TLDR Malware hidden in poker software updates let a cheater view high-stakes players’ screens and hidden cards in real time. Jurojin Poker and IntuitiveTables were both compromised, with Jurojin’s tampered updates sent between June 2025 and January 2026. CoinPoker banned an account registered in Paul Gregg’s name, confiscated over $100,000, and repaid affected players. One player says he lost between $100,000 and $200,000 to the suspect account. ACR Poker has launched a “Screen Shield” to block screen-capture and screen-sharing programs.
High-stakes online poker players were targeted by a malware attack that let a cheater secretly see their screens and hidden cards in real time. The scheme came to light this week.
The attacker is believed to have broken into third-party software that serious players use to manage several tables at once. These programs also set up hotkeys and other game tools.
Jurojin Poker, one of the software makers affected, confirmed that an attacker swapped some of its updates with tampered versions. Those versions contained remote-access software.
“This was a highly targeted operation, not a mass attack,” Jurojin said. The company described the attacker as a “known cheater” who went after specific high-stakes opponents.
A second program, IntuitiveTables, was also compromised, according to Jurojin and reports on the investigation. Neither company has been accused of knowingly taking part.
How the Malware Worked
The malware was built on MeshCentral, a legitimate tool IT departments use to access computers remotely. Once hidden on a player’s machine, a “Mesh Agent” could reportedly let the attacker watch the screen and control the computer.
In online poker, that means seeing an opponent’s face-down cards while a hand is being played. It gives the cheater a huge edge.
A cybersecurity researcher known as “WolfSec0x0” first exposed the operation on X. The researcher initially found