Reports Link Mesh Agent Compromise to Alleged High-Stakes Poker Cheating

About 30 players may have had their Windows PCs remotely accessed, exposing hole cards and potentially far more than poker data.

A suspected remote-access compromise of poker players’ Windows PCs may have exposed opponents’ hole cards and other sensitive data, with roughly 30 high-stakes users believed to be affected across Europe, North America and Oceania. The allegations describe Mesh Agent, a legitimate remote-access program, being deployed through compromised software used by poker players.

PokerNews reported the claims based on a thread from the anonymous account @wolfsec0×0. The account alleged that whoever controlled the remote-access server could watch an infected player’s screen in real time, including hole cards, and control their mouse and keyboard. It said the activity could date back to 2024 and did not identify the affected sites or players.

The claimed access extended well beyond poker tables. An infected computer could expose browser-saved passwords, session cookies and saved card information, according to the allegations. Mesh Agent was said to install as a Windows service, conceal its files and launch a system-level process called PowerShield.

PokerListings’ Sept. 30 update identified Canadian player Paul Gregg as the suspected perpetrator, alleging he installed a Trojan on poker regulars’ computers and may have had help from others. The outlet said the malware let the cheater see infected opponents’ hole cards, target them and repeatedly beat them over months.

Players had noticed an unusual playing pattern before the suspected scheme was identified. PokerListings and GipsyTeam both described the suspected cheater winning disproportionately against particular regulars while playing about 90% of his hands against them. GipsyTeam said unusually strong results ultimately helped bring attention to the activity.

PokerListings said its earlier theory that the Trojan came through third-party software had been confirmed in its Sept. 30 update. But the infection route had previously remained unresolved: GipsyTeam, reporting on Sept. 29, listed third-party poker tools, trackers, table-setting programs, phishing emails and a possible exploit among the potential methods. PokerNews also described the compromised program as a third-party tool, rather than poker-site software, based on comments from Todd Witteles.

The alleged losses vary by the reporting and the scope being measured. GipsyTeam said access to computers and cards enabled Gregg, possibly alongside others, to take almost $900,000 on the WPN network alone. It also reported that Aleksey “Avr0ra” Borovkov said more than 10 high-stakes regulars had been scammed for several million dollars across GG, ACR and Coin.

GipsyTeam said Gregg used the screen name Europe on CoinPoker. PokerListings separately reported that SmartHand screenshots supplied by Avr0ra showed more than $837,000 in combined profit for the accounts OxOO and JackKlompus. The outlet also listed strong StatName results for several accounts, including Gregg’s $55,000 profit at NL2K in May and $21,000 in August.

Mesh Agent’s status as legitimate remote-access software may have made the alleged operation harder to spot. GipsyTeam quoted commentator Gleb Kovtunov saying antivirus programs might not have treated it as a threat, while another commentator said the suspected fraudster had removed Mesh Agent from nearly all of the computers involved, leaving traces on some systems.

For players concerned about infection, PokerListings advised checking Windows Task Manager for a Mesh Agent process and running an antivirus scan. GipsyTeam said information concerning the suspected fraudster had been passed to the FBI and other agencies.

The claims echo earlier online-poker superuser cases, although the alleged mechanism here was access to players’ own computers rather than an operator-side cheat. In the Ultimate Bet and Absolute Poker scandal, insiders used software and internal-system access to view opponents’ hole cards; PokerNews reported that thousands of players lost more than $50 million over several years. A Kahnawake Gaming Commission investigation later identified 117 usernames tied to 23 Ultimate Bet accounts and ordered a $1.5 million fine plus $22 million in player reimbursements.

21+ in OH. Please play responsibly. For help, call the Ohio Problem Gambling Helpline at 1-800-589-9966 or 1-800-GAMBLER.
published 56 minutes ago • by Team F5 • permalink

Keep Reading:

« Back to Homepage