Poker Superusers: Inside the $837K Poker Trojan Allegations

Online poker has spent years worrying about bots, real-time assistance, ghosting and superuser accounts. The latest cheating allegations to hit the high-stakes community are considerably more sinister, because the alleged attack may not have been aimed at the poker software at all.

A report published by PokerListings on September 29 claims that malicious remote-access software was installed on the computers of selected high-stakes players, potentially allowing an attacker to watch their screens and see their hole cards in real time. The investigation has been linked to several online poker accounts, including two WPN screen names that reportedly recorded more than $837,000 in combined profit.

There is an important distinction between an allegation and an established fact. Poker Type has not independently verified the malware logs, established who controlled each poker account or confirmed that the person named in the original report installed software on another player’s computer. We have also not found a court judgment, law-enforcement finding or detailed public operator report establishing criminal wrongdoing in this case.

What is already public, however, is enough to make this one of the more unusual online poker security stories of recent years.

How Did Players Become Suspicious?

It appears the investigation began with something poker players understand very well: results that did not look normal.

PokerListings attributes the original account of the case to high-stakes regular Aleksey “Avr0ra” Borovkov. According to that report, players examining tracking data noticed that the accounts involved were producing remarkable results against particular opponents rather than simply crushing the entire player pool.

One statistic was especially striking. PokerListings reports that around 90% of the hands played by the suspected player were against certain regulars. That matters.

An elite high-stakes player might deliberately seek weaker opponents, but consistently targeting a narrow group of established regulars becomes more interesting when the results against those players are exceptionally strong. Players reportedly began going through hand histories and examining decisions that, with hindsight, appeared unusually accurate.

Calls were apparently arriving in the right places. Folds were being made when opponents held the goods. The accounts kept appearing near the top of high-stakes results tables.

None of that alone proves cheating. Extraordinary players can produce extraordinary results, and poker databases inevitably produce statistical outliers.

The allegations became much more serious when suspicious remote-access software reportedly entered the picture.

Which Poker Accounts Have Been Linked to the Allegations?

PokerListings identifies five accounts across three online poker networks. These are reported links rather than independently established proof that one individual controlled every account.

NetworkAccount named in the reportWhat has been alleged
GGPokerPaul GreggPokerListings links the account to the investigation
CoinPokerEuropeReported as another account associated with the case
WPNJackKlompusLinked by PokerListings and included in the reported profit data
WPNOxOOLinked to the investigation and included in the reported profit data
WPNEz[Pz]Reported as another associated screen name

PokerListings identifies the GGPoker account “Paul Gregg” with a Canadian player of that name and attributes several of the other accounts to the same alleged scheme. Poker Type has not independently established that identity or confirmed that one person controlled all five accounts.

That qualification is particularly important when several usernames are being connected to a real person’s name.

Online poker has dealt with account-identity problems before. Our feature on online poker account sharing examined cases involving ghosting, multi-accounting and players competing through identities that opponents did not realize they were facing.

This allegation goes much further.

If opponents’ computers really were compromised, the person sitting behind the suspicious account would not simply have been hiding their own identity. They could potentially have known exactly what cards the other player was holding.

What Does the $837,000 Figure Actually Represent?

Screenshots of SmartHand data supplied by Borovkov showed that the WPN accounts OxOO and JackKlompus had earned more than $837,000 in combined profit. That does not mean investigators have proved $837,000 was stolen, nor does it represent a confirmed total across every account linked to the allegations.

There is separate evidence that some of the accounts had been extremely successful.

JackKlompus was already visible in high-stakes tracking data before this story emerged. PokerListings’ January review of StatName results placed the account third among its best online cash players of 2025 with approximately $232,000 profit.

The September report says the account using Paul Gregg’s name topped StatName’s NL2K results in May 2026 with around $55,000 profit and was fifth at that stake in August with another $21,000. It also lists profitable 2026 months for OxOO and a $25,000 August result for Ez[Pz].

Tracking databases are useful evidence of playing results, but they do not establish why somebody won.

That is where MeshAgent changes the story.

What Is MeshAgent and Could It Really Reveal Hole Cards?

MeshAgent is not, by itself, a piece of poker-cheating malware.

It is part of MeshCentral, legitimate open-source remote-management software designed to allow computers to be administered remotely. There is no evidence in the material we reviewed that the developers of MeshAgent were involved in the alleged poker attack.

The problem is what happens when such software is installed without the computer owner’s knowledge and controlled by somebody else.

Microsoft specifically tracks maliciously weaponized MeshAgent deployments under detections including Trojan/MeshAgent. Microsoft says an attacker using it maliciously can remotely control a compromised computer, execute commands, transfer files, steal information and maintain persistent access.

