Start Grinding for FREE!
This is a slightly more technical account of how the security breach worked. It is here so anyone can follow it: what a normal update does, what was changed, and how we know the update people get now is not a compromised one.
We can confirm that because Amazon S3 kept every previous upload. We compared all of them. The file that address serves today is a normal build. The compromised uploads are only in the history behind it, and that history is what dates them.
Two separate tricks. One changed which zip a group downloaded. The other changed what was inside that zip. The signed launcher did not have to change.
The group name below is an example. It is not the real name.
A normal update, and the altered one
Both columns are the same sequence. The group name below is an example. A group is a label on the account, and people in it share one download address. That name, and the address the installer uses, are stored separately. Official updates write the legitimate address.
The altered column changes one letter in that address, from a capital N to a small n. Amazon S3 keeps those as two different paths, and serves the one that matches the URI saved on the group. launcher.exe still starts the file named JurojinUI.exe, so it never needed a new build. Inside the tampered zip that file is a stand-in: it installs Mesh at that moment from ProcessCommunicator.exe, a name that belongs to a legitimate signed helper in a normal zip.
account in group NorthstarNorthstar → URI in S3versions/Northstar/Jurojin.zipGET versions/Northstar/Jurojin.zipstart JurojinUI.exeJurojinUI.exe · signed · megabytesJurojinUI.exeLarge and signed. This is the app that opens.ProcessCommunicator.exeA legitimate helper. Signed.Jurojin.exeNot in this zip.group name still NorthstarNorthstar → URI in S3versions/northstar/Jurojin.zipGET versions/northstar/Jurojin.zipstart JurojinUI.exeJurojinUI.exe · under 1 MB · unsignedJurojinUI.exeThe stand-in. It runs now, installs Mesh, and starts the real app.ProcessCommunicator.exeIn a clean zip this name is the legitimate signed helper. Here the unsigned Mesh installer was hidden under that same name.Jurojin.exeThe real app, still signed, opened under this other name.On and off, so the group looked normal
They did not leave the tampered zip in place. Accounts were moved into the group and moved back out, and the group's URI was set back to the original path. A look at the group after that showed the normal address, and a different set of people. That is why it did not stand out.
S3 kept every upload on the altered path. From 11 June 2025 through 28 January 2026 a tampered zip would go up, then a clean zip would replace it, then another tampered zip would go up. Those are 92 windows, not one block. Added together, the tampered file was what a client would download for 72.7 days. For 158 days in that same span the current file was a normal build.
group Northstarversions/northstar/Jurojin.zipversions/Northstar/Jurojin.zipThe last file was left clean
The version that is current on the altered address is a legitimate build: a large signed JurojinUI.exe, and no renamed Jurojin.exe. Looking only at the file that is there now, the address looks ordinary. The tampered uploads are still in the version history behind it. That history is what shows the dates, which uploads were tampered, and which kind each one was.
How the remote-access tool was installed
It went to whoever was in the group and updated while a package containing it was the current file. It did not check poker screen names. The IntuitiveTables variant of this operation did that, as far as we know. This one did not.
Being served a tampered package is not the same as a device ending up with the tool. Not every tampered zip contained it, and not everyone in the group updated during one of those windows.