Ploutus-D Malware: How to Detect & Block ATM Jackpotting Attacks

SOC Briefing Summary :: Executive Key Takeaways
- [01]US authorities captured Anibal Canelon Aguirre (Prometheus), primary developer of Ploutus-D malware and first cybercriminal on FBI Top 10 Most Wanted.
- [02]Ploutus-D bypasses banking controls by abusing Kalignite CEN/XFS middleware, issuing direct hardware dispense commands to steal tens of thousands in cash.
- [03]Stolen cash ($40.7M+ across 1,500 ATMs) was laundered into TRON USDT; banks must enforce CDU cryptographic pairing, port locks, and XFS integrity monitoring.
Executive Summary
In a landmark international cybercrime operation, United States federal law enforcement and the US Coast Guard apprehended 50-year-old Venezuelan national Anibal Alexander Canelon Aguirre (known in criminal networks as "Prometheus" and "The Engineer"). Canelon Aguirre made history in March 2026 as the first cybercriminal ever placed on the FBI's "Ten Most Wanted Fugitives" list, serving as the principal software architect of the notorious Ploutus-D ATM jackpotting malware for the transnational criminal syndicate Tren de Aragua (TdA).
Arraigned in the US District Court for the District of Nebraska, Canelon Aguirre faces federal charges of bank fraud conspiracy and providing material support to a foreign terrorist organization. According to court records and US Treasury Department Office of Foreign Assets Control (OFAC) advisories, Ploutus-D fueled a massive cross-border crime wave: over 1,500 ATM jackpotting attacks yielded upwards of $40.7 million in stolen physical currency, including $5.1 million extracted from 117 American banks and credit unions.
The stolen cash was systematically laundered into cryptocurrency networks—predominantly TRON (USDT)—routing more than $35 million through sanctioned wallets to fund cartel violent operations, drug trafficking, and human smuggling. This dispatch dissects the technical anatomy of Ploutus-D, detailing how it subverts multi-vendor KAL Kalignite and CEN/XFS middleware architectures, and provides financial institutions with actionable detection rules, physical countermeasures, and cryptographic hardware defense playbooks.
---
Technical Vulnerability Analysis & Attack Chain
ATM jackpotting represents a hybrid physical-cyber attack vector that bypasses transactional core banking authorization by directly interrogating the automated teller machine's internal hardware bus.

Root-Cause & Exploitation Mechanics
Ploutus-D operates by neutralizing the software layers separating the operating system from physical mechanical dispensers:
- Physical Upper Chassis Penetration: Attack crews deploy specialized lock picks, duplicate keys, or drill chassis access holes into the ATM upper fascia (the service area housing the PC core). Crucially, the attackers do not need to breach the lower heavy safe vault where currency is stored; accessing the PC core motherboard provides direct bus connectivity to the cash dispenser mechanisms.
- Direct Port Interfacing: Operators insert bootable USB flash drives, connect micro-keyboards, or attach physical bus tap devices to exposed internal USB or serial ports.
- Termination of Endpoint Defenses: Upon execution, Ploutus-D terminates local antivirus and telemetry agents, stops diagnostic monitoring services, and modifies local Windows registry hives to maintain execution persistence across reboot cycles.
- Kalignite and CEN/XFS Architecture Abuse: Modern multi-vendor ATMs utilize the European Committee for Standardization (CEN) Extensions for Financial Services (XFS) standard, commonly implemented via KAL Kalignite middleware. This middleware enables standardized software to control hardware components across more than 40 different ATM manufacturers (including Diebold, NCR, and Wincor Nixdorf). Ploutus-D dynamically resolves and hooks Kalignite communication libraries, locating functions such as
WFSExecuteand cash dispenser command structures (WFS_CMD_CDM_DISPENSE). - Authorization Bypass & Cassette Solenoid Command: Bypassing card readers, transaction processing hosts, and account ledger balances entirely, Ploutus-D instructs the Cash Dispenser Unit (CDU) firmware to dispense stacks of maximum denomination bills. Operatives trigger dispense routines via key combinations on attached pin pads, external numeric keyboards, or SMS-relay commands.