Security researchers have documented the same basic technique outside poker. Intel 471 describes attackers abusing MeshAgent because legitimate remote-management tools can provide extensive control over a computer while being harder to distinguish from genuine administrative software.

That does not prove MeshAgent was used to cheat these poker players.

It does establish that the alleged mechanism is technically plausible.

If an attacker has unauthorized remote visibility of a poker player’s desktop, there is no need to hack the poker room itself to learn that player’s cards. The cards are already displayed on the victim’s screen.

The poker client could theoretically be operating exactly as designed.

The compromised component would be the player’s computer.

The Reported Pattern Goes Beyond a Huge Win Rate

Russian-language poker community reporting around the investigation has added another allegation. Pokerflow reported that one affected player discovered MeshAgent on their computer and that investigators compared remote-access activity, poker hand histories and connection timing.

That reporting also claims evidence was passed to poker operators and that accounts were subsequently blocked and funds frozen for possible reimbursement.

Poker Type has not independently confirmed those operator actions, so we are not treating them as established fact. As of publication, we have not located detailed public findings from GGPoker, WPN or CoinPoker confirming the complete account linkage, malware evidence or financial total.

PokerListings additionally reports that Patrick Leonard, one of online poker’s best-known high-stakes professionals, had previously referred to security issues involving Gregg and CoinPoker. The precise circumstances and any operator investigation behind that claim remain unclear.

There are therefore still substantial gaps in the public record.

Leonard reacted to the news on X.

Nobody Has Established How the Computers Were Infected

PokerListings says the method used to place the software on players’ computers remains unknown. One theory involving third-party software has circulated within the community, but there is currently insufficient public evidence to present any particular product or company as the source of the alleged infections.

That distinction matters because finding malicious remote-access software does not tell investigators how it arrived.

Cybercriminals can distribute remote-access tools through compromised downloads, fake updates, phishing, stolen credentials and numerous other methods. Microsoft has documented malicious MeshAgent deployments in several unrelated attack scenarios, including sophisticated campaigns that have nothing whatsoever to do with poker.

Until forensic evidence establishes an infection route in the poker case, anything more specific is speculation.

What Should Online Poker Players Check?

Players should not panic simply because MeshAgent exists. It has legitimate uses, particularly on computers managed remotely by businesses or IT departments.

Anyone who discovers remote-management software they did not knowingly install should take it seriously, however. Microsoft recommends isolating a genuinely compromised computer from the internet and local network, updating security software and performing a complete malware scan.

WSOP legend Shaun Deeb was quick to recall some of the trojan poker events from 15+ years ago, he took to X to advise high-stakes players to be smarter.

For poker players, sensible precautions include:

  1. Check installed programs and running processes for unfamiliar remote-access software, including MeshAgent, AnyDesk and similar tools. Do not assume their presence automatically proves an attack.
  2. Keep Windows, antivirus software and poker clients fully updated, and run a full security scan if anything suspicious appears.
  3. If unauthorized remote-access software is found, disconnect the affected machine and change important passwords from a separate, trusted device.
  4. Contact the relevant poker room’s security team if you believe your playing computer was compromised while real-money games were running.
  5. Preserve logs and other evidence before wiping a machine if substantial sums are involved. Those records may be far more useful to investigators than a freshly formatted computer.

This Is Bigger Than One Suspicious Poker Account

Poker security has changed. For years, much of the integrity conversation centered on what happened inside the poker client. Bots could automate decisions. Real-time assistance could calculate them. Ghosting could replace the person supposedly making them.

A compromised computer creates a different problem.

The poker room can protect its servers perfectly and still face an integrity issue if somebody sitting at the table can secretly watch another player’s machine.

The $837,000 figure makes this story eye-catching, but it is not the most important number. The bigger question is how many players, if any, had their computers compromised and how long any unauthorized access continued.

We also do not yet know conclusively who controlled all five reported accounts, how the alleged malware reached victims, how many poker rooms conducted investigations, how much money remains frozen or whether affected players will receive compensation.

Those answers need to come from forensic evidence and the operators themselves.

For now, this remains a serious set of allegations rather than a proven criminal case. But the way players reportedly spotted it is fascinating: not through one impossible hero call or a single spectacular hand, but by following the money, comparing opponents, examining hand histories and eventually looking beyond the poker table altogether.

If the central allegations are ultimately confirmed, the worrying lesson will be simple. Sometimes protecting your hole cards means protecting the computer displaying them.

Source article: PokerListings report on the allegations

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *