Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

Published:

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities. Aguirre, who pleaded not guilty to multiple charges, is accused of orchestrating a scheme that has reportedly siphoned millions from ATMs across the United States.

According to the FBI, Aguirre is the primary architect of the Ploutus malware, a sophisticated tool that enables criminals to drain cash from ATMs by linking the machines to personal devices. The Justice Department has previously arrested and convicted numerous individuals involved in this ATM jackpotting scheme, which has resulted in significant financial losses.

Details of the Arrest and Charges

Aguirre, a 50-year-old Venezuelan national, was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, marking a significant milestone as the first cybercriminal to receive this designation. His arrest details remain unclear, with a Justice Department spokesperson stating it would be “inaccurate” to describe his return to the U.S. as an extradition. Reports suggest he was captured in Venezuela last month.

He faces serious charges, including conspiracy to commit bank fraud and money laundering, with potential prison time of up to 70 years if convicted. The Justice Department has linked Aguirre to the violent transnational organization Tren de Aragua, which is believed to have benefited from the proceeds of the ATM thefts.

Impact of the Ploutus Malware

The Ploutus malware has been active since 2013 and is considered one of the most advanced strains targeting ATMs. Cybersecurity experts have tracked over 1,500 ATM jackpotting incidents, resulting in losses exceeding $40 million. While Aguirre has been implicated as a key figure in the malware’s development, experts have not definitively verified his role as the original creator.

U.S. officials have indicated that the funds obtained through these ATM attacks were often laundered through various means, including cryptocurrency and businesses owned by Tren de Aragua members. The Justice Department has emphasized the extensive connections between the Ploutus malware and the criminal organization.

Ongoing Investigations and Legal Proceedings

Aguirre’s case is part of a broader crackdown on ATM jackpotting, with 120 individuals charged in connection with the scheme. The Treasury Department recently sanctioned Aguirre and others involved in laundering the proceeds from these criminal activities. As the legal proceedings unfold, Aguirre remains in detention, awaiting trial.

The implications of this case extend beyond individual accountability, highlighting the ongoing challenges posed by sophisticated cybercriminal operations and the need for robust cybersecurity measures to protect financial institutions and their customers.

For further details on the legal proceedings, refer to The Record.

For more insights into global cybersecurity developments, visit our Global cybersecurity coverage.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...

Vulnerability in Google’s MCP toolbox exposes critical flaws in agent communication protocols

A recently discovered vulnerability in Google's MCP toolbox has raised significant concerns regarding the security of agent communication protocols. The flaw, identified as CVE-2026-97228,...