MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-05 · via BleepingComputer

Developer of ATM-targeting Ploutus malware arrested after leading multimillion-dollar theft ring

Image via BleepingComputer
Image via BleepingComputer

Federal authorities arrested Anibal Alexander Canelon Aguirre, the alleged creator of Ploutus malware used in extensive ATM jackpotting campaigns that stole over $5.4 million across at least 117 attacks on U.S. banks and credit unions between 2024 and 2025. Canelon Aguirre, who was on the FBI's Most Wanted Fugitives list, allegedly led a criminal organization that deployed sophisticated malware with anti-forensic capabilities designed to avoid detection and hide evidence of compromise on targeted systems. The stolen funds were laundered and transferred to accounts controlled by the Venezuelan Tren de Aragua gang operating internationally.

Expanded Detail

The Ploutus malware represented a significant technical threat due to its sophisticated design elements aimed at evading detection. Beyond simply extracting cash, the code included protective mechanisms to prevent security analysts from studying it and self-deletion routines intended to remove traces of compromise from affected machines. This combination of offensive capability and defensive obfuscation demonstrated considerable engineering effort tailored specifically for targeting financial infrastructure at scale across numerous U.S. states.

The criminal operation's connection to the Venezuelan Tren de Aragua gang illustrates how malware development intersects with organized crime networks operating across borders. The conspiracy's 47-state footprint and involvement of 98 charged suspects by late 2025 underscores the coordination required to execute repeated attacks on disparate financial institutions while managing stolen proceeds across international accounts.

Context

The arrest may disrupt a significant ATM theft operation, potentially reducing immediate jackpotting incidents if key technical expertise becomes unavailable to the criminal network. However, the case suggests that financial institutions face persistent threats from organized groups capable of developing sophisticated malware and coordinating large-scale campaigns. Banks and credit unions may need to reassess ATM security protocols and detection capabilities, while law enforcement coordination across states and international partners could become increasingly important for combating transnational cybercrime operations tied to designated criminal organizations.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Teenage Cybercriminal Arrested as Head of Prolific Ransomware Gang · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Alleged dev of Ploutus ATM malware appears in US court after arrest.” Browse more stories.