SCCG · Partners Hub

Targeted Malware Campaign Compromises High-Stakes Poker Players Through Third-Party Software Updates

growfreshsouth-america
Targeted Malware Campaign Compromises High-Stakes Poker Players Through Third-Party Software Updates
AI-generated illustration.

Malware hit high-stakes poker players from June 2025 to January 2026 via compromised updates to Jurojin Poker and IntuitiveTables. It leveraged MeshCentral for potential screen access, affecting 10-30 computers in a targeted campaign. The probe has renewed focus on the flagged Paul Gregg account.

SCCG Take — Poker operators must tighten vetting of third-party tools to limit supply-chain exposure that can undermine game integrity and player confidence.

A cyberattack distributed malware to high-stakes poker players through updates to third-party software. The operation ran between June 2025 and January 2026. Attackers pushed modified updates to select users.

Jurojin Poker confirmed the breach of its software. IntuitiveTables, a tool used for multi-tabling and automation, was also compromised. The malware relied on MeshCentral, a legitimate remote-access tool. This setup could let attackers view screens and expose private cards in live hands.

WolfSec0x0 identified between 10 and 30 potentially affected computers across several regions. The campaign focused on specific high-stakes players rather than a mass breach of the poker community. Focus Gaming News reported these details.

Mechanics of the Targeted Campaign

The attackers used software updates as the delivery method for the malware. Jurojin Poker stated the effort singled out certain high-stakes players. This limited scope distinguished the incident from broader attacks. The approach allowed potential access to real-time game information via remote control of infected systems. MeshCentral provided the technical means for such observation.

Renewed Attention on the Paul Gregg Account

The investigation revived scrutiny of the Paul Gregg account. This account had drawn flags for suspicious activity at CoinPoker and GGPoker. Players raised concerns in September over allegedly unusual results. PokerNews covered the questions surrounding the account. The matter draws comparison to superuser cases from the late 2000s. Available details stop short of linking the malware directly to any specific account gains.

Reporting: Focus Gaming News

Generated by SCCG’s automated editorial system from published source reporting. SCCG Management holds editorial responsibility.

SCCG Media · Daily briefing

Gaming, betting and prediction markets — the desk’s read, every weekday.

Subscribe →

Related

SponsoredMagellan Technologies — SCCG partnerCanadian Lottery Coalition Rebrands as Canadian Alliance for Regulated Gaming to Deliver National VoicePhilippine Authorities Arrest 244 Foreign Nationals in Raids Targeting Illegal Gambling Enclaves
Curated by SCCG · Powered by SCCG Technology