The first to report this was TylerRM on the Russian GTO or GTFO channel:
It's been discovered that poker viruses are circulating.
Here's a batch file from Mobius Poker.
Run it. Especially those who play cash games. Especially those who play high stakes.
If you find Mesh Agent on your computer, throw it out. It turns out quite a few high-stakes players are infected.
(Editor's note: Mesh Agent = software that provides remote access to a computer and allows you to see your opponent's cards)
A few hours later, Avr0ra wrote a long post with details:
– Scary news from high-stakes cash players: 10+ (and maybe even more) regs were scammed for several million dollars on GG, AKR, and Coin.
A cheater (most likely a group of cheaters) somehow installed spyware on many different regs and gained access to these players' screens.
The scammer was clever enough to avoid immediate detection and spent months hunting for those regs who managed to install the Trojan. In the end, they finally managed to identify him (no matter how you look at it, he was greedy and got caught sometimes, and overall, he showed such good results that they started looking into it and found a pattern: he won all his money from certain regs, and played 90%+ of his hands with them at the tables, meaning he was deliberately selecting them. And then they found the Trojan itself).
The Trojan was almost certainly distributed using some poker software (most likely even several ways), a tracker, or a table-setting program. They also pushed this Trojan through phishing emails. In short, they were working on all fronts.
It seems they installed it through intuitive tables (similar to Jurojin), but it could have been through others (perhaps in collusion with the developers).The Trojan itself is called: Mesh Agent (you can search for the process, or its traces, in your own system).
The cheater's main nicknames with ACR+ are his Real name with gg (along with a revealing hand) in screenshots



Few people can learn from others' mistakes, but you can try (all non-open source poker-related software should probably be removed from your work computer).
It's surprising that they worked through poker (the money involved was certainly not small, anyway), but if they had such capabilities for introducing Trojans, why didn't they simply steal crypto or engage in more extensive hacks? But these are all rhetorical questions, of course.
"This hand with kings is an example that he wasn't playing completely stupidly, but was also trying to avoid getting caught by the room's security," Avr0ra explained in the comments.
"NL10 can't even be beaten with cheats?" commentators asked.

Gleb "psyhoagromor" Kovtunov, whose hand was posted on the screenshot, commented that he likely lost the most to the scammer:
I've been accusing Paul Greg of cheating in private messages since April.
The hand above isn't particularly representative without context (but when someone can't lose a pot more than 30bb, and always chooses perfect lines and sizings with any of your hands, it feels like you're just being spun around on a carousel of absurdity).
A month ago, I was added to the HS Anti-Rat group, and I immediately posted there about my suspicions about him.
Two days later, he hit the jackpot😂 and never showed up at the tables again. I assume that since he could see my screen, he saw my messages too. Most likely, he was withdrawing all the money and covering his tracks. He personally deleted the mesh from almost everyone he cheated, but the tracks still remain.
And in the comments of the TylerRM channel, another victim was found.

"I wonder if there's any information on how someone managed to bypass antivirus software, or why the antivirus software didn't react to this software at all?" Elendil asked.
"I wouldn't blame the poker software specifically for now," Gleb replied. "What's interesting is that MeshAgent itself is legitimate remote access software, and judging by what we've found on the infected computers, antivirus programs might not have reacted to it at all. For example, it ran for quite a while on mine, and Defender didn't detect it as a threat."
So now the main question isn't even what software we installed, but how the attacker initially gained the ability to install MeshAgent. Once the infection vector becomes clear, we'll be able to draw conclusions about whether it was third-party poker software, phishing, an exploit, or something else.
Another important point: a rather suspicious story has already surfaced involving table selection software and artifacts/logic found within it related to player selection. Therefore, I certainly wouldn't completely rule out third-party poker software as a possible infection vector.
But I, for example, never had this particular software, yet MeshAgent was still detected on my computer. Therefore, it's entirely possible that there were multiple infection vectors, or we simply haven't yet found a common source.
One of TylerRM's colleagues wrote that the fraudster's data has already been transferred to the FBI and other agencies.

There aren't many examples of poker cheaters being formally prosecuted, but they do exist.
The most high-profile example is Peter Jepsen, who was sentenced to three years in prison in Denmark.

From the article:
"Peter Jepsen was accused of a six year long cheating spree that involved installing trojan horse viruses onto other player’s computers. It was thought that he recruited partners who would install the malware onto laptops in hotel rooms while playing at high-profile events such as the EPT."
At CoinPoker, Paul Gregg played under the nickname Europe.
Lorem posted a screenshot of Patrick Leonard's post, in which he writes that he was banned from CoinPoker two years ago.

Boris Grabowski was amazed at the scammers' carelessness:
– Regarding the hacker story (and this is more likely the work of a team than a lone wolf), it's quite remarkable that the hackers worked diligently and accomplished a significant amount of work (phishing emails, fake websites, hacking most of the poker software), but they didn't take much care in protecting themselves. It was fairly easy to establish the identity and residence of the nominal account holder (he played under his own name on all the sites), and he didn't even hide the fact that he lived almost across the street from the GG offices (though GG's role here is unclear). They also managed to learn a lot about the process through Windows logs, which they neglected to clean up, and only when the social media frenzy began did they begin deleting everything they could from the victims' computers.
This all goes to show that, given the current attitude of poker rooms and the law toward such scammers, they feel safe from the consequences.
This news hasn't made its way public in the international community yet. Most of the discussion is taking place in closed groups of high-stakes regs.
A thread was opened on 2+2 (https://forumserver.twoplustwo.com/misc.php?do=tpt-new-forum&destination=%2FNews-Views-and-Gossip%2F13ytv%2FScary-News), but it hasn't yet generated much buzz.
GipsyTeam will follow this story as it develops.