Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Corporate

Malware in Jurojin and IntuitiveTables Updates Exposed High-Stakes Hole Cards

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times3 min read
Malware in Jurojin and IntuitiveTables Updates Exposed High-Stakes Hole Cards

A cheater reached high-stakes online poker players through the table-management tools on their own computers, not through the poker rooms. The rooms hold the hand histories and the money, and they are now deciding what to refund and how to stop it happening again.

  • Jurojin Poker, a multi-tabling tool, says an attacker intermittently swapped the update package served to one group of its users between June 2025 and January 2026, and that some of the tampered packages carried a remote-access tool
  • The tool was Mesh Agent, part of the open-source MeshCentral remote-management software, which a security researcher posting on X as WolfSec0x0 says let whoever ran it watch players' screens live, hole cards included, and take over their PCs; the researcher estimates 10 to 30 high-stakes players were affected
  • Jurojin calls it "a highly targeted operation, not a mass attack" by "a known cheater", says the rival tool IntuitiveTables was also targeted, and lists phishing domains imitating GGPoker, ACR Poker and other rooms
  • CoinPoker banned an account and confiscated more than $100,000, according to its ambassadors, GGPoker had been warned about a suspect account in September, and ACR says it has built a "Screen Shield" against screen capture
  • No authority has publicly identified the attacker and no charges have been reported; Jurojin says it has given its logs to law enforcement and that refunds are a matter for the rooms

The Attack Came Through the Tools Players Run Beside the Tables

The scheme surfaced on Tuesday 29 September, when WolfSec0x0 wrote on X that "we've confirmed a covert remote-access agent planted on players' Windows PCs through compromised poker software", according to PokerNews. The agent installed itself as a Windows service and hid its files, and, the researcher said, it meant the attacker "could see everything on screen and reach anything on the PC: browser-saved passwords, session cookies, saved cards". The researcher put the number of affected players at between 10 and 30, all at high stakes, with activity dating back to 2024, Poker.org reported, and said the poker clients themselves, naming GGPoker and ClubWPT Gold, were "not involved in this situation". The two tools were later identified as Jurojin and IntuitiveTables, Poker.org reported.

Jurojin's security notice, last updated on 2 October, gives the vendor's account. It says the attacker "was able to intermittently replace the update package delivered to one specific group of Jurojin users with a tampered version", that "some of those packages included a remote-access tool", and that the swaps were made "by hand by the actor, not a mass or automated blast". The first version, reported by PokerNews on 30 September, put the end of the window at June 2026; the updated notice says the infection timeframe ended in January 2026 and that nothing further was uploaded to its servers after 28 January. Jurojin says only "a handful of high-stakes players" were harmed by playing against the attacker while their cards were exposed, that it has emailed every user who may have received a tampered update, and that it has given its logs to cybersecurity, anti-fraud and law-enforcement authorities. It has published a check tool and advises anyone in doubt to reinstall Windows from scratch. IntuitiveTables had not published a statement that iGaming Times could find.

iGaming glossary: 430+ terms explained.

The same server, according to Jurojin, hosted phishing sites impersonating poker rooms and tools, among them Bodog, Ignition, ACR Poker, GGPoker, PokerKing, the Winning Poker Network and BCPoker. The company stresses that the screen names circulating in the community "are accusations" and that "no official public investigation has confirmed them".

The Rooms Respond, at Different Speeds

CoinPoker appears to have acted first. Its ambassador Mario Mosbock confirmed that the site's security team detected the account, confiscated $100,000 and banned it, PokerNews reported, and fellow ambassador Patrick Leonard wrote that "we didn't know exactly what he was doing, but it was obvious he had more information than other players". Leonard said the account, called "Europe", was registered under the name Paul Gregg and that affected players were reimbursed, according to Casino.org. iGaming Times has not been able to establish who controlled it. Leonard also said that around 100 players had raised suspicions about an account of that name with poker sites years ago, but that it was "allowed to continue playing on those sites, winning and withdrawing at win rates that were likely not possible".

On GGPoker, coach Patrick Howard of Mobius Poker sent the operator an analysis of an account called "Paul Gregg" in September, asking it to investigate without accusing the player of cheating, and said on 2 October that GGPoker had since contacted him, according to PokerNews. The Spanish professional Ignacio Morón estimates he lost between $100,000 and $200,000 to the account, including $60,000 in one 15-minute session. ACR Poker's chief executive Phil Nagy has announced a "Screen Shield" that blocks screen-capture and screen-sharing software while the client runs, and said an investigation is under way, according to Casino.org and PokerStrategy.com. Neither GGPoker nor ACR had published a full statement that iGaming Times could find.

The Weak Point Was Software the Rooms Allow but Do Not Audit

Poker rooms have spent a decade building defences against bots, real-time assistance software and collusion, almost all of them aimed at what happens inside the client and at the account's results. This attack bypassed both: it lived on the victim's machine and was delivered by a trusted vendor's updater, the same supply-chain route that has made software updates a favoured target well beyond gambling. Rooms routinely tell players which third-party tools they may run, which amounts to a soft endorsement of small vendors whose security they do not check. ACR's Screen Shield is a sensible response, but an agent running with system privileges on a player's own computer is a hard adversary for any client-side defence, which is why both Jurojin and WolfSec0x0 tell affected players to wipe their machines. The industry has had its own data breaches and, last month, a regulator's portal left open for nine months; this time the target was the integrity of the game itself.

iGaming glossary: 430+ terms explained.

The Players Saw the Statistics Before the Security Teams Did

A superuser leaves a trail in the results. CoinPoker's ambassadors say it caught the account within a week; Howard's analysis and the complaints Leonard describes suggest the signal was visible elsewhere long before 29 September. That is the same pattern as 2007, when players on the TwoPlusTwo forums exposed the "Potripper" account at Absolute Poker from hand histories, and the Kahnawake Gaming Commission later fined the operator $500,000 and found Russ Hamilton chiefly responsible for the parallel cheating at UltimateBet. The dates also do not line up neatly: Jurojin's window opens in June 2025, while the researcher traces activity to 2024 and Jurojin names other tools and phishing sites run by the same actor. The vendor breach is therefore unlikely to be the whole story, and the question for the rooms is why accounts flagged by their own customers kept playing.

Refunds Will Decide Whether the High-Stakes Pool Stays Online

Jurojin says refunds are the rooms' responsibility because they hold the hand histories and the account records, and CoinPoker has already refunded players while ACR says it is investigating. The rooms did not cause the breach, but the money moved through their tables and into an account they allowed to keep playing. High-stakes online poker depends on a small group of regulars, and the case for playing online at all rests on their belief that the cards are private. Several of the rooms involved operate offshore, outside the licensing regimes of many of the markets they serve, so no regulator is likely to order refunds as Kahnawake once did, and the response will be set by each operator's commercial judgement. With shared liquidity going before Canada's Supreme Court this week, the regulated side of the game has an interest in showing that licensing would have made a difference.

The rooms did not write the malware, but they hold the hand histories, the accounts and the money. How quickly they use all three will decide whether this is remembered as a vendor breach or as online poker's next superuser scandal.

Sources

Citations and primary documents this article references. Captured at the time of writing.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.