Bitcoin Forum
October 07, 2026, 04:35:22 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Suspected Ploutus ATM Malware Developer Appears in U.S. Court  (Read 60 times)
Dave1 (OP)
Hero Member
*****
Offline

Activity: 2184
Merit: 652



View Profile
October 06, 2026, 04:04:12 AM
 #1



https://www.documentcloud.org/documents/28721126-canelon-aguirre-and-accomplices-indictment/

So the US DOJ has arrested the alleged developer of Ploutus malware.

Quote
The Ploutus ATM malware family, first detected in 2013 by Symantec as Backdoor.Ploutus, allows attackers to withdraw cash from an ATM machine on command. The malware is installed by accessing the ATM’s CD-ROM drive and inserting a new boot disk that delivers the Ploutus variant. After connecting an external keyboard to the ATM machine, threat actors must press ‘F8’ to display the hidden trojan window. Once visible, numerous commands can be executed such as pressing ‘F1’ to generate ATM ID, ‘F2’ to activate ATM ID, and ‘F3’ to dispense cash.

https://www.cyber.nj.gov/threat-landscape/malware/atm-malware/ploutus

Anibal Alexander Canelon Aguirre, known as "Prometheus" and "The Engineer", deployed this malware with the help of his accomplishes also name in the court document. As they emptied  bank and credit union automated teller machines (ATMs) in jackpotting attacks between February 2024 and December 2025.

And they have stolen more than $5.4 million stolen in at least 63 ATM jackpottings targeting banks and another 54 against credit unions, plus an additional $1,429,738 in attempted attacks. The money stolen was then laundered to accounts controlled by the Tren de Aragua (TdA) Venezuelan gang in various countries.

So it's a blend of jackpotting plus involvement of trans national group or criminal gangs.

Maximum sentences for this group ranges from  20 to 335 years in prison each.


███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

█▄▄▄██████▄▄▄███████▄▄▄
████████████████████████████
████▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
████▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀██████████▌█████████████▄▄████▀
██████████▄█████▀████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀
 
..PLAY NOW..
Dr.Bitcoin_Strange
Hero Member
*****
Offline

Activity: 1456
Merit: 619


Leading Crypto Sports Betting & Casino Platform


View Profile
October 06, 2026, 08:53:07 AM
 #2

Maximum sentences for this group ranges from  20 to 335 years in prison each.

They have stolen a whole lot of money from 63 ATMs according to the report, so I do not think that 20 years sentence is even enough for such crime, life sentence is perhaps a good punishment for them because they have been operating for a long time and have rubbed people off their had earned money. If authorities can also recover some of the money they have stolen by ceasing their properties and selling it off, that would be nice too.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
NotFuzzyWarm
Legendary
*
Offline

Activity: 4508
Merit: 3592


Evil beware: We have waffles!


View Profile
October 06, 2026, 10:03:22 PM
 #3

What is not reported is how they accessed the internals of the ATM's. You cannot just walk up to one and slip in a disk or plug in a keyboard...

Did they steal them? Have an inside man with access to the internals to plant the malware and plug in a Bluetooth keyboard dongle so they could later just drive up and do the thefts?

- For bitcoin to succeed the community must police itself -    My info useful? Donations welcome!  3NtFuzyWREGoDHWeMczeJzxFZpiLAFJXYr
 -Sole remaining active Primary developer of cgminer, Kano's repo is here  Discord support invite at https://kano.is/
-Support Sidehacks miner development. Donations to:   1BURGERAXHH6Yi6LRybRJK7ybEm5m5HwTr
suzanne5223
Hero Member
*****
Offline

Activity: 3458
Merit: 774


Want top-notch marketing for your brand. Hire me


View Profile WWW
October 06, 2026, 11:56:45 PM
Last edit: Today at 12:57:26 AM by suzanne5223
 #4

What is not reported is how they accessed the internals of the ATM's. You cannot just walk up to one and slip in a disk or plug in a keyboard...

Did they steal them? Have an inside man with access to the internals to plant the malware and plug in a Bluetooth keyboard dongle so they could later just drive up and do the thefts?

