (eXtensions for Financial Services) layer that mediates between Windows and ATM hardware (dispenser, PIN pad), allowing the operator to command cash dispensing without a customer account debit; cash-outs complete in minutes. The malware includes anti-analysis/anti-debugging protection utilities and self-deletion capability to hinder forensics. Ploutus has been tracked since 2013 (Mexico, first reported by Symantec); the Ploutus-D variant (FireEye) targets the Kalignite multivendor platform, and Diebold Nixdorf Opteva 500/700 ATMs were targeted in earlier campaigns. FBI FLASH-20260219-001 (2026-02-19) reported 700+ jackpotting incidents and $20M+ in losses in 2025 (about 1,900 incidents since 2020) and published host IOCs (file names, scripts, MD5 hashes). No CVEs are cited; the attack relies on physical access and weak ATM hardening. The MD5 values in the FLASH could not be retrieved as readable text in this run and are therefore not included.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1027 Obfuscated Files or Information
- T1622 Debugger Evasion
- T1219 Remote Access Tools
- T1657 Financial Theft

## Sources

- [BleepingComputer: Suspected dev of Ploutus ATM malware appears in US court after arrest](https://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/)
- [FBI FLASH-20260219-001: ATM Jackpotting (IC3)](https://www.ic3.gov/CSA/2026/260219.pdf)
- [TechCrunch: FBI says ATM jackpotting attacks are on the rise](https://techcrunch.com/2026/02/19/fbi-says-atm-jackpotting-attacks-are-on-the-rise-and-netting-hackers-millions-in-stolen-cash/)
- [Security Affairs: FBI warns of surge in ATM Jackpotting, $20 Million lost in 2025](https://securityaffairs.com/?p=188281)
- [The Record: Kansas ATM jackpotting guilty pleas](https://therecord.media/kansas-atm-jackpotting-guilty-pleas)
- [KTIV: Nebraska grand jury indicts dozens more, totaling 87 charged defendants](https://www.ktiv.com/2026/01/26/federal-grand-jury-nebraska-indicts-dozens-more-atm-jackpotting-scheme-totaling-87-charged-defendants/)
- [KNOP: Federal grand jury in Nebraska indicts 54 people in ATM jackpotting scheme](https://www.knopnews2.com/2025/12/18/federal-grand-jury-nebraska-indicts-54-people-massive-atm-jackpotting-scheme/)
- [Rescana: DOJ charges 54 in Ploutus ATM jackpotting attacks (Diebold Nixdorf, Kalignite)](https://www.rescana.com/post/u-s-doj-charges-54-in-ploutus-malware-atm-jackpotting-attacks-targeting-diebold-nixdorf-and-kaligni)
- [BankInfoSecurity: First ATM jackpotting attacks hit US (Ploutus-D / Kalignite)](https://www.bankinfosecurity.com/first-cases-atm-jackpotting-hit-us-a-10610)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2939
