Compromised Poker Tools Gave Attacker Remote Access to Players’ Screens

Jurojin and IntuitiveTables builds installed a MeshCentral agent on an estimated 10 to 30 Windows PCs, while the researcher found no compromise of poker-site clients.
Compromised Poker Tools Gave Attacker Remote Access to Players’ Screens
October 01, 2026

Compromised builds of the poker utilities Jurojin and IntuitiveTables installed a MeshCentral remote-access agent on some Windows PCs, giving its controller a live view of victims’ screens and the ability to take control of their computers. That access could have exposed players’ hole cards during real-money games, although the researcher found no compromise of poker sites’ own clients.

The vendors’ confirmations followed a Sept. 29 report by the cybersecurity researcher WolfSec0×0, according to PokerTube. The researcher estimated that 10 to 30 PCs in Europe, North America and Oceania had been affected, and traced the earliest confirmed activity to March 16, 2024. All confirmed machines had had the agent removed or disabled by the time of the report, and no current version of either utility was still delivering it.

MeshCentral is a legitimate open-source remote-management product used for IT support. In this case, its agent was installed without owners’ knowledge through code-signed versions of the poker tools. Once running, it could operate in the background, hide its files, watch a screen live and control the PC. PokerStrategy reported that, where dates were known, the agent had remained installed for months and in some cases more than a year; the attacker was also seen remotely removing the software and deleting scripts.

Jurojin described the incident as a “highly targeted operation, not a mass attack,” aimed at particular, mostly high-stakes opponents. It said the attacker was a known cheater seeking to view opponents’ hole cards remotely. Jurojin also said the same actor had targeted IntuitiveTables and operated phishing sites impersonating poker rooms and established poker tools.

Separately, Jurojin said that from June 2025 through June 2026 an attacker intermittently replaced update packages sent to a specific group of users with tampered versions. Some included a remote-access tool, and June was the final month in which the company served a compromised version. The company said it had privately emailed every user it identified as affected and retained logs of each compromised version and its delivery date for authorities and security teams.

Jurojin said it had rotated the encryption keys used between its application and servers before it discovered the compromise, and that this and other measures stopped the attacker from uploading further material. After discovering the attack, it restricted access to sensitive configuration, began logging every server download and required multiple authentication factors where server data can be edited or deleted.

The company worked with Wolf after the incident came to light and made a machine check available to users. Read-only PowerShell checks can search for a Mesh Agent service, MeshCentral registry entries and a Microsoft Defender exclusion covering the whole C:\Windows folder. Registry entries may remain even after the agent has been removed, potentially allowing a check to identify a prior infection. The researcher also urged poker sites to examine affected accounts for unfamiliar-device logins and review table histories involving opponents who repeatedly played against affected users.