The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The U.S. Department of Justice arrested Anibal Alexander Canelon Aguirre, alleged developer of Ploutus ATM malware and leader of a criminal organization linked to the Tren de Aragua Venezuelan gang. Between February 2024 and December 2025, Canelon Aguirre and accomplices conducted jackpotting attacks against ATMs across 47 states, stealing over $5.4 million from 63 bank ATMs and 54 credit union machines. The sophisticated malware included anti-analysis features and self-deletion capabilities to evade detection. Financial losses exceeded $100,000 per incident, with stolen funds laundered and transferred to TdA accounts internationally.

This case represents the largest coordinated ATM jackpotting campaign in U.S. history, highlighting the growing sophistication of transnational cybercrime organizations and their ability to monetize physical infrastructure attacks at scale across multiple jurisdictions.

Why This Matters Now

ATM jackpotting attacks have surged 300% since 2024, with over $20 million stolen in 2025 alone. Financial institutions face unprecedented physical and cyber convergence threats as organized crime groups weaponize malware against critical payment infrastructure.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Ploutus malware is installed directly on ATM systems to force cash dispensing without valid transactions, featuring anti-analysis protections and self-deletion capabilities to evade forensic detection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the blast radius and network reachability of this ATM malware campaign through segmentation and controlled access policies. The criminal network's ability to coordinate across multiple financial institutions would likely be constrained by east-west traffic enforcement and egress controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network-level segmentation policies would likely limit the malware's ability to communicate beyond its immediate network segment and reduce reconnaissance capabilities across the broader financial institution infrastructure

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely constrain the malware's administrative reach by limiting access to cash dispensing mechanisms and reducing the scope of systems accessible through elevated privileges

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely constrain the attackers' ability to move between ATM networks and financial institutions by blocking unauthorized inter-network communications and reducing their operational reach

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Visibility and control mechanisms would likely detect and constrain command and control communications between compromised ATMs and external criminal networks, reducing coordination capabilities across the distributed operation

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely limit the malware's ability to communicate jackpotting success or coordinate cash pickup operations by constraining outbound network communications and reducing the efficiency of the criminal operation

Impact (Mitigations)

While physical cash theft would likely still occur at individual ATM locations, the overall campaign impact would likely be reduced through constrained network coordination and limited ability to scale operations across multiple institutions simultaneously

Impact at a Glance

Affected Business Functions

  • ATM Cash Dispensing Services
  • Electronic Banking Operations
  • Financial Transaction Processing
  • Cash Management Systems
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $6,829,738

Data Exposure

ATM transaction logs and potentially customer banking data from compromised ATM systems. The malware included anti-forensic capabilities to delete traces and hinder investigation of the breached systems.

Recommended Actions

  • • Implement Zero Trust segmentation to isolate ATM networks and financial systems from broader infrastructure with identity-based policy enforcement
  • • Deploy egress security controls and FQDN filtering to detect and block unauthorized outbound communications from financial institution networks
  • • Establish multicloud visibility and control mechanisms to monitor anomalous interactions and suspicious automation across distributed ATM networks
  • • Enable threat detection and anomaly response capabilities to baseline normal ATM behavior and alert on covert tools or remote access attempts
  • • Implement encrypted traffic inspection and east-west traffic security to prevent lateral movement between compromised financial systems

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image