Aníbal Alexander Cañellón Aguirre, 50, appeared before a U.S. court after being arrested on charges of developing the Ploutus malware and leading part of a scheme to steal money directly from ATMs. The U.S. Federal Bureau of Investigation added him to its “Ten Most Wanted” list in March 2026, making him the first cybercriminal to be placed on it.
According to case documents, “jackpotting” attacks were carried out between February 2024 and December 2025, using the malware to empty ATMs belonging to banks and credit unions. Losses exceeded $100,000 in each incident, and the stolen funds totaled more than $5.4 million in 63 attacks on banks and 54 attacks on credit unions, in addition to $1,429,738 in attacks that were not completed.
Malware Designed to Hide Its Traces
The U.S. Department of Justice said that Ploutus, also known as “Prometheus” and “The Engineer,” contained files and procedures designed to resist forensic analysis, including tools to protect the software from reverse engineering and debugging. It also contained files intended to delete the malware from an ATM after use, helping conceal the deployment process and mislead financial institution employees.
These details indicate that the attacks did not rely solely on dispensing cash from the machine, but also involved attempts to reduce the digital evidence available to investigators. However, the source does not explain how each machine was compromised or whether all incidents followed the same technical chain.
Connection to the Tren de Aragua Network
Authorities say that network members laundered the stolen money and transferred it to accounts controlled by the Venezuelan Tren de Aragua (TdA) gang in different countries. The U.S. Treasury Department designated TdA a transnational criminal organization in July 2024, while the U.S. Department of State designated it a foreign terrorist organization in February 2025.
In the previous week, the Office of Foreign Assets Control (OFAC) imposed sanctions on eight TdA members, including Cañellón Aguirre, for their role in jackpotting attacks targeting U.S. financial institutions. The Department of Justice said investigations linked the scheme to attacks carried out against or targeting institutions in 47 U.S. states, the District of Columbia, and several foreign countries.
What Does This Mean for Financial Institutions?
The case shows that protecting ATMs does not stop at securing the central banking network; the machine itself has become an operational target whose compromise can result in a direct loss of cash, while malware may be used to hinder forensic analysis and erase its traces. The connection between the attacks, money laundering, and sanctions also broadens the scope of the response required from security teams to include financial investigations and coordination with law enforcement agencies.
In Nebraska, Cañellón Aguirre was charged in December 2025 with conspiracy to commit bank fraud, conspiracy to launder money, conspiracy to burgle banks, computer-related fraud, and conspiracy to provide material support to terrorists. The maximum penalties prescribed for these charges are 30 years, 20 years, five years, and 15 years, respectively, but the charges do not constitute a conviction.
Since October 2025, the Department of Justice has charged 98 suspects in jackpotting schemes linked to TdA, with maximum penalties ranging from 20 to 335 years for each defendant. The FBI also warned in February that a wave of ATM attacks during 2025 resulted in the theft of more than $20 million.