News Date: 2026-10-06
US authorities have taken an alleged developer of the Ploutus ATM malware into custody, marking a significant step in the investigation of a large cash-machine jackpotting operation. Anibal Alexander Canelon Aguirre, also known as Prometheus and The Engineer, is accused of helping organize cyber-enabled theft associated with the Tren de Aragua criminal organization.
Canelon Aguirre appeared in court on October 2 to face charges related to bank burglary, fraud and money-laundering conspiracy. He has pleaded not guilty and remains detained pending trial. Authorities had placed him on the FBI's Ten Most Wanted Fugitives list in March 2026, reportedly making him the first person added to that list primarily for alleged cybercrime.
Malware That Converts Access Into Cash
Ploutus is associated with ATM jackpotting, an attack in which criminals compromise a cash machine and instruct its dispenser to release money without debiting a legitimate account. Such operations can combine malware deployment, physical access, stolen service credentials and teams of cash collectors positioned near targeted machines.
The malware reportedly included anti-analysis functions and the ability to remove itself, complicating forensic investigations. US authorities have linked the wider operation to attacks across 47 states, the District of Columbia and other countries. More than 100 defendants have reportedly been charged in connection with the alleged conspiracy, although individual responsibility must still be established through the courts.
Defensive Priorities for ATM Operators
- Disable unused physical and logical service interfaces.
- Use application allowlisting to prevent unauthorized executables and scripts.
- Separate ATM management networks from general corporate systems.
- Monitor unusual dispenser commands, repeated maintenance sessions and cash-level discrepancies.
- Protect technician credentials with phishing-resistant authentication and short-lived access.
- Correlate surveillance, service activity and endpoint telemetry during investigations.
I believe the arrest illustrates why ATM malware should not be treated as an isolated technical threat. Jackpotting depends on an entire criminal supply chain, including malware developers, access brokers, money launderers and individuals who collect cash. Removing a suspected technical leader can disrupt that chain, but other groups may retain copies of the tools and knowledge. Banks and ATM operators should assume that the techniques will survive and continue strengthening both cyber controls and physical security around cash infrastructure.
