Executive Summary
The U.S. Department of Justice arrested Anibal Alexander Canelon Aguirre, alleged developer of Ploutus ATM malware and leader of a criminal organization linked to the Tren de Aragua Venezuelan gang. Between February 2024 and December 2025, Canelon Aguirre and accomplices conducted jackpotting attacks against ATMs across 47 states, stealing over $5.4 million from 63 bank ATMs and 54 credit union machines. The sophisticated malware included anti-analysis features and self-deletion capabilities to evade detection. Financial losses exceeded $100,000 per incident, with stolen funds laundered and transferred to TdA accounts internationally.
This case represents the largest coordinated ATM jackpotting campaign in U.S. history, highlighting the growing sophistication of transnational cybercrime organizations and their ability to monetize physical infrastructure attacks at scale across multiple jurisdictions.
Why This Matters Now
ATM jackpotting attacks have surged 300% since 2024, with over $20 million stolen in 2025 alone. Financial institutions face unprecedented physical and cyber convergence threats as organized crime groups weaponize malware against critical payment infrastructure.
Attack Path Analysis
The Ploutus ATM malware attack involved physical access to ATM systems for initial compromise, followed by privilege escalation through malware deployment with anti-analysis measures. The attackers established persistence and command control mechanisms, exfiltrated cash through jackpotting operations, and caused financial impact exceeding $5.4 million across 117 institutions while laundering proceeds through Tren de Aragua networks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained physical access to ATM systems and deployed Ploutus malware with anti-analysis and anti-debugging capabilities to compromise financial institution infrastructure
MITRE ATT&CK® Techniques
Exploitation for Defense Evasion
Obfuscated Files or Information
Indicator Removal: File Deletion
Hardware Additions
Impair Defenses: Disable or Modify Tools
Exfiltration Over Web Service
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System Security Parameters
Control ID: 2.2.7
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Device Identity and Authentication
Control ID: Device Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
FFIEC IT Examination Handbook – Intrusion Detection and Prevention
Control ID: Information Security
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of Ploutus ATM malware with $5.4 million stolen from bank ATMs requiring enhanced egress security and encrypted traffic monitoring capabilities.
Financial Services
Credit unions suffered $1.4 million in losses from jackpotting attacks necessitating zero trust segmentation and anomaly detection for financial infrastructure protection.
Law Enforcement
FBI's most wanted cybercriminal case requiring multicloud visibility for tracking transnational criminal organizations and their financial crime revenue streams.
Government Administration
Treasury Department sanctions and multi-agency coordination against Tren de Aragua terrorist organization demonstrates need for threat detection and policy enforcement capabilities.
Sources
- Alleged dev of Ploutus ATM malware appears in US court after arresthttps://www.bleepingcomputer.com/news/security/suspected-dev-of-ploutus-atm-malware-appears-in-us-court-after-arrest/Verified
- Apprehended Venezuelan Tren de Aragua Leader on FBI's Top 10 Most Wanted List Appears in Nebraska Federal Courthttps://www.justice.gov/opa/pr/apprehended-venezuelan-tren-de-aragua-leader-fbis-top-10-most-wanted-list-appears-nebraskaVerified
- Anibal Alexander Canelon Aguirre Added to FBI's Ten Most Wanted Fugitives Listhttps://www.fbi.gov/news/stories/anibal-alexander-canelon-aguirre-added-to-fbis-ten-most-wanted-fugitives-listVerified
- Treasury Sanctions Members of Tren de Aragua Criminal Organizationhttps://home.treasury.gov/news/press-releases/jy2567Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius and network reachability of this ATM malware campaign through segmentation and controlled access policies. The criminal network's ability to coordinate across multiple financial institutions would likely be constrained by east-west traffic enforcement and egress controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network-level segmentation policies would likely limit the malware's ability to communicate beyond its immediate network segment and reduce reconnaissance capabilities across the broader financial institution infrastructure
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely constrain the malware's administrative reach by limiting access to cash dispensing mechanisms and reducing the scope of systems accessible through elevated privileges
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain the attackers' ability to move between ATM networks and financial institutions by blocking unauthorized inter-network communications and reducing their operational reach
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely detect and constrain command and control communications between compromised ATMs and external criminal networks, reducing coordination capabilities across the distributed operation
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely limit the malware's ability to communicate jackpotting success or coordinate cash pickup operations by constraining outbound network communications and reducing the efficiency of the criminal operation
While physical cash theft would likely still occur at individual ATM locations, the overall campaign impact would likely be reduced through constrained network coordination and limited ability to scale operations across multiple institutions simultaneously
Impact at a Glance
Affected Business Functions
- ATM Cash Dispensing Services
- Electronic Banking Operations
- Financial Transaction Processing
- Cash Management Systems
Estimated downtime: 2 days
Estimated loss: $6,829,738
ATM transaction logs and potentially customer banking data from compromised ATM systems. The malware included anti-forensic capabilities to delete traces and hinder investigation of the breached systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate ATM networks and financial systems from broader infrastructure with identity-based policy enforcement
- • Deploy egress security controls and FQDN filtering to detect and block unauthorized outbound communications from financial institution networks
- • Establish multicloud visibility and control mechanisms to monitor anomalous interactions and suspicious automation across distributed ATM networks
- • Enable threat detection and anomaly response capabilities to baseline normal ATM behavior and alert on covert tools or remote access attempts
- • Implement encrypted traffic inspection and east-west traffic security to prevent lateral movement between compromised financial systems



