Cybercrime

FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.

Hacker

A Venezuelan national believed to be a leader of Tren de Aragua (TdA)’s ATM jackpotting activities and the developer of the infamous Ploutus ATM malware has been arrested.

According to the US, TdA is a violent transnational criminal organization that engages in different types of trafficking, robbery, fraud, extortion, and various types of financial crimes targeting US organizations, including ATM jackpotting.

The organization is blamed for ATM jackpotting attacks across 47 states, the District of Columbia, and foreign countries.

On October 2, Anibal Alexander Canelon Aguirre, 50, also known as ‘Prometheus’ and ‘The Engineer’, who was sanctioned last week by the US Treasury, appeared in court to face charges associated with his role in TdA.

He has been on the FBI’s top 10 most wanted fugitives list since March 2026, becoming the first individual added to that list for cybercrimes.

Canelon Aguirre was indicted in the US in December 2025 along with 21 other individuals for bank burglary, fraud, and money laundering conspiracy.

Advertisement. Scroll to continue reading.

The US has not shared details on how he was apprehended, but noted that he will remain detained pending trial, after entering not guilty pleas.

According to the US, Canelon Aguirre is one of the masterminds behind the ATM jackpotting attacks carried out by TdA using Ploutus.

Members of the operation exploited vulnerabilities in ATMs to deploy the malware, which allowed them to force the systems to dispense cash without debiting accounts.

Ploutus contained anti-analysis capabilities to hinder forensic analysis and could also erase itself from the infected systems to hide its tracks.

To date, 120 defendants have been charged for their roles in the conspiracy, and three of them have been sentenced to prison: Oddry Arnoldo Cabrera Torrealba, Carlos Javier Padron, and Juan Manuel Gouveia Aguilera.

Related: Alleged ShinyHunters Leader Arrested in Jordan

Related: In Rare Move, Alleged Iranian State Hacker Extradited to US

Related: Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Related: Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Related Content

Malware & Threats

Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

Malware & Threats

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

Cybercrime

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

Cybercrime

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.

Artificial Intelligence

The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.

Tracking & Law Enforcement

Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them.

Malware & Threats

The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

Malware & Threats

The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version