How malware exposed poker players' hole cards in a real superuser scam, plus how to detect an infection and lock down your device and account.
The short version: the cheat was on the player’s computer, not the poker site
An online poker malware scam is simple to describe: software hidden on your own machine shows someone else what you can see, including your hole cards. That’s the one-line definition. The complication is that in the case that brought this back into the spotlight, nobody had to hack a poker room, break encryption, or bribe an employee. The attacker went after the small, trusted programs that serious grinders install themselves.
Jurojin Poker, a table-management tool used by high-volume players for table layouts and hotkeys, confirmed that an attacker managed to intermittently swap its updates for tampered versions containing remote-access software. The company described it as “a highly targeted operation, not a mass attack,” and said the person behind it was a known cheater going after specific high-stakes opponents to see their cards in real time. According to Jurojin and reporting on the investigation, a second popular program, IntuitiveTables, was also compromised. Neither provider has been accused of knowingly taking part.
The recent poker malware scheme exposed
The malicious payload was built on MeshCentral, a legitimate open-source remote-management platform that IT departments use to support computers from a distance. Installed quietly as a hidden “Mesh Agent,” it could reportedly let whoever held the controls watch an infected player’s screen and operate the machine. At a poker table, that is the whole ballgame: the attacker sees your face-down cards while the hand is still being played.
The scheme was first exposed publicly by cybersecurity researcher “WolfSec0x0” on X, who initially identified somewhere between 10 and 30 affected computers across Europe, North America and Oceania. Jurojin said its compromised updates went out intermittently between June 2025 and January 2026, that only a small group of users was targeted, and that it had contacted potentially affected customers and passed information to law enforcement and poker-site security teams.
Players had already smelled something. PokerNews reported that an account using the name “Paul Gregg” had been flagged before the malware operation became public, with poker coach Patrick Howard sending GGPoker an analysis of unusual results in September without directly accusing anyone. CoinPoker ambassador Patrick Leonard said his site had previously banned an account called “Europe,” registered in Paul Gregg’s name, confiscating more than $100,000 and reimbursing affected players. High-stakes regular Ignacio Morón has said he lost between $100,000 and $200,000 to the suspect account, including roughly $60,000 in a single 15-minute session.
Operators are responding. ACR Poker says it has built a “Screen Shield” feature designed to stop its tables from being visible to screen-capture and screen-sharing programs. For anyone who remembers UltimateBet and “God Mode,” the shape of this is familiar, with one difference that matters: the old superuser scandals lived inside the operator. This one lived inside the player.
How poker malware works: the technical breakdown
Poker cheating software doesn’t need to break the game’s cryptography. It only needs a seat behind your eyes. There are three broad ways it gets there.
Screen capture and card recognition
The crudest method is also the most effective. Remote-access tools stream your desktop frame by frame, so a human on the other end simply reads your cards. Fully automated versions go a step further and run optical character recognition or template matching on the captured pixels, the same basic technique legitimate HUDs and trackers use to parse table data. The output can be piped into a solver, which is why screen capture is the backbone of serious cheating rather than a casual peek.
Memory access and data extraction
A poker client holds the current hand state in memory while you play. Malware with the right privileges can read another process’s memory and pull the same information without ever touching your screen. Worth understanding, though: your client is only told your own hole cards, so reading it exposes you, not the table. That’s exactly why this kind of attack has to be targeted, one victim at a time. The same access also lets an attacker scrape hand histories, tracker databases, saved passwords and browser session cookies off the disk.
Network traffic interception
Poker traffic is encrypted in transit, so sniffing packets on a coffee-shop Wi-Fi network gets an attacker very little on its own. The practical version of this attack happens on the device: malware installs its own root certificate and proxies your connections, decrypting them locally, or it simply reads the data before encryption and after decryption. A VPN protects you from snooping on an untrusted network. It does nothing at all about code already running on your laptop.
Installation is usually the least glamorous part. Tampered software updates, as in the Jurojin case, are the premium route. Below that sit phishing emails impersonating a poker room, cracked or “free” versions of paid tools, HUDs and scripts shared in Discord servers and forums, and plain social engineering, where a friendly fellow grinder sends you a “custom layout file” or asks you to install a screen-share tool for coaching.
What information is at risk
Device malware in a gambling context is rarely after only one thing. Once code runs with your privileges, the whole account is in scope.
| Technique | What it exposes | Main defence |
|---|---|---|
| Remote screen view / capture | Hole cards, bet sizing, timing, table selection | Remove remote-access agents; operator screen-shield features |
| Process memory reading | Live hand state, session data | Patched OS, least-privilege user account, antivirus |
| Keylogging | Passwords, 2FA codes typed manually, PINs | Password manager, app-based 2FA, clean device |
| File and database theft | Hand histories, tracker stats, saved cards, ID documents | Encrypted storage, no KYC scans left on the desktop |
| Session cookie theft | Logged-in access without your password | Log out, revoke sessions, change password after any scare |
The edge a cheater gains from your cards is enormous, but the quieter risk is financial: banking details, e-wallet logins, and the email account that can reset everything else.