There's an indepth information about how the attacker did the operation, the Bitcoin ATM that seems to be affected, and what the BTC ATM operators should look for so their machine won't be another victim of the attack in the link below.

https://rottenwifi.com/ploutus-atm-malware-why-press-f3-for-money-was-really-an-atm-jackpotting-attack/
https://www.cyber.nj.gov/threat-landscape/malware/atm-malware/ploutus
Edit
It's something like this


░░░░██████████████░░░░░▄▄███████████░░░░░░▄████████████░█████░░░▄███████▀
░░░░█████████████░░░░▄██████████████░░░░▄██████████████░█████░▄███████▀
░░░░▀▀▀▀▀▀▀██████░░▄██████▀▀▀▀▀█████░░▄██████▀▀▀▀▀▀▀▀▀▀░████████████▀
░░░░░░░░░░░██████░░█████▀░░░░░░█████░██████▀░░░░░░░░░░░░██████████▀
▄▄▄▄▄
░░░░▄███████░░█████████████████░█████░░░░░░░░░░░░░░██████████▄
█████▄▄▄███████▀
░░░█████████████████░█████▄▄▄▄▄▄▄▄▄▄▄▄▄░████████████▄
█████████████▀
░░░░░████▀▀▀▀▀▀▀▀█████░██████████████████░█████░▀███████▄
██████████▀▀
░░░░░░░████░░░░░░░░█████░██████████████████░█████░░░▀███████▄
.com
.
...🎰 100 FreeSpins | No Wager ... Instant Rakeback + VIP Transfer ... ⚽ Sport's Welcome Pack | Risk-Free ....PLAY NOW..
[/center]
Dave1 (OP)
Hero Member
*****
Offline

Activity: 2184
Merit: 652



View Profile
Today at 02:25:18 AM
 #5

What is not reported is how they accessed the internals of the ATM's. You cannot just walk up to one and slip in a disk or plug in a keyboard...

Did they steal them? Have an inside man with access to the internals to plant the malware and plug in a Bluetooth keyboard dongle so they could later just drive up and do the thefts?

You have to check the second link that I attached here as there is the description on how the criminals attacks the ATM,

Quote
The Ploutus ATM malware family, first detected in 2013 by Symantec as Backdoor.Ploutus, allows attackers to withdraw cash from an ATM machine on command. The malware is installed by accessing the ATM’s CD-ROM drive and inserting a new boot disk that delivers the Ploutus variant. After connecting an external keyboard to the ATM machine, threat actors must press ‘F8’ to display the hidden trojan window. Once visible, numerous commands can be executed such as pressing ‘F1’ to generate ATM ID, ‘F2’ to activate ATM ID, and ‘F3’ to dispense cash.

So the attackers goes to the root, the ATM's CD-ROM and compromised it with a new boot disk that have the malware, then connecting a external keyboard to control everything. So there is no inside man, it's that the attack are sophisticated. Although there is still some questions on how they know the exploit to begin with. They could have a blue print of the machine itself to study and have someone with technical abilities to come up with this kind of exploits.



███████▄▄███▄███▄
███▄▄████████▌████▄
▄██████████████▐███▌
██▄███████████▌████▌
████████▀███████▐▌█
███████████████▌█▌▐
████████▄████████▐▐
██████████████████▌
███████████████▄██▄
██████████████▀▀▀
█████▀███▀▀▀

█▄▄▄██████▄▄▄███████▄▄▄
████████████████████████████
████▌█████▀███▌█████▀▀███████████▄▄▄▄▄▄▄▄
████▌█████▄███▌█████▄███▐███████████████████▄
▐████████████▀███████▄██████████▀▀▀▀▀▀▀▀████▀
▐████████████▄██▄███████████▌█████████▄████▀
▐█████████▀██████████▌█████████████▄▄████▀
██████████▄█████▀████████▐███▌██▄██████▀
██████████████▀███▐███▌██████████████████████
████▀██████▀▀█████████▌███▀▀▀▀███▀▀▀▀▀▀▀████▌
 
      P R E M I E R   B I T C O I N   C A S I N O   &   S P O R T S B O O K      

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

  98%  
RTP

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀

█▀▀
█
█
█
█
█
█
█
█
█
▀▀▀

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 HIGH 
ODDS

 
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▀▀█
█
█
█
█
█
█
█
█
█
▀▀▀
 
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!