The alleged developer of the Ploutus ATM jackpotting malware appeared in a US federal court on October 2 after being captured in Venezuela, ending a manhunt for the first cybercriminal ever placed on the FBI's Ten Most Wanted Fugitives list.

Anibal Alexander Canelon Aguirre, 50, known as "Prometheus" and "The Engineer," entered not guilty pleas before a US magistrate judge in the District of Nebraska and will remain detained pending trial, the Justice Department announced. Added to the FBI list in March 2026 as its 540th fugitive, Canelon Aguirre was the first person designated a "cyber" fugitive on the list, as reported by UPI.

The charges

A federal grand jury in Nebraska indicted Canelon Aguirre in December 2025 on four conspiracy counts: bank fraud (carrying up to 30 years in prison), bank burglary and fraud in connection with computers, money laundering, and providing material support to terrorists. The Justice Department alleges he was a principal leader of an ATM jackpotting conspiracy tied to Tren de Aragua, the Venezuelan transnational criminal organization designated a foreign terrorist organization.

Prosecutors say the conspiracy targeted or carried out attacks in 47 states, the District of Columbia and several foreign countries. To date, 120 defendants have been charged in the District of Nebraska alone, with three already sentenced to between 78 and 96 months in prison. An indictment is an allegation; all defendants are presumed innocent until proven guilty.

Malware built to vanish

According to the Justice Department, Ploutus — the malware at the center of the case — was engineered to force ATMs to dispense cash without debiting any account. Canelon Aguirre is alleged to have developed the code, which included anti-forensic features: software protection utilities to block reverse-engineering and debugging, plus routines that deleted the malware from infected machines to conceal the intrusion from bank staff.

The crypto rail

The case is the loudest signal yet of a shift in how physical cash crime gets moved: Treasury's Office of Foreign Assets Control says the network converted stolen ATM cash into cryptocurrency and transferred it internationally — much of it through TRON — to finance Tren de Aragua operations.

On September 30, OFAC sanctioned Canelon Aguirre along with a broader network: eight individuals and two Mexico-based companies, plus seven TRON addresses added to the Specially Designated Nationals list, as documented by GBHackers and TRM Labs. The sanctioned TRON addresses received approximately $6.1 million since March 2022, TRM Labs told Cyber Security News. Treasury puts reported US losses from the jackpotting campaign at $40.73 million across more than 1,500 attacks as of August 2025, and the Department of Justice has indicted 98 people over such schemes since October 2025.

The designation makes any transaction with the listed addresses sanctionable for US persons, and effectively walls the wallets off from compliant exchanges and stablecoin issuers. For a gang whose cash-out path ran through TRON transfers, the geometry of the enforcement action — malware charges in Nebraska, terrorist-designation authorities at Treasury, blockchain analytics mapping the flow — shows how tightly physical and on-chain crime tracks are now fused.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.