Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

Oracle PeopleSoft zero-day

Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.

An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain.

Google’s warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication.

ShinyHunters, tracked by Google as UNC6240, targeted more than 100 PeopleSoft customers in June. Confirmed victims include the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan.

“This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,” Mandiant and GTIG warn now.

In the recent attack aimed at the FBI, ShinyHunters claimed to have leveraged a PeopleSoft zero-day. The hackers may be referring to this modified exploit rather than a new zero-day. 

Advertisement. Scroll to continue reading.

While ShinyHunters’ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says.

As part of the new campaign, the hackers have been deploying web shells on dozens of systems after bypassing WAF rules using ‘%50’, the URL-encoded form of the character ‘P’, in the request path containing the string ‘/PSEMHUB’.

“Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,” Google says.

The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.

Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.

Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral.

The hackers executed commands with root or System privileges to perform host and user discovery and process verification, and abused PeopleSoft and WebLogic service accounts for gaining access to application data, configuration files, and database connection strings.

PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise.

“UNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data,” Google says.

Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

Related: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.