Jurojin Says Targeted Update Tampering Exposed High-Stakes Players’ Hole Cards

The poker software maker says manually swapped update packages sometimes installed remote-access tools, but not every exposed user was infected.

Jurojin Poker said an attacker manually replaced software-update packages sent to a specific group of users between June 2025 and January 2026, in a targeted scheme aimed largely at high-stakes opponents. Some altered packages carried remote-access software that could let the attacker view players’ hole cards remotely, the company said.

The company described it as a “highly targeted operation,” rather than a mass attack. Jurojin said the actor, whom it characterized as a known cheater, selected users individually and swapped their updates by hand instead of using an automated blast.

The notice adds Jurojin’s account to the suspected remote-access compromise affecting poker players’ PCs that we reported on Sept. 30. Jurojin said only a handful of high-stakes players were harmed by playing against the attacker while their cards were exposed, although it identified a limited group of accounts that may have received tampered updates.

Receiving a tampered package did not necessarily mean a computer was infected, Jurojin said. Not every modified package included the remote-access tool. The company retained logs of each compromised version and the dates it was served, and said no further material was uploaded to its servers after Jan. 28.

SpadePoker reported that the attacker gained access to Jurojin’s server keys and an admin-panel account. Its account said the altered packages used a fake executable to install Mesh Agent, MeshCentral’s legitimate remote-management tool, before launching the digitally signed Jurojin application. Such access could allow an operator to watch a victim’s screen and control the PC, according to separate reporting by Casino.org and PokerShield.

The timeline in Jurojin’s new notice differs from an earlier PokerNews report, which said compromised updates had been served through June 2026. Jurojin’s current account places the end of the upload activity in January and says stronger authentication and rotated keys stopped the scheme.

Jurojin said the same actor also targeted other applications, including IntuitiveTables, and ran phishing sites impersonating poker rooms and established poker tools. It has contacted every user it identified as potentially affected, provided findings to cybersecurity, anti-fraud and law-enforcement authorities, and worked with Amazon Web Services, investigators, poker-room security teams and researcher Wolf.

Following the incident, the company began logging every server download, strengthened administrative audit trails, restricted access to sensitive configuration, and added multiple authentication factors where server data can be edited or deleted. Jurojin recommends that users who may have been affected perform a clean Windows reinstall.

21+ in OH. Please play responsibly. For help, call the Ohio Problem Gambling Helpline at 1-800-589-9966 or 1-800-GAMBLER.
published 1 hour, 47 minutes ago • by Team F5 • permalink

Keep Reading:

« Back to Homepage