Google Warns of ShinyHuntersâ Fresh Oracle PeopleSoft Campaign
Mandiant and Google Threat Intelligence Group (GTIG) over the weekend warned that the notorious extortion group ShinyHunters has launched a fresh mass-exploitation campaign targeting Oracle PeopleSoft customers.
An integrated enterprise resource planning (ERP) software suite, PeopleSoft is used across numerous large enterprises for the management of core business functions, including finance, HR, payroll, and supply chain.
Googleâs warning comes four months after the hacking group was seen exploiting a zero-day vulnerability in PeopleSoft, tracked as CVE-2026-35273, to gain remote code execution without authentication.
ShinyHunters, tracked by Google as UNC6240, targeted more than 100 PeopleSoft customers in June. Confirmed victims include the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan.
âThis new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint,â Mandiant and GTIG warn now.
In the recent attack aimed at the FBI, ShinyHunters claimed to have leveraged a PeopleSoft zero-day. The hackers may be referring to this modified exploit rather than a new zero-day.
While ShinyHuntersâ initial PeopleSoft campaign focused on the education sector, the new wave of attacks has expanded to agriculture, government, healthcare, IT services, technology, and transportation organizations, Google says.
As part of the new campaign, the hackers have been deploying web shells on dozens of systems after bypassing WAF rules using â%50â, the URL-encoded form of the character âPâ, in the request path containing the string â/PSEMHUBâ.
âMany WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure,â Google says.
The attackers either sent multiple POST requests to access web shells behind some load-balanced environments, likely to ensure that a copy of the web shell is deployed on every WebLogic node, or sent POST requests that returned command output directly in the HTTP response to spawn the shell processes.
Mandiant and GTIG observed the hacking group establishing persistence through two complementary, single-line JSP web shells, and deploying the SideEye backdoor on Windows servers to steal credentials from browsers and applications, manage files and processes, and gain reverse shell and reverse proxy capabilities.
Additionally, the attackers deployed the open source Neo-reGeorg tunneling toolkit for internal discovery and lateral movement, and the open source remote management platform MeshCentral.
The hackers executed commands with root or System privileges to perform host and user discovery and process verification, and abused PeopleSoft and WebLogic service accounts for gaining access to application data, configuration files, and database connection strings.
PeopleSoft customers are advised to apply Oracleâs patches for CVE-2026-35273, to harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of compromise.
âUNC6240 has a well-established pattern of data theft extortion, that is, stealing data and threatening to release it on a data leak site unless the victim pays a ransom. Affected organizations should prepare for extortion communications and monitor for potential public exposure of stolen data,â Google says.
Related: Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Related: China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
Related: New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Related: In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.