Skip to main content

Alleged dev of Ploutus ATM malware appears in US court after arrest

0
High
Malwaremalware
Published: 10/05/2026 (10/05/2026, 13:01:45 UTC)
Source: Bleeping Computer

Description

The alleged developer of Ploutus malware, used in ATM jackpotting attacks across the United States, was arrested and appeared in US court. Ploutus malware enabled criminals to steal millions of dollars by compromising ATMs, with attacks occurring between February 2024 and December 2025. The malware included anti-analysis features to hinder forensic investigation and attempted to conceal its presence by deleting itself from infected ATMs. The criminal operation was linked to the Venezuelan Tren de Aragua gang, which laundered stolen funds internationally. The DOJ charged the developer with multiple offenses including bank fraud conspiracy and providing material support to terrorists. The attacks targeted financial institutions in 47 US states and several foreign countries, resulting in over $5.4 million stolen in confirmed incidents and additional attempted thefts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 13:03:45 UTC

Technical Analysis

Ploutus malware, developed by Anibal Alexander Canelon Aguirre, facilitated ATM jackpotting attacks that stole millions from banks and credit unions in the US from 2024 to 2025. The malware incorporated anti-analysis and self-deletion mechanisms to evade detection and forensic analysis. The criminal network laundering the stolen funds was connected to the Tren de Aragua Venezuelan gang, designated as a transnational criminal and foreign terrorist organization by US authorities. The DOJ has charged the developer and numerous accomplices with serious crimes including conspiracy to commit bank fraud, money laundering, and providing material support to terrorists. The attacks spanned 47 states and the District of Columbia, with at least 63 bank and 54 credit union ATMs compromised. The FBI has linked these crimes to a surge in ATM hacking losses exceeding $20 million in 2025.

Potential Impact

The Ploutus malware enabled attackers to steal over $5.4 million in confirmed ATM jackpotting incidents and caused additional attempted thefts totaling more than $1.4 million. The attacks compromised ATMs across 47 US states and the District of Columbia, severely impacting financial institutions. The criminal organization involved is linked to a designated foreign terrorist group, increasing the severity of the threat. The malware's anti-forensic features complicated detection and response efforts, allowing prolonged fraudulent activity. The arrests and charges against the developer and accomplices aim to disrupt this extensive criminal operation.

Defensive Guidance

The vendor advisory or patch information is not applicable as this is a criminal malware campaign rather than a software vulnerability. Mitigation focuses on law enforcement actions, arrests, and sanctions against the perpetrators. Financial institutions should continue to implement ATM security best practices and monitor for suspicious activity, but no specific patch or fix exists for the malware itself. The DOJ and FBI are actively prosecuting involved individuals and disrupting the criminal network.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/","fetched":true,"fetchedAt":"2026-10-05T13:03:37.748Z","wordCount":931}

Threat ID: 6ac3a02b2cdf04f656009d63

Added to database: 10/05/2026, 13:03:39 UTC

Last enriched: 10/05/2026, 13:03:45 UTC

Last updated: 10/05/2026, 19:18:35 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses