Ploutus ATM Malware Suspect Pleads Not Guilty in Nebraska
Anibal Canelon Aguirre, alleged Ploutus ATM jackpotting architect tied to Tren de Aragua, pleaded not guilty in Nebraska; 1,500 attacks caused $40.7M in losses.

Executive Summary
Anibal Alexander Canelon Aguirre, the Venezuelan national the FBI alleges is the architect of the Ploutus ATM malware family, pleaded not guilty Friday in a Nebraska district court and will remain in detention pending trial. Aguirre, 50, was indicted by a federal grand jury in Nebraska last December on charges of conspiracy to commit bank fraud, conspiracy to commit bank burglary and fraud in connection with computers, money laundering, and providing material support to terrorists. He faces up to 70 years in prison if convicted.
The arraignment marks the first court appearance for a suspect the FBI added to its "Top 10 Most Wanted Fugitives" list in March — the first cybercriminal placed on that list. The case matters to defenders at banks and credit unions because Ploutus is one of the most advanced ATM-focused malware strains in active use, and the DOJ has now tied its deployment to a specific transnational criminal organization, Tren de Aragua, with a documented loss figure: $40.7 million across at least 1,500 jackpotting attacks.
Technical Analysis
Ploutus is not a remote network exploit. According to the Justice Department's description of the scheme, operators physically open the top of an ATM, connect it to a personal device, and install the malware, which then forces the machine to dispense all of its cash — a technique known as ATM jackpotting. Aguirre allegedly tasked others with driving to ATMs and opening them before he remotely installed the malware, with the in-person operators keeping a percentage of proceeds before passing the rest up the chain.
The malware has been tracked by security researchers for more than a decade, with variants used against ATMs across Latin America and the United States since 2013. The Record notes that cybersecurity experts who have followed Ploutus have not been able to verify whether Aguirre is the true developer of the malware — a caveat worth flagging given the DOJ's characterization of him as the "mastermind" and "key architect."
The DOJ attributes 117 ATM jackpotting attacks on banks and credit unions to Aguirre and others between February 2024 and December 2025, generating more than $5.4 million. The group typically targeted ATMs in remote locations, including in Nebraska and other U.S. states. Proceeds were allegedly transferred to Tren de Aragua members who concealed their origin through cryptocurrency or by laundering funds through companies they own in Mexico and elsewhere. Assistant Attorney General A. Tysen Duva described Aguirre as having served as "a key architect of sophisticated malware used to drain ATMs of cash across the United States — technology that helped fuel the criminal operations of the violent transnational organization Tren de Aragua."
In total, 120 people have been charged in connection with the ATM jackpotting scheme, and the Justice Department has secured dozens of arrests and convictions. Last week, the Treasury Department sanctioned Aguirre and several others accused of using businesses and other tools to launder the scheme's proceeds.
The circumstances of Aguirre's apprehension remain unclear. A DOJ spokesperson said it would be "inaccurate" to describe his return as an extradition, and when pressed confirmed Aguirre was not in the United States and had not been extradited — declining to explain how he was legally returned. Fox News reported he was arrested in Venezuela last month. FBI Director Kash Patel said Aguirre is "back in the United States to face justice." The Justice Department has not disclosed when or where he was detained.
Mitigations & Recommendations
Because Ploutus requires physical access to the ATM's top enclosure, the relevant controls are physical and operational rather than patch-based. Financial institutions should review physical security around ATM top hats — tamper sensors, enclosure locks, and camera coverage of the service area — and audit cash-dispensing logs for anomalous full-dispense events that do not correspond to legitimate transactions. The DOJ's pattern of targeting ATMs in remote locations suggests that off-premises and low-traffic machines warrant elevated monitoring. Institutions that have not already done so should coordinate with their ATM vendors on firmware integrity checks and validate that dispensing logic cannot be triggered by an unauthorized locally connected device.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.
