Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Anibal Alexander Canelon Aguirre, 50, known in criminal circles as "Prometheus" and "The Engineer," appeared in U.S. federal court on Oct. 2, 2026, charged with orchestrating an ATM jackpotting scheme that stole more than $5 million from 117 financial institutions across 47 states. The arrest, carried out at sea in September 2026 by the U.S. Coast Guard, concludes a manhunt launched in March 2026 when the FBI placed him on its "Ten Most Wanted Fugitives" list — the first cybercriminal in the program's history.
Prosecutors describe Canelon Aguirre as a leader of the Venezuelan cartel Tren de Aragua — designated a Foreign Terrorist Organization by the Trump administration in February 2025 — and the alleged principal architect of the Ploutus-D malware. The case illuminates a critical node of physical-digital convergence: attacks that require no remote vulnerabilities or zero-days, yet generate transnational financial flows subsequently laundered through cryptocurrency networks.
- Anibal Canelon Aguirre, alias "Prometheus," was arrested at sea in September 2026 and appeared in court on Oct. 2, 2026, pleading not guilty; he is the first cybercriminal in the history of the FBI's "Ten Most Wanted" list.
- The Ploutus-D malware manipulates ATM XFS middleware to bypass bank authorization and command cash dispensing directly, requiring physical access to the machine.
- The scheme hit 117 institutions (63 banks and 54 credit unions) in 47 states plus the District of Columbia, with a haul of $5.1 million per the original indictment, while alternative sources cite $5.4 million confirmed plus $1.4 million in failed attempts.
- Proceeds were laundered through cryptocurrency networks in Venezuela, Mexico, and Colombia, including TRON addresses sanctioned by OFAC in September 2025; approximately $35 million was routed to a network associated with Jorge Figueira, charged with laundering roughly $1 billion.
The Technical Mechanism: Why Ploutus-D Still Works in 2026
Ploutus-D is not sophisticated malware in the conventional sense. The Ploutus family was first detected in Mexico in 2013, and its operating principle exploits a persistent architectural feature of the ATM sector: the XFS (eXtensions for Financial Services) middleware, the software layer that mediates between the cash dispenser hardware and bank authorization systems.
The malware inserts itself at this level, intercepting and altering commands between the dispenser and the transaction validation system. The result: the ATM dispenses banknotes with no corresponding account debit or interbank authorization. The entire operation requires physical access — attackers open ATM panels, often with generic keys, remove or replace hard drives with infected versions, then reboot the system.
Integrated anti-forensic countermeasures include termination of security processes, self-deletion, and obfuscation, complicating post-incident analysis. Compatibility with the Kalignite platform, which supports over 40 ATM vendors beyond Diebold, extends the reach well beyond a single manufacturer.
The Scale of the Scheme: Conflicting Numbers and Convergences
The original indictment, cited by Dark Reading, quantifies the damage at $5.1 million stolen from 117 banks and credit unions between February 2024 and December 2025. However, OffSeq and Aviatrix converge on a slightly higher figure: $5.4 million in confirmed incidents, with an additional $1.4 million in unsuccessful theft attempts. The discrepancy between $5.1 and $5.4 million is unresolved in the dossier; it does not emerge whether the higher figure includes or replaces the indictment total.
The geographic distribution was exceptionally broad: 47 states plus the District of Columbia, with 63 commercial bank ATMs and 54 credit union ATMs compromised. The territorial breadth suggests a structured logistical organization, not a sporadic operation by localized crews.
The national context amplifies the phenomenon's scope. According to OFAC data cited by Dark Reading, more than 1,500 jackpotting incidents had occurred by August 2025, totaling $40.7 million. The FBI estimates 2025 damages alone reached $20 million, with roughly 700 machines hit — a figure placing the Canelon Aguirre operation in the context of a systemic escalation, not an isolated exception.
The Cartel as a Terrorist Organization: Financing and Laundering
"Tren de Aragua is using ATM malware as a terrorist financing tool, then moving the cash onto TRON so it looks like ordinary exchange deposits." — Ari Redbord, TRM Labs
The designation of Tren de Aragua as a Foreign Terrorist Organization in February 2025 transformed the investigation's legal framework. Court materials and analyses from TRM Labs and Chainalysis reveal an operational model linking physical cybercrime to terrorism's financial infrastructure: jackpotting generates cash liquidity, which is then converted and moved via blockchain to mask its origin.
The routing through TRON networks — with seven specific addresses sanctioned by OFAC in September 2025 — reflects a tactical choice. TRON offers high throughput and low fees, characteristics favoring its use for volume transfers. According to TRM Labs analysis, approximately $35 million was routed to a network associated with Jorge Figueira, separately charged with laundering roughly $1 billion through cryptocurrency infrastructure.