- Cryptocurrency Conversion via TRON: Cash mules transport the physical bank notes to regional over-the-counter (OTC) money laundering brokers in Colombia, Mexico, and Venezuela, converting the proceeds into Tether (USDT) on the high-throughput TRON blockchain network across sanctioned wallets.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1200 | Hardware Additions | Physically accessing ATM chassis to attach rogue USB storage, keyboards, or bus probes. |
| Execution | T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Executing Ploutus-D droppers and payload installers directly on the ATM host PC. |
| Defense Evasion | T1562.001 | Impair Defenses: Disable Security Tools | Terminating host EDR processes, monitoring agents, and hardware diagnostic services. |
| Defense Evasion | T1055 | Process Injection / DLL Hijacking | Injecting malicious code into native Kalignite middleware and XFS manager processes. |
| Defense Evasion | T1556 | Modify Authentication Process | Overriding bank card verification and host network transaction authorization checks. |
| Collection | T1052.001 | Exfiltration Over Physical Bus | Interfacing with the internal serial/USB bus to command the Cash Dispenser Unit (CDU). |
| Impact | T1499 | Endpoint Denial of Service: Hardware Exhaustion | Emptying physical cash cassettes, leaving ATM terminals in an out-of-service state. |
| Command & Control | T1048 | Exfiltration Over Alternative Protocol: Crypto Laundering | Funneling illicit cash into decentralized TRON blockchain addresses to finance cartel operations. |
---
Threat Actor Profile & Campaign Attribution
The arrest of Anibal Canelon Aguirre provides rare operational visibility into the convergence of violent transnational cartels and specialized malware developers:
- Tren de Aragua (TdA) Cyber Division: Originating inside Venezuela’s Tocorón prison, Tren de Aragua expanded across South America, Central America, and the United States. Designated a Foreign Terrorist Organization (FTO) by the US government, the group established a dedicated cyber arm to generate millions in untraceable capital.
- Role of "Prometheus" / "The Engineer": Indicted by the US Attorney's Office for the District of Nebraska, Canelon Aguirre was identified as the lead developer responsible for refining Ploutus variants, reverse-engineering Kalignite middleware specifications, and equipping regional field crews with turnkey attack packages.
- Blockchain Laundering Footprint: On-chain forensic investigations by TRM Labs and Chainalysis traced approximately $35 million in jackpotting proceeds through seven TRON addresses sanctioned by OFAC. The addresses interconnected with a broader billion-dollar laundering network headed by Venezuelan national Jorge Figueira.
---
Detection & SOC Mitigation Playbook
1. Concrete Remediation & Workarounds
Financial institutions, ATM deployers, and independent ATM deployers (IADs) must deploy multi-layered physical and software controls:
Step 1: Enforce Cryptographic Hardware Binding between PC Core and Cash Dispenser
Deploy end-to-end authenticated pairing (such as XFS 3.30+ message authentication or vendor-specific MAC cryptographic pairing) between the PC core and the Cash Dispenser Unit (CDU):
- The dispenser must refuse commands from any operating system or application lacking a pre-shared cryptographic session key.
- Firmware updates must require physical hardware keys and dual-custody authorization.
Step 2: Implement Physical Port Hardening and BIOS Security Locks
Enforce strict hardware lockdown across all deployed ATM endpoints (PowerShell audit command):
# PowerShell script to audit removable USB storage status on Windows-based ATM terminals
$UsbStorage = Get-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\USBSTOR"
if ($UsbStorage.Start -ne 4) {
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\USBSTOR" -Name "Start" -Value 4
Write-Output "USBSTOR disabled: External USB drives blocked on ATM terminal."
} else {
Write-Output "USBSTOR already set to Disabled (4)."
}Enforce full-disk encryption with BitLocker (TPM 2.0) to prevent offline modification of system binaries or offline injection of malicious executables.
Step 3: Install Top-Box Physical Tamper Sensors
Equip ATM service enclosures with mechanical micro-switches connected to the alarm panel. If the top fascia is opened without an authenticated electronic service badge, the ATM must immediately purge cryptographic session keys and place the cash dispenser into hard lockout mode.
2. Network & Perimeter Defenses
- Segmented ATM VLANs: Maintain zero-trust network segmentation. ATMs should communicate exclusively with authorized core transaction processing switches using mutual TLS (mTLS).
- Out-of-Band Disconnection Alerting: Trigger critical priority SOC alerts whenever an ATM ceases heartbeat communication or reports abnormal peripheral hardware disconnections.
