GBHackers

Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations


The ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273.

Expanding beyond its earlier focus on higher education into technology, healthcare, government, transportation, agriculture, and IT services.

The campaign demonstrates how quickly financially motivated actors can adapt when organizations rely on perimeter workarounds rather than applying vendor-issued patches.

Rather than requesting the literal /PSEMHUB/ path, operators sent requests to /%50SEMHUB/, where %50 is the URL-encoded representation of the letter “P.”

WebLogic decodes the path and forwards the request to the vulnerable servlet, while many WAF and reverse-proxy rules fail because they compare the pre-decoded literal string.

CVE-2026-35273 is a critical unauthenticated remote-code-execution flaw in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools.

Oracle lists PeopleTools versions 8.61 and 8.62 as affected, assigns the bug a CVSS 3.1 score of 9.8, and warns that a successful attack can result in takeover of the PeopleSoft environment.

UNC6240 initially exploited the flaw as a zero-day between May 27 and June 9, predominantly against academic institutions.

Oracle issued an out-of-band security alert on June 10, but the latest activity shows attackers specifically pursuing organizations that implemented URL-path blocking while leaving the underlying vulnerable software unpatched.

The development reinforces a recurring operational lesson: WAF signatures can reduce opportunistic noise but are not compensating controls for an internet-reachable, unauthenticated RCE flaw.

PSEMHUB WAF bypass (Source : Google Cloud).

Normalization inconsistencies between a security appliance and an application server can make simple path-based protections ineffective.

Google Threat Intelligence Group and Mandiant said that, the threat actor modified its exploit to bypass web application firewall rules intended to block the vulnerable PeopleSoft Environment Management Hub, or PSEMHUB, endpoint.

Oracle PeopleSoft Servers

Mandiant observed an attack chain beginning with repeated POST requests to /%50SEMHUB/hub, using serialized Java objects to validate whether a host is exploitable.

In some cases, no malware is dropped during this stage; the victim may only retain suspicious requests in PIA WebLogic logs.

After successful exploitation, UNC6240 deployed JSP web shells to the PSEMHUB application directory.

The x.jsp shell executes commands on Windows and Linux hosts using hex-encoded POST parameters, while u.jsp and a related variant upload Base64-encoded payload chunks and can execute commands after reassembly.

This design reduces exposure of cleartext commands in URLs and helps operators bypass request-size restrictions.

The group also used a 5.2 MB trojanized Light Alloy installer named Ple64.exe, tracked as SIDEEYE.

The binary reportedly contains a multi-stage in-memory execution chain and communicates with its command-and-control server over raw TCP, using ports 3333 and 3334 for separate control and data channels.

Capabilities include credential theft, process and file management, reverse-shell access, and reverse-proxy functionality.

UNC6240’s tooling suggests the campaign is built for sustained access and data-theft operations rather than simple opportunistic exploitation.

Investigators also identified Neo-reGeorg, an open-source tunneling utility that can proxy SOCKS5 traffic through HTTP or HTTPS, allowing attackers to pivot into internal networks from a compromised PeopleSoft web tier.

On Linux systems, the actor deployed MeshAgent, a legitimate remote-management component associated with MeshCentral.

Earlier intrusions used /tmp for MeshAgent binaries and configuration files, while September activity involved infrastructure including winmanage-me[.]network at 104.219.234[.]138.

Mandiant also identified Microsoft-themed domains used in prior activity, including azurenetfiles[.]net, microsoft-entra[.]net, and enroll.azuredevice[.]cloud.

A quarter of observed commands ran as root or NT AUTHORITYSYSTEM, significantly increasing the likelihood of complete server compromise.

Even execution under PeopleSoft or WebLogic service accounts can expose application configuration files, database connection strings, Integration Broker credentials, and accessible cloud secrets.

Organizations should apply Oracle’s security update for CVE-2026-35273 immediately and treat any reliance on WAF-only mitigation as inadequate.

Oracle’s advisory confirms the issue is remotely exploitable without authentication and can enable remote code execution.

Security teams should disable the Environment Management Hub service in multi-server deployments where possible, or remove the PSEMHUB application in single-server configurations, following Oracle’s guidance.

They should also review PIA WebLogic access logs for /PSEMHUB/ plus encoded, mixed-case, and non-normalized variants; externally sourced POST requests to /hub; and unexpected .jsp or .jspx file requests.

Incident responders should inspect PSEMHUB.war and PORTAL.war for unauthorized JSP, JSPX, or executable files, investigate shell processes launched by WebLogic Java processes, and rotate every credential available to the PeopleSoft application tier.

Discovery of a web shell should be treated as evidence of a full host compromise, with priority given to systems where the service account runs with root or SYSTEM privileges.

Indicators of Compromise

IndicatorTypeDescription
5.199.162.157IPv4Attack controller, scanner, and HTTP callback receiver
104.219.234.138IPv4Exfiltration staging and remote management host
162.219.30.165IPv4C2 for SIDEEYE backdoor

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link