Alleged dev of Ploutus ATM malware appears in US court after arrest
Description
The alleged developer of Ploutus malware, used in ATM jackpotting attacks across the United States, was arrested and appeared in US court. Ploutus malware enabled criminals to steal millions of dollars by compromising ATMs, with attacks occurring between February 2024 and December 2025. The malware included anti-analysis features to hinder forensic investigation and attempted to conceal its presence by deleting itself from infected ATMs. The criminal operation was linked to the Venezuelan Tren de Aragua gang, which laundered stolen funds internationally. The DOJ charged the developer with multiple offenses including bank fraud conspiracy and providing material support to terrorists. The attacks targeted financial institutions in 47 US states and several foreign countries, resulting in over $5.4 million stolen in confirmed incidents and additional attempted thefts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Ploutus malware, developed by Anibal Alexander Canelon Aguirre, facilitated ATM jackpotting attacks that stole millions from banks and credit unions in the US from 2024 to 2025. The malware incorporated anti-analysis and self-deletion mechanisms to evade detection and forensic analysis. The criminal network laundering the stolen funds was connected to the Tren de Aragua Venezuelan gang, designated as a transnational criminal and foreign terrorist organization by US authorities. The DOJ has charged the developer and numerous accomplices with serious crimes including conspiracy to commit bank fraud, money laundering, and providing material support to terrorists. The attacks spanned 47 states and the District of Columbia, with at least 63 bank and 54 credit union ATMs compromised. The FBI has linked these crimes to a surge in ATM hacking losses exceeding $20 million in 2025.
Potential Impact
The Ploutus malware enabled attackers to steal over $5.4 million in confirmed ATM jackpotting incidents and caused additional attempted thefts totaling more than $1.4 million. The attacks compromised ATMs across 47 US states and the District of Columbia, severely impacting financial institutions. The criminal organization involved is linked to a designated foreign terrorist group, increasing the severity of the threat. The malware's anti-forensic features complicated detection and response efforts, allowing prolonged fraudulent activity. The arrests and charges against the developer and accomplices aim to disrupt this extensive criminal operation.
Defensive Guidance
The vendor advisory or patch information is not applicable as this is a criminal malware campaign rather than a software vulnerability. Mitigation focuses on law enforcement actions, arrests, and sanctions against the perpetrators. Financial institutions should continue to implement ATM security best practices and monitor for suspicious activity, but no specific patch or fix exists for the malware itself. The DOJ and FBI are actively prosecuting involved individuals and disrupting the criminal network.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/","fetched":true,"fetchedAt":"2026-10-05T13:03:37.748Z","wordCount":931}
Threat ID: 6ac3a02b2cdf04f656009d63
Added to database: 10/05/2026, 13:03:39 UTC
Last enriched: 10/05/2026, 13:03:45 UTC
Last updated: 10/05/2026, 19:18:35 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.