3. Endpoint Detection & Hunting Query
Validated Sigma Rule (YAML)
title: Ploutus-D ATM Jackpotting Execution and Kalignite XFS Tampering
id: d820a174-6b91-4c10-9192-3a87102e8812
status: experimental
description: Detects suspicious process execution, service manipulation, or unsigned DLL loading associated with Ploutus-D ATM jackpotting malware interacting with Kalignite XFS middleware.
author: CyberNewsAI Threat Research Team
date: 2026/10/08
references:
- https://www.darkreading.com/cyberattacks-data-breaches/venezuelan-cartel-malware-honcho-nabbed-atm-jackpotting
logsource:
category: process_creation
product: windows
detection:
selection_names:
Image|endswith:
- '\Ploutus.exe'
- '\Ploutus-D.exe'
- '\diebold.exe'
- '\dispense.exe'
selection_kalignite_path:
CommandLine|contains:
- 'Kalignite'
- 'XFS'
- 'WFSExecute'
- 'msxfs.dll'
- 'xfs_conf.dll'
selection_tampering:
CommandLine|contains:
- 'net stop "ATM Monitoring"'
- 'sc config "XFS Manager" start= disabled'
- 'taskkill /f /im edr_agent.exe'
condition: selection_names or (selection_kalignite_path and selection_tampering)
falsepositives:
- Legitimate ATM maintenance engineers running diagnostic tools during authorized servicing windows
level: critical
tags:
- attack.execution
- attack.t1059.003
- attack.t1562.001
- attack.t1200Microsoft Sentinel / Defender KQL Hunting Query
// Microsoft Sentinel / Defender for Endpoint: Hunting for Unauthorized ATM XFS Peripheral Interaction
// Detects processes interacting with XFS Manager DLLs outside authorized banking software paths
DeviceProcessEvents
| where TimeGenerated >= ago(14d)
| where ProcessCommandLine has_any ("msxfs.dll", "Kalignite", "WFS_CMD_CDM", "WFSExecute")
| where not(FolderPath has_any (@"\Program Files\KAL\", @"\Program Files\Diebold\", @"\Program Files\NCR\"))
| project TimeGenerated, DeviceName, DeviceId, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, FileName, ProcessCommandLine
| order by EventCount descSplunk Hunting Query (SPL)
index=* sourcetype IN ("WinEventLog:Security", "XmlWinEventLog:Microsoft-Windows-Sysmon/Operational") (EventCode=1 OR EventCode=7)
| where (match(Image, "(?i)(Ploutus|dispense|cdu_test)") OR match(LoadedDll, "(?i)(msxfs\.dll|kalignite.*\.dll)")) AND NOT match(Image, "(?i)(authorized_atm_app\.exe|kal_core\.exe)")
| stats count values(Image) as Executables values(LoadedDll) as LoadedLibraries by host, user
| eval alert="SUSPICIOUS: Potential Ploutus-D ATM Jackpotting Peripheral Hook"
| where count > 0
| sort - count---
| Indicator Type | Value / Pattern | Operational Context |
|---|---|---|
| Malware Family | Ploutus-D | Specialized ATM jackpotting binary targeting Diebold and multi-vendor systems. |
| Target Middleware | KAL Kalignite Platform | Multi-vendor CEN/XFS ATM software platform abused to issue hardware dispense calls. |
| Threat Actor | Tren de Aragua (TdA) | Venezuelan transnational cartel and Foreign Terrorist Organization (FTO). |
| Malware Architect | Anibal Canelon Aguirre | Lead Ploutus-D developer ("Prometheus" / "The Engineer"), captured at sea. |
| Financial Losses | $40.7M+ Across 1,500+ ATMs | Reported aggregate US jackpotting losses documented by OFAC and DOJ. |
| Laundering Protocol | TRON Blockchain (USDT) | Cryptocurrency network utilized to launder stolen cash into sanctioned wallets. |
| Hardware Target | Cash Dispenser Unit (CDU) | Internal mechanical dispensing unit triggered via unauthenticated bus commands. |
Ploutus-DKAL Kalignite Multi-Vendor CEN/XFS PlatformTren de Aragua (TdA) / Anibal Alexander Canelon Aguirre40.7M+ USD across 1,500+ ATM Jackpotting IncidentsTRON Blockchain (USDT)Cash Dispenser Unit (CDU) Physical Solenoids// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
FakeGit: How to Detect & Block 17,000+ Malicious GitHub Repos
FakeGit campaign weaponizes 17,610 GitHub repositories to deploy SmartLoader and StealC malware. Learn how to detect lures, hunt IOCs, and secure credentials.

Fake AI Sites: How to Detect & Block BitB Ad Account Theft
Attackers deploy fake ChatGPT and Gemini portals using Browser-in-the-Browser attacks to hijack corporate ad accounts and bypass real-time MFA defenses.

TA419: How to Detect & Block Chinese AiTM Phishing Attacks
China-aligned actor TA419 impersonates former US White House officials in AiTM phishing campaigns targeting AI policy experts to bypass MFA defenses.