// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 3 EXPLOIT IN THE LAST 24H→
Anibal Canelon Aguirre, alleged creator of the Ploutus ATM malware, appeared in a Nebraska court on Oct. 2, 2026. For the first time, a financial cybercriminal lands on the FBI's Top 10 Most Wanted list, charged with providing material support to the designated foreign terrorist organization Tren de Aragua.

Anibal Alexander Canelon Aguirre, 50, appeared in a Nebraska federal court on Oct. 2, 2026. He is the first cybercriminal in the history of the FBI's Top 10 Most Wanted Fugitives list — not a ransomware operator, not a nation-state hacker, but an alleged developer of ATM malware. The technical novelty is only part of the story. The Department of Justice charges that he provided "material support" to Tren de Aragua, a designated foreign terrorist organization, through cyber tools.

Key Takeaways
  • Anibal Canelon Aguirre, known as "Prometheus" and "The Engineer," appeared in Nebraska on Oct. 2, 2026; he pleaded not guilty and remains detained.
  • The DOJ alleges the Ploutus malware powered Tren de Aragua operations, with 120 defendants in the conspiracy and confirmed attacks across 47 U.S. states plus the District of Columbia.
  • Ploutus implements anti-analysis measures to block reverse-engineering and debugging, plus self-deletion routines post-execution.
  • The Treasury Department sanctioned Aguirre in the last week of September 2026; the DOJ denied his transfer from Venezuela was a formal extradition.

The Malware That Erases Its Own Tracks

According to the Department of Justice, Ploutus is no rudimentary tool. The malware includes "software protection utilities" to prevent reverse-engineering and debugging, along with files that ensure its self-deletion from the system. These characteristics — typical of APT malware and offensive cyber operations traditionally associated with nation-states — have been applied to a mass financial crime campaign.

Operation requires physical access to the ATM: opening the chassis, connecting an external device, and executing the payload. The combination of physical and logical compromise makes the vector hybrid. Once activated, the malware forces cash dispensing without recording legitimate transactions. The anti-analysis protections hinder forensic dissection.

The identification of Aguirre as a "key architect" of this tool drove his placement on the FBI Top 10 in March 2026, as the 540th individual in the list's history. Cybersecurity experts have not been able to independently verify that Aguirre is the original developer of Ploutus; his position in the malware production chain — primary creator, modifier, or operational manager — is not definitively documented in available sources.

From 117 Attacks to $5.4 Million: The Operational Scope

Quantitative data converge on an extensive campaign but with estimation variables. According to The Record, the period February 2024 through December 2025 recorded 117 ATM jackpotting attacks. BleepingComputer documents over $5.4 million stolen in 63 attacks on banks and 54 on credit unions, with $1,429,738 in unsuccessful attempts. The Record estimates total losses of $40.7 million across roughly 1,500 tracked ATM jackpotting attacks. An FBI alert from February 2026, cited by BleepingComputer, indicates over $20 million stolen in 2025 alone.

Geographic distribution is broad: 47 states plus the District of Columbia, with operations also abroad. The money-laundering model, per the DOJ, involves transfers to TdA members via cryptocurrency or money-laundering firms in Mexico and other jurisdictions. Three convictions have already been handed down in the broader conspiracy: two defendants, Torrealba and Gouveia Aguilera, received 78 and 96 months in prison, respectively.

"Anibal Canelon Aguirre served as a key architect of sophisticated malware used to drain ATMs of cash across the United States — technology that helped fuel the criminal operations of the violent transnational organization Tren de Aragua" — Assistant Attorney General A. Tysen Duva, DOJ Criminal Division

The 'Material Support to Terrorists' Framework Applied to a Developer

The charge of "conspiracy to provide material support to terrorists" — carrying a maximum 15-year sentence — represents a significant extension of the post-9/11 legal framework. The DOJ does not allege that Aguirre committed acts of violence or participated in TdA field operations. The charge rests on the instrumental nexus: the malware as an enabler of a designated terrorist organization's operational capabilities.

This legal construction has consequences for the liability of cyber tool creators. If upheld at trial, it establishes that developing malware for generic criminal purposes can be reclassified as terrorist support when the end user is a designated organization. The criterion is not the developer's specific intent, but knowledge of the end use or the willingness to provide material resources.

Tren de Aragua was designated a foreign terrorist organization by President Trump. In the broader investigative picture, the DOJ has charged 98 defendants since October 2025 for schemes linked to TdA. Aguirre's arrest places financial cybercrime squarely in this national security context.

The Transfer That Was Not an Extradition

One point remains undocumented. Fox News reported that Aguirre was arrested in Venezuela the month before his Nebraska appearance. A DOJ spokesperson called it "inaccurate" to describe the transfer as an extradition, declining to explain the legal mechanism. The dossier contains no information on the precise circumstances of Aguirre's return to the United States.

The documentary gap is significant: the transfer mechanism affects the traceability of international cooperation and procedural guarantees. The DOJ's caution in defining the operation suggests a diplomatic complexity the sources do not clarify.

Why It Matters

The dossier does not specify whether other Ploutus developers remain active or have been identified. The source does not document specific remedial measures for the affected financial institutions. It does not emerge, at this stage, whether the malware's anti-analysis protections actually prevented significant forensic investigations or how much they slowed operator identification.

The case signals a redefinition of the risk profile in the ATM sector: from local financial crime to a component of a transnational operation with a terrorist designation. For financial institution CISOs, the lesson is not in the technical detail of Ploutus — known to the community for over a decade — but in the organizational structure that weaponized it at national scale.

The application of the "material support" framework to a malware developer, if confirmed jurisprudentially, expands the perimeter of criminal liability in the cybercrime sector. The distinction between tool provider and organizational participant thins when the charge rests on the instrumental nexus with a designated entity. This regulatory evolution directly impacts risk models for those who develop, distribute, or commercialize offensive capabilities.

Frequently Asked Questions

What is Ploutus and when was it first documented?

Ploutus is an ATM jackpotting malware: it forces cash dispensing without a legitimate transaction. It has been documented by the cybersecurity community since 2013. The DOJ attributes to Aguirre the role of "key architect" of a sophisticated variant with anti-analysis protections, but independent experts have not verified this attribution definitively.

Why is Aguirre the first cybercriminal on the FBI Top 10?

According to the DOJ, Aguirre is the first individual placed on the Top 10 Most Wanted Fugitives list for exclusively cyber offenses. His addition in March 2026 — as the 540th person in the list's history — reflects the reclassification of financial cybercrime as a national security threat, particularly due to its link to a designated terrorist organization.

What is the maximum sentence Aguirre faces?

If convicted on all counts, Aguirre faces a maximum combined sentence of 70 years: 30 for bank fraud conspiracy, 5 for bank burglary conspiracy and computer fraud, 20 for money laundering conspiracy, and 15 for conspiracy to provide material support to terrorists. He has pleaded not guilty and trial is pending.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. therecord.media
  2. securityweek.com
  3. justice.gov
  4. bleepingcomputer.com
  5. podcast.securityweek.com