ShinyHunters-Linked Campaign Exploits Oracle PeopleSoft Vulnerability at Scale

Google is warning of renewed mass exploitation of a critical vulnerability in Oracle PeopleSoft that is being used against organizations across multiple industries worldwide.

The activity has been linked to UNC6240, a threat actor associated with ShinyHunters, and involves exploitation of CVE-2026-35273, a critical vulnerability with a CVSS score of 9.8 that can enable unauthenticated remote code execution.

Attackers Modify Exploit to Bypass WAF Protections

CVE-2026-35273 was previously exploited as a zero-day against academic institutions.

In those attacks, the threat actor conducted reconnaissance, deployed remote access software such as MeshCentral Agent, moved laterally using SSH, connected to additional internal PeopleSoft systems, and stole data.

Google-owned Mandiant previously notified more than 100 organizations whose IP addresses appeared to expose vulnerable PeopleSoft endpoints.

The latest campaign uses a modified exploit designed to bypass Web Application Firewall (WAF) protections blocking access to the vulnerable Environment Management Hub (PSEMHUB) endpoint.

The attackers bypass string-based WAF rules by URL-encoding the first character of the endpoint:

/PSEMHUB/

is replaced with:

/%50SEMHUB/

Many WAFs and reverse proxies evaluate the URL before decoding it, allowing the request to bypass rules looking specifically for /PSEMHUB/. PeopleSoft then decodes the request and routes it to the vulnerable servlet.

Organizations Across Multiple Sectors Targeted

The latest activity has affected organizations across several sectors, including:

  • Higher education
  • Technology
  • IT services
  • Healthcare
  • Agriculture
  • Transportation
  • Government

Attackers have deployed web shells on dozens of compromised systems.

Attack Chain

The observed attack sequence includes the following steps:

  1. Attackers identify vulnerable PeopleSoft systems by sending POST requests to /%50SEMHUB/hub.
  2. Serialized Java objects are included in the requests to exploit the vulnerable servlet.
  3. The URL-encoded P bypasses WAF rules targeting the standard /PSEMHUB/ path.
  4. Java deserialization is abused to deploy web shells and execute commands without writing the primary payload directly to disk.
  5. Two JSP web shells, x.jsp and u.jsp, are placed inside the PSEMHUB.war directory.
  6. x.jsp provides cross-platform command execution.
  7. u.jsp supports chunked file uploads and command execution through cmd.exe.
  8. The attackers use u.jsp to upload a trojanized installer named Ple64.exe.
  9. The installer loads SIDEEYE, a C++ backdoor, directly into memory.
  10. The attackers also deploy Neo-reGeorg for network tunneling.
  11. On Linux systems, MeshAgent is used to maintain persistent remote access.

SIDEEYE Backdoor

The Ple64.exe installer loads the SIDEEYE backdoor, which communicates with an external server over TCP.

The observed infrastructure includes:

162.219.30[.]165

SIDEEYE provides capabilities including:

  • Browser credential theft
  • Desktop application credential theft
  • Process management
  • File management
  • Interactive reverse shell access
  • Reverse proxy functionality

The combination gives attackers both credential theft capabilities and interactive control over compromised PeopleSoft environments.

Attackers Achieve High-Level Access

Google reported that approximately one-quarter of observed commands were executed with either root or NT AUTHORITY\SYSTEM privileges.

The remaining commands were executed under PeopleSoft or WebLogic service accounts.

This level of access can provide attackers with extensive control over the underlying operating system and access to sensitive application data.

Organizations running Oracle PeopleSoft should take the following actions:

  • Apply security updates for CVE-2026-35273.
  • Disable the Environment Management Hub service in multi-server deployments.
  • Remove the PSEMHUB application entirely in single-server configurations where appropriate.
  • Review WebLogic access logs for /PSEMHUB/ requests and URL-encoded variants such as /%50SEMHUB/.
  • Inspect the PSEMHUB.war directory for unexpected JSP files and other malicious artifacts.
  • Rotate credentials accessible to the PeopleSoft application service account.
  • Search PeopleSoft and database systems for unusually large archive files in temporary or web-accessible directories.
  • Review database audit logs for bulk queries or exports involving HR, payroll, and student records.
  • Monitor outbound connections from PeopleSoft servers for suspicious destinations.

Data Theft and Extortion Risk

Google said UNC6240 has a documented pattern of stealing data and subsequently threatening to publish it unless the victim pays.

Organizations affected by this campaign should therefore monitor for signs of data theft and prepare for possible extortion attempts or public disclosure of stolen information.

The latest activity demonstrates how attackers can modify existing exploits to bypass perimeter security controls such as WAFs. Organizations that previously blocked direct access to /PSEMHUB/ should also verify whether equivalent URL-encoded paths can reach the vulnerable application.

Key Takeaway

The renewed exploitation of CVE-2026-35273 shows that patching PeopleSoft systems alone is not enough if organizations continue to expose vulnerable services or rely solely on WAF signatures.

Security teams should patch affected systems, restrict or disable the Environment Management Hub where possible, investigate encoded variants of vulnerable URLs, and actively hunt for web shells, tunneling tools, credential theft, and unauthorized outbound connections.