Mesh Agent Trojan Exposed High-Stakes Regulars' Hole Cards: How Scammers Beat the Players

Author
Dmitry NewSted
Published
10/3/2026
Updated
10/3/2026

Dozens of high-stakes players may have fallen victim to attackers who gained remote access to their computers via Mesh Agent. The infection occurred through third-party poker software installed on the players' computers. The potential losses could amount to hundreds of thousands of dollars. 

Mesh Agent Trojan High Stakes Cheating

How the Mesh Agent scheme was exposed

On September 29, 2026, the poker community uncovered a scheme that allowed attackers to see high-stakes players’ hole cards for years. Mesh Agent, a remote-access tool, was found on grinders’ computers, while accounts linked to the investigation showed hundreds of thousands of dollars in profits. Some suspected victims also reported losing large sums to these players.

Andrey "TylerRM" Streltsov was the first to warn the public. He reported that Mesh Agent had appeared on some players’ PCs without their knowledge and urged his followers to check their computers.

Later that day, cybersecurity specialist "WolfSec0x0" published a technical investigation. He found traces of Mesh Agent on approximately 30 computers and determined that additional files had been downloaded only to devices belonging to users whose screen names appeared on a precompiled list.

This suggested a targeted attack: the perpetrator selected specific players, gained access to their computers, and could see what was happening at the poker tables.

Later, the developers of Jurojin and IntuitiveTables confirmed that their products had been compromised. According to the investigation, Mesh Agent was installed on selected players’ computers through third-party poker software.

What exactly did "WolfSec0x0" discover

"WolfSec0x0" published a post warning players:

The researcher specifically emphasized that the issue involves players' computers, not a breach of poker room servers. Mesh Agent is not malicious software itself; it is a component of MeshCentral, a legitimate open-source solution for remote computer management.

The problem was that it was installed on players’ devices without their knowledge. This allowed the attacker to remotely access the computer and see what was happening on the screen, including players’ hole cards.
Key findings from "WolfSec0x0":

  • Stealthy operation. The agent could run as a Windows service, and its files and activity were not always apparent to the user.
  • Bypassing Defender checks. Microsoft Defender exclusions were found on some computers, allowing specific directories to bypass scanning.
  • Long-term presence. The earliest confirmed traces of Mesh Agent date back to March 16, 2024. On some computers, the agent remained for over a year.
  • Removing traces. Shortly before the investigation was published, the attacker, according to "WolfSec0x0", began remotely removing Mesh Agent and its associated scripts. However, traces of its presence could remain on the system.

This also explains why a simple check of the Task Manager might not have shown anything: by the time the check was performed, the agent could have already been removed.

How Mesh Agent was Installed on players’ computers 

"WolfSec0x0 " found that the attackers used two popular table-selection tools. Following the publication of his investigation, the developers of Jurojin and IntuitiveTables confirmed that their applications had been compromised. Jurojin mentioned  reviewing the researcher’s report and collaborating  with him on the investigation: 

Jurojin later clarified that from June 2025 to June 2026, the attacker periodically replaced update packages for a specific group of users. Some of the modified packages contained a remote-access tool. According to the company, the last compromised package was distributed in June 2026.

IntuitiveTables also confirmed that its software had been compromised and said that the current versions of the program don’t contain any malicious code.

Where suspicions about Paul Gregg came from

Oxoo High Stakes Winnings Wpn
OxOO’s results in the WPN Network

Following the publication of "WolfSec0x0’s" investigation, one of the main names discussed was Canadian player Paul Gregg. He has been linked to the Paul Gregg account on GGPoker, Europe on CoinPoker, as well as JackKlompus, OxOO, and Ez[Pz] on the WPN network. According to SmartHand, JackKlompus and OxOO generated more than $837,000 in combined profit.

The investigation also noted that some of these accounts played an unusually large share of their hands against certain regulars. In some cases, more than 90% of their hands were played against specific groups of players, prompting further analysis of their activity.

Manuel Saavedra said the agent had been on his PC for more than a year and that he had lost around $60,000 to Gregg at GGPoker tables over the previous six months. Gleb Kovtunov also reported finding the agent on his computer and suffering significant losses to Gregg.

However, there is currently no direct evidence that Gregg installed Mesh Agent, controlled it, or used access to players’ hole cards.

How to check a computer for the Mesh Agent

Although the attack primarily targeted high-stakes players, anyone using poker software should check their computer. Mesh Agent could run as a system service and would not appear among standard running programs.

"WolfSec0x0" recommended performing a check using PowerShell. To do this:

  1. Open PowerShell as an administrator. Right-click the Start menu and select **Terminal (Admin)** or **PowerShell (Admin)**.
  2. Check for the Mesh Agent service. Run the command: `Get-Service 'Mesh Agent'`. If Windows reports that the service wasn’t found, that is a good sign, but this check alone is not sufficient.
  3. Check for traces of MeshCentral: `Get-ChildItem 'HKLM:\SOFTWARE\Open Source'`. The presence of entries related to MeshCentral or Mesh Agent warrants further investigation.
  4. Check Microsoft Defender exclusions: `(Get-MpPreference).ExclusionPath`. If `C:\Windows` or other system directories appear in the list—and you didn’t add them yourself—this is cause for concern.
  5. Do not delete suspicious files immediately.

If any of the checks detect Mesh Agent or unknown Windows Defender exclusions, it is better to save the results first and consult a cybersecurity specialist. Removing the software yourself could destroy important evidence that may help determine what happened on the computer. 

What happens next

The investigation should now shift from the detection of the Mesh Agent to an analysis of the attack's impact. Jurojin has preserved logs of all compromised versions and the users to whom they were distributed, and is prepared to hand this data over to law enforcement agencies and cybersecurity experts. The company has also already contacted the affected players directly.

The game histories will also need to be examined. "WolfSec0x0" urged poker rooms to investigate logins from unknown devices and the hand histories of affected players, particularly sessions against opponents who played against them unusually often. Such analysis could reveal whether remote access was used directly at the tables and how much damage it may have caused.

Meanwhile, the latest versions of Jurojin and IntuitiveTables no longer contain the malicious component, and Mesh Agent has been removed or disabled on all confirmed affected computers.

Poker rooms won’t stay on the sidelines either. For example, CoinPoker has already launched daily, detailed tracking of all high-stakes games at railbird.vip.

Related posts