FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
Description
An alleged leader of the Tren de Aragua transnational criminal organization and developer of the Ploutus ATM malware, Anibal Alexander Canelon Aguirre, was arrested by the FBI. The Ploutus malware was used in ATM jackpotting attacks across 47 US states, DC, and other countries, enabling attackers to dispense cash fraudulently. The malware included anti-analysis features and could self-delete to evade forensic detection. Canelon Aguirre was on the FBI's top 10 most wanted list for cybercrimes and faces charges including bank burglary, fraud, and money laundering conspiracy. To date, 120 individuals have been charged in connection with this conspiracy, with some already sentenced to prison.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Anibal Alexander Canelon Aguirre, a Venezuelan national and alleged leader of the Tren de Aragua criminal group, was arrested for his role in developing the Ploutus ATM malware used in widespread ATM jackpotting attacks. The malware exploited vulnerabilities in ATM systems to force cash dispensing without account debits. Ploutus featured anti-analysis capabilities and could erase itself from infected systems to avoid detection. The criminal organization targeted US organizations across 47 states and internationally. Canelon Aguirre was indicted along with 21 others in December 2025 and was the first cybercriminal added to the FBI's top 10 most wanted list. The US Treasury sanctioned him prior to his arrest. The operation has led to charges against 120 defendants, with several already sentenced.
Potential Impact
The Ploutus malware enabled attackers to dispense cash from ATMs without debiting accounts, resulting in significant financial losses across numerous US states and other countries. The malware's anti-forensic features complicated incident response and forensic investigations. The criminal activities involved bank burglary, fraud, and money laundering conspiracies, impacting financial institutions and their customers. The arrest of the developer and other defendants disrupts the criminal network responsible for these attacks.
Defensive Guidance
No specific patch or remediation applies as this is a criminal operation involving malware deployment on ATM systems. Law enforcement actions, including arrests and prosecutions, are the primary mitigation. Financial institutions should continue to monitor for ATM jackpotting activity and apply security controls recommended for ATM infrastructure, but no direct technical remediation for Ploutus malware is described in this report.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/fbi-arrests-most-wanted-developer-of-ploutus-atm-malware/","fetched":true,"fetchedAt":"2026-10-06T12:48:22.672Z","wordCount":996}
Threat ID: 6ac4ee182cdf04f656acee2c
Added to database: 10/06/2026, 12:48:24 UTC
Last enriched: 10/06/2026, 12:48:31 UTC
Last updated: 10/06/2026, 12:48:31 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.