← Back to Daily Briefing (#FBIMostWanted)

Ploutus ATM Malware: Arrest of Alleged Developer and Disruption of Tren de Aragua

Published October 7, 2026

In March 2024, the FBI added Aníbal Canelon Aguirre, alleged lead developer of the Ploutus ATM malware family (variants Ploutus.D and Ploutus.E), to its Top 10 Most Wanted Fugitives list; he was apprehended in Nebraska and charged with facilitating a transnational jackpotting campaign linked to the Venezuelan Tren de Aragua gang. Ploutus malware forces ATMs to dispense cash via USB or network‑based delivery, interacting with XFS/CEN/XFS middleware to issue cash‑dispense commands, employing obfuscation, packing, encryption, and a C2 infrastructure for remote activation. The arrest disrupted a key node of the Tren de Aragua cybercrime network and halted ongoing Ploutus‑based jackpotting operations targeting ATMs across the United States and Latin America.

  • Incident Overview
  • Arrest of Aníbal Canelon Aguirre in Nebraska, added to FBI Top 10 Most Wanted.
  • Charges tied to transnational jackpotting campaign supporting Tren de Aragua.
  • DOJ and U.S. Attorney’s Office for District of Nebraska announced the operation.

  • Attack Vector & Malware Mechanics

  • Ploutus.D/E variants delivered via USB physical access or network compromise of ATM hardware.
  • Malware interacts with XFS/CEN/XFS middleware to issue cash‑dispense (jackpotting) commands.
  • Uses code obfuscation, packing, and encryption to evade AV detection.
  • Employs C2 infrastructure for remote activation, monitoring, and command issuance.

  • Threat Group Profile & Impact

  • Linked to Venezuelan transnational criminal organization Tren de Aragua.
  • Targeted ATMs across the United States and Latin America, enabling cash‑out fraud.
  • Disruption halted ongoing jackpotting operations, preventing further financial loss.
  • Marked first cybercriminal appearance on FBI’s Top 10 Most Wanted list.

  • Indicators of Compromise & Defensive Measures

  • IOCs: specific Ploutus binary hashes (not disclosed), USB autorun triggers, anomalous XFS command sequences.
  • Network traffic to known C2 domains/IPs associated with Ploutus infrastructure.
  • Defensive actions: restrict USB ports on ATMs, enforce middleware authentication, monitor XFS call anomalies, deploy behavioral AV/EDR, block C2 indicators.

  • Law Enforcement Action & Outcome

  • FBI apprehended Aguirre following coordinated investigation with Omaha law enforcement.
  • DOJ press release highlighted disruption of a pivotal node in Tren de Aragua’s cybercrime infrastructure.
  • Arrest underscores FBI’s capability to pursue high‑profile cyber fugitives across borders.
  • Ongoing efforts to dismantle remaining Ploutus‑affiliated infrastructure continue.

Related posts

  1. SecurityWeek — FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
  2. The Record by Recorded Future — Alleged ATM malware creator appears in Nebraska court after arrest
  3. Northplattebulletin
  4. Newsweek
  5. Justice
  6. Stl
  7. Youtube
  8. Justice
  9. Radar
  10. Thehackernews
  11. Ground
  12. Bitdefender

LINK COPIED TO CLIPBOARD