Poker Superuser Hack Used 92 Malicious Update Windows, Jurojin Reveals

The poker superuser investigation has taken another major step forward after Jurojin published a detailed technical breakdown of how compromised versions of its software were delivered to selected users.

Poker Superuser Hack Used 92 Malicious Update Windows, Jurojin Reveals.

Jorojin says it has identified 92 separate malicious update windows between June 11, 2025 and January 28, 2026, with tampered files available for a combined 72.7 days.

That is considerably more specific than Jurojin’s first public confirmation of the breach, which Poker Type covered as the investigation moved from suspicious poker results to compromised third-party software. our previous Jurojin superuser report The latest disclosure explains exactly how users could be redirected to a malicious update while the normal Jurojin application continued appearing to work.

One Letter Was Enough to Change the Download

According to Jurojin’s technical breakdown, the attacker did not need to replace Jurojin’s signed launcher. Instead, the download address assigned to a particular group of accounts could be changed by a single character, with a capital letter in an Amazon S3 path replaced by its lowercase equivalent.

Amazon treated those addresses as different locations. The legitimate update could therefore remain untouched while users assigned to the altered path received a different ZIP package.

The same signed launcher.exe would then start a file called JurojinUI.exe, just as it normally did. The crucial difference was that the malicious package contained an unsigned stand-in using that filename, which could install Mesh remote-access software before opening the genuine Jurojin program under another name.

To the player sitting at the computer, Jurojin could still appear to launch normally. That makes the attack considerably harder to spot than a conventional fake application that simply crashes, disappears or produces an obvious antivirus warning.

The Malicious Files Kept Appearing and Disappearing

Perhaps the most revealing part of Jurojin’s new disclosure is that the malicious package was not left permanently available. Jurojin says accounts could be moved into the affected group, the download path changed, and the legitimate configuration restored again afterwards.

Amazon S3’s version history preserved the evidence. Jurojin says it found 92 separate windows between June 11, 2025 and January 28, 2026, with malicious files current for a combined 72.7 days and clean versions current for 158 days during the same period.

Some malicious windows lasted only hours, while the longest lasted approximately five days. The final tampered file was replaced at 14:25 UTC on January 28, and Jurojin says the version currently available from the altered address is legitimate.

That stop-start pattern helps explain why an ordinary inspection could have missed what was happening. Looking at the group or download file after one of those windows had closed could show an entirely legitimate configuration, even though a different file had previously occupied the same route.

Jurojin Says Poker Screen Names Were Not Used

There is another important distinction in the new technical report. Jurojin says its compromised update did not itself check a victim’s poker screen name before installing the remote-access tool.

Instead, exposure depended on the user being placed in the relevant Jurojin group and updating while one of the affected packages was live. Jurojin also stresses that receiving a tampered package does not automatically mean a computer became infected, because not every altered ZIP contained Mesh and not every user necessarily updated during an active window.

That adds useful detail to Poker Type’s original superuser investigation, which examined allegations involving remote access, suspicious high-stakes accounts and more than $837,000 in recorded WPN profit. The technical evidence now provides a clearer potential delivery mechanism, although it does not by itself establish who controlled the remote machines or which poker results were affected.

CoinPoker Caught Paul Gregg More Than Two Years Ago, Says Mosböck

The Jurojin dates also make a separate disclosure from Mario Mosböck particularly interesting. Writing on X on October 2, Mosböck said CoinPoker’s security team had caught Paul Gregg more than two years earlier and refunded Ignacio Morón and other affected players more than $100,000.

Mosböck recalled CoinPoker approaching both him and Patrick Leonard for additional advice because the situation was initially difficult to understand. Gregg was a capable player, Mosböck said, which made separating exceptional poker from something more suspicious considerably harder.

“The data was quite clear,” Mosböck wrote, adding that repeatedly crushing one of the strongest heads-up players involved eventually appeared impossible to reconcile with normal results. He said CoinPoker decided that banning Gregg and refunding affected players was the only reasonable option.

Mosböck further claimed Gregg continued denying wrongdoing and made threats after his funds were confiscated. Those comments are Mosböck’s account of the earlier CoinPoker investigation, rather than findings contained in Jurojin’s newly published forensic report.

CoinPoker Security Draws Praise From Players

Mosböck’s post prompted a string of positive responses about CoinPoker’s handling of the earlier case. BobbyJamesPoker described its security team as “the best of the best,” while Scott “ScottyChips” Strickland called CoinPoker the “safest place to play poker.”

Trotman said knowing about the earlier investigation made him feel safer playing on CoinPoker, pointing to the work of its ambassadors and security team. Jonathan66610 said the operator had already demonstrated that it was highly capable when dealing with security issues and argued that a fair rake would strengthen the room further.

Those comments do not provide additional evidence about how the alleged cheating worked. They do show how strongly some players have reacted to an operator identifying suspicious activity, confiscating funds and returning money rather than allowing an unusual set of results to disappear into poker history.

The Timeline Now Starts Before the Known Jurojin Attack

The biggest unanswered question may now be one of timing. Mosböck says CoinPoker identified Gregg more than two years ago, while Jurojin’s preserved S3 history places its first known malicious update window on June 11, 2025.

That does not prove the earlier CoinPoker incident involved malware, Mesh, Jurojin or any other particular cheating method. It would be a mistake to work backwards from the newly discovered attack and assume every earlier allegation had the same explanation.

It does show that suspicions surrounding Gregg’s play appear to predate the currently documented Jurojin compromise. Establishing what happened in those earlier games, and whether any technical connection exists between the separate periods, is now one of the more interesting unanswered parts of the wider investigation.

Jurojin’s 92 malicious update windows provide investigators with something far more useful than another unusual graph or suspicious hand history. They provide dates, file versions and a documented mechanism that can potentially be compared against affected computers and poker sessions.

The superuser story is therefore becoming less about one extraordinary winning account and more about reconstructing a timeline. With operators, players and software developers now holding different pieces of that history, finding where those timelines overlap could eventually reveal just how far the attack reached.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *