The FBI confirmed arrest of first cyber fugitive on the 10 most wanted list, for four federal charges.
US authorities have apprehended Anibal Alexander Canelon Aguirre, also known as “Prometheus” and “The Engineer”, a Venezuelan national identified by the FBI as a senior figure in the transnational criminal organisation Tren de Aragua (TdA), the
most powerful criminal organisation in Venezuela and the only local group that has managed to establish a foothold abroad.
The case centres on ATM jackpotting and malware. According to the indictment and the Department of Justice (DoJ), Aguirre is alleged to have developed Ploutus, malware designed to compromise ATMs and force them to dispense cash without corresponding withdrawals from legitimate accounts. Investigators describe him as one of the principal leaders of a wider ATM-jackpotting conspiracy linked to TdA.
The malware allegedly incorporated anti-analysis and anti-forensic capabilities, including mechanisms intended to hinder reverse engineering and debugging, as well as functionality designed to remove traces of the malware from compromised systems. The Nebraska investigation has so far resulted in charges against 120 defendants, while investigators say ATM jackpotting activity associated with the conspiracy has targeted or been carried out in 47 US states, the District of Columbia and several foreign countries. Three defendants have already received prison sentences ranging from 78 to 96 months.
Aguirre was added to the FBI’s Ten Most Wanted Fugitives list in March 2026 and was the first cybercrime fugitive to appear on the list, according to the DoJ. He appeared before a federal court in Nebraska on 2 October, pleaded not guilty to four charges and was ordered to remain detained pending trial. His apprehension follows a multi-agency investigation led by the FBI and Homeland Security Investigations (HSI), supported by the DoJ’s Joint Task Force Vulcan and other US and international partners.
The four federal charges against Aguirre are conspiracy to commit bank fraud; conspiracy to commit bank burglary and computer-related fraud; conspiracy to commit money laundering; and conspiracy to provide material support to terrorists. The last charge reflects the US government’s designation of TdA as a Foreign Terrorist Organization, while the Treasury Department separately sanctioned Aguirre and nine other individuals on 30 September over what it described as a TdA financial network responsible for stealing millions of dollars from US banks.
The wider Homeland Security Task Force brings together agencies including the FBI, HSI, DEA, ATF, US Marshals Service, Postal Inspection Service and IRS Criminal Investigation. According to FBI, the objective is to pursue not only individuals directly carrying out attacks but also the technical developers, financial facilitators and organisational leadership behind them. Aguirre’s apprehension therefore represents an investigation extending across cybercrime, financial crime, organised crime and counter-terrorism jurisdictions.
Why does it matter?
The investigation demonstrates the increasingly international character of responses to cyber-enabled organised crime. The Nebraska prosecution involves the FBI, HSI, DoJ’s Computer Crime and Intellectual Property Section and Joint Task Force Vulcan, with assistance from the Justice Department’s Office of International Affairs, its Judicial Attaché in Bogotá and the US Secret Service.
The case illustrates how cyber-enabled financial crime can become integrated into the revenue-generating structures of a transnational criminal organisation. Rather than treating malware development, ATM compromise, cash extraction and money laundering as separate activities, US investigators describe an interconnected ecosystem in which specialised technical capabilities supported physical criminal operations and generated illicit proceeds.
It also demonstrates how cybercrime and transnational organised crime are becoming increasingly intertwinned, particularly where malware becomes an enabling technology for physical theft and criminal finance. ATM jackpotting demonstrates that cyberattacks do not necessarily seek data or digital disruption: compromising a networked financial device can be used directly to produce physical cash. The alleged use of anti-analysis and self-removal capabilities also illustrates how criminal malware developers increasingly incorporate techniques intended to complicate forensic investigation and attribution.
The case shows how specialised cyber capabilities can be embedded within distributed criminal networks, with developers, operators, money launderers and organisational leaders potentially located in different jurisdictions. It also highlights the operational importance of combining cyber investigation, financial intelligence, international law enforcement cooperation and disruption of criminal leadership when addressing cyber-enabled transnational crime. The charges remain allegations, and Aguirre is presumed innocent unless proven guilty in court.
Click Here For The Original Source.