Kaitlin Martin of Chainalysis confirmed that "criminal organizations are exploiting common infrastructure for laundering," an observation underscoring the commoditization of laundering tools across diverse criminal ecosystems. The "playbook" — in Redbord's term — is identifiable in other foreign terrorist organizations, suggesting a standardization of techniques transcending individual groups.
The Investigation: 120 Defendants, Three Convictions, a Network Still Active
The judicial net cast around Tren de Aragua is substantial: 120 individuals have been charged in connection with the conspiracy, at least 73 cartel members are in custody, and three defendants — Oddry Arnoldo Cabrera Torrealba, Carlos Javier Padron, and Juan Manuel Gouveia Aguilera — have already been convicted. Canelon Aguirre, however, remains detained awaiting trial after entering not-guilty pleas.
U.S. Attorney Lesley A. Woods for the District of Nebraska highlighted the investigative strategy: the district was "the first in the country to develop the investigation and prosecution in a broader conspiracy case, to follow the money to Tren de Aragua and Venezuelan actors." Eugene Kowel, Special Agent in Charge of the FBI Omaha field office, confirmed the objective is "the entire jackpotting network, from the leaders and malware developers to the crews in the United States."
From an evidentiary standpoint, significant limits remain. The U.S. Attorney "declined to comment on the evidence" supporting the attribution to Canelon Aguirre as the author of Ploutus-D, according to Dark Reading. The aliases "Prometheus" and "The Engineer" appear in court documents, but no independent confirmation emerges of their verified association with the defendant. Similarly, the exact circumstances of the at-sea arrest — date, location, manner of identification — have not been disclosed beyond generic confirmation from the U.S. Attorney's Office.
Why It Matters
The Canelon Aguirre case challenges the dominant narrative of cyber threats as a domain of remote vulnerabilities and sophisticated exploits. ATM hardware, XFS middleware, generic physical keys: these elements constitute an attack surface requiring no advanced technical skills, yet yielding million-dollar returns and financing operations with terrorist ambitions.
The on-chain mapping of laundering flows — with OFAC sanctions on specific addresses and analysis of tens of millions in movement — signals an expansion of the Treasury Department's role in financially dismantling organized cybercrime. The infrastructural overlap between Latin American cartels, cryptocurrency networks, and potential terrorist actors is not yet quantified in available documents, but the convergence of techniques is documented.
For financial institutions, the lesson does not lie in a single patch to apply. ATM jackpotting exploits a physical vector that bypasses network perimeter defenses: local hardware security, physical access control, and segmentation between dispensing and authorization systems remain the decisive perimeter. The fact that malware conceived in 2013 continues to generate millions in 2025-2026 indicates a discontinuity between threat maturity and defensive response in the field.
Frequently Asked Questions
What exactly is ATM "jackpotting"?
Jackpotting is an attack technique that forces an ATM to dispense cash without a corresponding authorized transaction. In the Ploutus-D case, the malware intercepts the XFS middleware to command the dispenser directly, bypassing bank controls. It requires physical access to the machine.
Why was Canelon Aguirre labeled the "first cybercriminal" on the FBI Ten Most Wanted list?
According to FBI Omaha SAC Eugene Kowel, cited by Dark Reading, SecurityWeek, and OffSeq, the March 2026 placement recognizes Canelon Aguirre's alleged role as a malware infrastructure developer used to finance a designated terrorist organization, elevating cybercrime to a priority national threat.
What are the discrepancies in the case's financial data?
The original indictment cites $5.1 million stolen, while OffSeq and Aviatrix report $5.4 million in confirmed incidents plus $1.4 million in attempts. The dossier does not clarify whether the alternative figures are inclusive, cumulative, or based on distinct investigative sources.
Information verified against cited sources and current as of publication.
Sources
- https://www.darkreading.com/cyberattacks-data-breaches/venezuelan-cartel-malware-honcho-nabbed-atm-jackpotting
- https://radar.offseq.com/threat/alleged-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest-1897452d76efc7a3
- https://aviatrix.ai/threat-research-center/alleged-dev-ploutus-atm-malware-appears-us-court-after-arrest/
- https://radar.offseq.com/threat/fbi-arrests-most-wanted-developer-of-ploutus-atm-malware-f45f309f5431c13d
- https://www.securityweek.com/fbi-arrests-most-wanted-developer-of-ploutus-atm-malware/
- https://www.darkreading.com/cyber-risk/atm-jackpotting-attacks-surged-2025
- https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.