Full Report
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
Analysis Summary
# Incident Report: Operations Ploutus & Tren de Aragua ATM Jackpotting
## Executive Summary
Anibal Alexander Canelon Aguirre (aka "Prometheus"), the alleged developer of the Ploutus malware, was arrested and charged for leading a massive "jackpotting" conspiracy targeting U.S. financial institutions. Between February 2024 and December 2025, the group successfully stole over $5.4 million from 117 ATMs across 47 states, laundering the proceeds to the Tren de Aragua (TdA) gang. The incident highlights a sophisticated convergence of specialized malware development and transnational organized crime.
## Incident Details
- **Discovery Date:** Late 2024/Early 2025 (escalated investigation)
- **Incident Date:** February 2024 – December 2025
- **Affected Organization:** Multiple Banks and Credit Unions (117+ successful attacks)
- **Sector:** Financial Services / Banking
- **Geography:** 47 U.S. States, District of Columbia, and several foreign nations
## Timeline of Events
### Initial Access
- **Date/Time:** Commencing February 2024
- **Vector:** Physical access to ATM internals
- **Details:** Accomplices physically accessed ATMs to deploy the Ploutus malware directly onto the machines' internal computers.
### Lateral Movement
- **Details:** Not applicable in a traditional network sense; the attack focused on local exploitation of the ATM’s middleware (XFS layer) to control the cash dispensing peripheral.
### Data Exfiltration/Impact
- **Impact:** Forced dispensing of all cash held in the ATM cassettes ("Jackpotting"). Over $5.4 million stolen; an additional $1.4 million in attempted thefts.
### Detection & Response
- **December 2025:** Canelon Aguirre charged in Nebraska; FBI investigation intensifies.
- **March 2026:** Aguirre added to FBI’s "Top 10 Most Wanted Fugitives" list.
- **October 2026:** Aguirre apprehended and appears in U.S. court.
## Attack Methodology
- **Initial Access:** Physical breach of ATM chassis to interface with internal hardware.
- **Persistence:** Not a primary goal; the malware was designed for high-speed theft followed by self-deletion.
- **Defense Evasion:** Use of software protection utilities to prevent reverse-engineering/debugging; automated self-deletion features to remove forensic evidence post-attack.
- **Lateral Movement:** Physical deployment across multiple geographic locations.
- **Impact:** Unauthorized command execution to the ATM dispenser unit to release cash.
## Impact Assessment
- **Financial:** $5.4M+ stolen in successful attacks; $1.4M in attempted losses; individual incidents exceeding $100k each.
- **Data Breach:** Minimal PII risk reported; focus was exclusively on currency theft.
- **Operational:** Disruption of ATM services across 47 states; significant resource drain for forensic recovery.
- **Reputational:** High public visibility due to FBI "Top 10" status and links to a designated terrorist organization (TdA).
## Indicators of Compromise
- **Network indicators:** None provided (attack was largely offline/physical).
- **File indicators:**
- `Ploutus` malware variants (also known as "Prometheus").
- Files containing anti-forensic wrappers/obfuscation.
- **Behavioral indicators:**
- Unauthorized physical access to ATM top-hats or service panels.
- ATMs dispensing large volumes of cash without corresponding transaction logs.
- Presence of unrecognized external devices (e.g., keyboards or mobile phones) attached to internal ATM USB ports.
## Response Actions
- **Containment:** U.S. Treasury and State Department designated Tren de Aragua (TdA) as a transnational criminal/terrorist organization to freeze assets.
- **Eradication:** Large-scale law enforcement sweep resulting in 98 arrests since October 2025.
- **Recovery:** Financial institutions implemented hardware hardening and updated forensic review protocols for ATMs.
## Lessons Learned
- **Physical Security is Cybersecurity:** Technical malware defenses are useless if the physical housing of the ATM can be easily breached to access USB/COM ports.
- **Anti-Forensic Maturity:** Modern ATM malware (Ploutus) is increasingly sophisticated, using debugger detection and self-deletion to hinder incident response.
- **Criminal Synergy:** The partnership between specialized malware developers ("The Engineer") and street-level gangs (TdA) allows for rapid, nationwide scaling of attacks.
## Recommendations
- **Physical Hardening:** Upgrade ATM physical locks to high-security versions and install tilt/vibration sensors linked to silent alarms.
- **Full Disk Encryption (FDE):** Ensure ATM hard drives are encrypted to prevent offline modification of the OS or injection of malware.
- **Trusted Boot:** Implement Secure Boot and code-signing requirements to ensure only authorized financial software can execute.
- **Port Security:** Disable unused physical ports (USB, CD-ROM) and use epoxy or physical blockers on internal headers.