How to detect malware on your device
No single sign is proof. A cluster of them is worth acting on.
- Remote-access artefacts you didn’t install: Mesh Agent, RDP enabled, TeamViewer-style services, unfamiliar entries in Task Manager or Activity Monitor.
- Cursor movement, windows opening, or table actions you didn’t make, even briefly.
- Steady CPU use, fan noise or battery drain when you’re idle.
- Unexpected outbound connections. On Windows, netstat -ano plus Task Manager’s Details tab maps connections to processes; macOS and Linux users can use Activity Monitor or lsof -i.
- New scheduled tasks, startup items, browser extensions or root certificates in your trust store.
- Antivirus or Windows Update silently disabled, or scans that fail to complete.
- Login alerts, password-reset emails, or account activity logs showing sessions from places you’ve never been.
If you suspect something, do a full offline scan with your main antivirus and then a second-opinion scan with a different reputable on-demand scanner. Malware that controls the running system can hide from tools inside it, so booting from clean rescue media is better. If a targeted remote-access tool is confirmed, a full reinstall of the operating system is the only honest cleanup, and change every password from a different, trusted device afterwards.
Protecting your poker account and device
Device security essentials
- Install poker software only from the operator’s or developer’s official site, and check publisher signatures or checksums where they’re offered.
- Never run cracked tools, keygens or “free” versions of paid HUDs and table managers.
- Keep the OS, browser and poker clients patched, and keep real-time antivirus on with a weekly full scan.
- Turn off remote desktop and remote-assistance features you don’t use, and uninstall remote-support tools once a technician is done.
- Play from a standard user account rather than an administrator one, and consider a dedicated machine or user profile for poker only.
Account protection measures
- Use a unique, long password per site, generated and stored in a password manager.
- Enable two-factor authentication, preferring an authenticator app or security key over SMS.
- Secure the email address attached to the account with its own 2FA. It’s the master key.
- Switch on every operator control available: withdrawal address whitelisting, login alerts, session history, device management.
- Keep gambling money separate from your main bank account, and don’t store KYC document scans on the same desktop you play from.
Safe gaming practices
Treat any unsolicited file, “layout pack”, script or screen-share request from an opponent or online acquaintance as hostile until proven otherwise. Don’t play on shared or public computers. Avoid logging in over open Wi-Fi without a VPN, while remembering that some operators restrict VPN use in their terms, so check before you connect. If your room offers anti screen-capture protection, use it. And review your own account’s session list every few weeks, the way you would a bank statement. More on this in our online poker security guide.
Red flags: spotting potential cheating
Variance is a brilliant liar, and most “that guy must be cheating” hands are nothing of the sort. Patterns, not single hands, are what matter. Be alert when one opponent folds correctly to your bluffs with no price to justify it, makes thin hero calls that only make sense with information, consistently avoids your strong ranges, or seems to seek out your tables and leaves when you do. A brand new account playing confidently at nosebleed stakes deserves a raised eyebrow, as does a long-term win rate your sample size says shouldn’t exist.
Signs pointing at your own machine rather than theirs: hands in your history you don’t remember playing, brief loss of mouse control mid-session, actions taken at a table you’d left open, or login notifications you can’t explain.
When something feels wrong, gather evidence rather than noise. Save hand histories, note dates, times, stakes and usernames, and send it all to the operator’s security team with a request for a hand-history and collusion review. Report any compromised third-party tool to its developer too, since that’s how the Jurojin case started unravelling. Resist the urge to name names publicly before an investigation, which tips off the suspect and exposes you legally. Sites do act: CoinPoker confiscated more than $100,000 from the banned “Europe” account and reimbursed affected players.
One last thing worth saying plainly. Poker is a negative-expectation game against the rake before anyone cheats, and no amount of security turns it into income. Set deposit and session limits, keep your bankroll separate from money you need, and use the responsible gambling tools your operator provides. If the games have stopped being a game, step away and talk to a support service in your country.
FAQ
What is superuser cheating?
A superuser is an account or program with visibility into information it shouldn’t have, classically face-down cards. The original scandals, such as UltimateBet’s “God Mode,” were built into operator software. The newer version achieves the same result from the outside, by putting remote-access malware on an opponent’s computer.
How does poker malware work?
It gets installed through a tampered update, phishing, cracked software or social engineering, then streams or reads what your poker client displays. The attacker sees your hole cards live and can combine them with your betting patterns, or feed them into a solver.
Can a VPN or antivirus stop this?
Antivirus helps, especially against known tools and suspicious remote-access agents, but a targeted build can slip past it. A VPN encrypts your network traffic and does nothing about malware already on the device. Software hygiene, patching and verified downloads do more heavy lifting than either.
Am I likely to be targeted?
Probably not. This operation hit an estimated 10 to 30 machines and focused on specific high-stakes opponents. The techniques trickle down, though, and the credential and payment theft that rides along with them is indiscriminate.
