ShinyHunters Resurges with Advanced Oracle PeopleSoft Attacks

ShinyHunters hacking group conceptual image illustrating WAF evasion targeting Oracle PeopleSoft

The notorious ShinyHunters cybercriminal syndicate has aggressively resumed mass exploitation campaigns explicitly targeting Oracle PeopleSoft infrastructure. Alarmingly, they have engineered sophisticated methodologies to seamlessly bypass the defensive countermeasures organizations frantically erected following the initial wave of intrusions. This revitalized campaign has successfully compromised dozens of discrete systems globally, significantly expanding the victimology far beyond the previously targeted academic institutions.

The adversaries are relentlessly exploiting CVE-2026-35273, a devastating vulnerability carrying a near-maximum CVSS severity rating of 9.8. This profound flaw, residing within Oracle PeopleSoft Enterprise PeopleTools, empowers an attacker to execute arbitrary code remotely, completely circumventing any authentication requirements. During the summer, security advisories explicitly instructed administrators unable to rapidly deploy the official patch to immediately block all external access to the PSEMHUB component utilizing Web Application Firewalls (WAF). However, ShinyHunters has methodically adapted its tactics to surgically neutralize this exact defensive strategy.

Deconstructing the URL Encoding WAF Bypass

Rather than utilizing the conventional, anticipated /PSEMHUB/ requested path, the attackers are deploying a classic obfuscation technique, requesting /%50SEMHUB/ instead. In this formulation, %50 represents the URL-encoded equivalent of the uppercase letter ‘P’. A multitude of WAFs and reverse proxy configurations natively evaluate the raw, incoming request string against their established rule sets before normalizing the URI. Consequently, they inadvertently permit the modified, obfuscated address to pass unchallenged. Subsequently, the underlying WebLogic server dutifully decodes the URL and flawlessly routes the malicious request directly to the vulnerable component. Forensically, prior to full exploitation, the targeted server typically receives a barrage of between five and fifteen highly specific POST requests; these subtle probes allow the attackers to stealthily ascertain the system’s precise vulnerability status.

Following a successful breach, ShinyHunters either implants stealthy JSP web shells or, increasingly, executes sophisticated commands entirely in-memory, rigorously avoiding any forensic footprint on the physical disk. This “fileless” operational paradigm profoundly complicates traditional incident response methodologies that rely heavily upon detecting the creation of suspicious, anomalous files. This specific threat actor, officially tracked by Google Threat Intelligence as UNC6240, has repeatedly demonstrated extraordinary tactical agility, seamlessly pivoting between exploiting software vulnerabilities, aggressively harvesting lucrative cloud tokens, and orchestrating direct assaults against core corporate services.

Malware Deployment and Data Exfiltration Strategy

On compromised Windows environments, the adversaries systematically deploy the formidable SIDEEYE backdoor, cunningly disguised as a benign media player installer executable. To establish covert command and control communication, they heavily utilize Neo-reGeorg for robust network tunneling. Conversely, on Linux environments, they frequently deploy the legitimate MeshAgent remote management utility to maintain persistent, illicit access. Frighteningly, forensic analysis indicates that approximately a quarter of all intercepted malicious commands were executed utilizing the absolute highest system privileges—either root or NT Authority\SYSTEM. Given the sheer volume of critical vulnerabilities perpetually affecting Oracle’s vast enterprise portfolio, the software giant urgently implored its global clientele over the summer to prioritize immediate patch deployment.

This renewed, ferocious wave of attacks has engulfed a diverse spectrum of critical sectors, encompassing higher education, prominent technology firms, vital IT service providers, healthcare networks, agricultural conglomerates, transportation logistics, and sensitive governmental agencies. Unfettered access to PeopleSoft environments is exceptionally lucrative for ransomware syndicates and extortionists, given the system’s foundational role in processing exquisitely sensitive human resources data, confidential payroll information, and comprehensive student records. Security specialists have also detected unambiguous forensic artifacts indicating the systematic preparation of massive data archives, followed by aggressive exfiltration utilizing rsync, SSH tunneling, and standard HTTP protocols.

Remediation Mandates and the Alleged FBI Breach

In a comprehensive, urgent advisory, the Mandiant and Google Threat Intelligence Group emphatically dictate that administrators must immediately apply the official Oracle patch. They further command the complete disablement of the Environment Management Hub wherever its functionality is not absolutely mission-critical. Crucially, forensic investigators must meticulously scan web server logs not merely for the standard /PSEMHUB/ path, but also specifically for any URL-encoded variations. If a JSP web shell is discovered, the entire server must be considered catastrophically compromised; administrators must immediately initiate a comprehensive incident response protocol, including the immediate rotation of all cryptographic keys and credentials accessible to the compromised PeopleSoft instance. For complete technical details, consult the analysis concerning the ShinyHunters renewed mass exploitation campaign targeting Oracle PeopleSoft.

The aggressive expansion of this campaign coincidentally aligns with a sensational, albeit highly controversial, public declaration by ShinyHunters claiming they successfully breached the Federal Bureau of Investigation (FBI) specifically via a vulnerable PeopleSoft instance. The syndicate boldly asserts they have exfiltrated the highly sensitive personal data of countless federal agents. However, independent journalists have been utterly unable to definitively corroborate a direct, causal link between this alleged, spectacular incident and the exploitation of CVE-2026-35273. The FBI has officially acknowledged the situation, stating only that they are actively investigating the purported breach. Further context on this alleged incident can be found in reports indicating that ShinyHunters hackers expanded attacks on Oracle’s PeopleSoft.

ShinyHunters possesses a well-documented, brutal history of ruthlessly exploiting the educational sector to harvest colossal repositories of personally identifiable information (PII). This spring, following a devastating attack against the Canvas learning management system, the parent company Instructure grimly reported entering into a controversial agreement with the extortionists; the potentially compromised dataset was terrifyingly linked to the sensitive information of approximately 275 million individuals.

This sector continues to attract intense, sustained focus from the group. In May, the FBI formally issued an urgent, flash warning directed at academic institutions regarding heightened ShinyHunters activity, explicitly following a severe cyberattack that forced a major educational platform to temporarily suspend all critical operations. This current, revitalized campaign starkly demonstrates that even after the publication of an official vendor patch, sophisticated adversaries will relentlessly hunt for organizations that mistakenly relied exclusively upon temporary, easily bypassed traffic filtering rather than implementing the definitive software remediation.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply