ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273

Summary
Mandiant and Google report UNC6240 exploiting Oracle PeopleSoft CVE-2026-35273 with an URL-encoded WAF bypass, deploying web shells and remote-access tools across organizations worldwide.
Key points
- UNC6240 (ShinyHunters) used /%50SEMHUB/ to bypass literal-path WAF rules and reach the vulnerable PeopleSoft endpoint.
- The campaign affected dozens of systems worldwide across education, technology, IT services, healthcare, agriculture, transportation, and government.
- Attackers deployed JSP web shells for command execution and chunked file uploads, and also used fileless command execution.
- On Windows systems, Ple64.exe delivered the SIDEEYE backdoor; Neo-reGeorg tunneling and MeshCentral agents supported access and movement.
- Some observed commands ran as root or SYSTEM; compromised service accounts could also expose PeopleSoft configuration, credentials, and application data.
- Organizations should apply Oracle's security alert patch, disable or remove PSEMHUB where appropriate, inspect logs and systems for encoded paths and attacker files, and rotate accessible credentials.
Article Details
- Attack Vectors
- UNC6240 sent POST requests containing serialized Java objects to the Oracle PeopleSoft PSEMHUB hub servlet to exploit CVE-2026-35273.
- Requests used /%50SEMHUB/ instead of /PSEMHUB/ to bypass WAF rules that matched the literal path before URL decoding.
- Exploitation either deployed JSP web shells or returned command output directly in HTTP responses without writing a file.
- The actor used web shells to upload and execute the SIDEEYE backdoor, deploy Neo-reGeorg tunnels, and establish MeshAgent access.
- Defensive Notes
- Apply Oracle’s security patch for CVE-2026-35273; WAF path rules are not a substitute for patching.
- Disable Environment Management Hub where appropriate or remove the PSEMHUB application, following Oracle’s guidance. Restrict administrative components from public internet access.
- Search WebLogic access logs for /PSEMHUB/ and encoded variants, POST requests to /hub, and unexpected JSP or JSPX requests. Enforce path blocking after normalization.
- Inspect all WebLogic nodes for unexpected files in PSEMHUB.war and PORTAL.war, and alert on shell processes spawned by WebLogic Java processes.
- Check for unexpected MeshCentral agents and outbound connections to the listed network indicators. Preserve evidence and rotate credentials accessible from the PeopleSoft tier if a web shell is found.
- Review for large archives, bulk database exports, and sustained outbound transfers; prepare for possible data-theft extortion.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | azurenetfiles[.]net | Microsoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions. |
| DOMAIN | enroll[.]azuredevice[.]cloud | Microsoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions. |
| DOMAIN | microsoft-entra[.]net | Microsoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions. |
| DOMAIN | winmanage-me[.]network | Domain resolving to the listed staging host and associated with MeshCentral infrastructure. |
| IPV4 | 104[.]219[.]234[.]138 | Listed exfiltration staging and remote management host. |
| IPV4 | 162[.]219[.]30[.]165 | Listed SIDEEYE backdoor C2 server. |
| IPV4 | 5[.]199[.]162[.]157 | Listed attack controller, scanner, and HTTP callback receiver. |
| SHA256 | 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 | Listed hash of the u.jsp upload and execution servlet. |
| SHA256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | Listed hash of the trojanized Ple64.exe installer delivering SIDEEYE. |
| SHA256 | 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86 | Listed hash of a deployed Neo-reGeorg tunnel.jsp servlet. |
| SHA256 | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 | Listed hash of the x.jsp command-execution web shell. |
| SHA256 | ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07 | Listed hash of a deployed Neo-reGeorg tunnel.jspx servlet. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe x.jsp shell accepted hex-encoded commands and reconstructed the /bin/sh string from character codes; the exploit path also used percent encoding to evade literal-path WAF rules.T1036 · MasqueradingPle64.exe masqueraded as a signed Light Alloy media-player installer while loading the SIDEEYE backdoor.T1059.003 · Windows Command ShellThe deployed web shells spawned cmd.exe on Windows to execute actor-supplied commands.T1059.004 · Unix ShellThe x.jsp web shell spawned /bin/sh on Linux to execute actor-supplied commands.T1082 · System Information DiscoveryExploit-verification requests elicited the host operating system, and post-exploitation commands included hostname and uname.T1090 · ProxyNeo-reGeorg routed SOCKS5 proxy traffic through HTTP or HTTPS connections to the compromised web tier.T1105 · Ingress Tool TransferThe u.jsp servlet received Base64-encoded file chunks and reassembled the Ple64.exe backdoor on compromised Windows hosts.T1190 · Exploit Public-Facing ApplicationUNC6240 exploited CVE-2026-35273 in the internet-accessible PeopleSoft PSEMHUB servlet.T1219 · Remote Access ToolsUNC6240 deployed MeshAgent on Linux systems to maintain remote interactive access.T1505.003 · Web ShellUNC6240 placed JSP web shells in the PeopleSoft PSEMHUB.war directory for continued access and payload staging.T1595.002 · Vulnerability ScanningRepeated POST requests to the PSEMHUB hub servlet checked whether targeted servers were exploitable.
CVE
Threat Actors
Malware
Vendors
Googleto the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240OracleMandiant and GTIG report renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by UNC6240 (ShinyHunters), using a URL-encoded WAF bypass to reach the vulnerable PSEMHUB endpoint and deploy web shellsSectigoThe analyzed sample was signed with a valid Extended Validation (EV) certificate issued to Tobias Weihmann Software Development OU via Sectigo.
Products
Oracle PeopleSoftMandiant and GTIG report renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by UNC6240 (ShinyHunters), using a URL-encoded WAF bypass to reach the vulnerable PSEMHUB endpoint and deploy web shellsPeopleToolsApply the Oracle Security Alert for CVE-2026-35273 and remain on supported PeopleTools versions.WebLogicSearch PIA WebLogic access logs for requests to /PSEMHUB/ and any percent-encoded variant (for example, /%50SEMHUB/), particularly POST requests to /hub and requests to .jsp files from external source IP addresses.
Tools
MeshAgentNeo-reGeorg tunneling and MeshAgent were used for lateral movement and remote control.MeshCentralThe campaign expanded beyond education into technology, IT services, healthcare, agriculture, transportation, and government, and also involved SIDEEYE, Neo-reGeorg, and MeshCentral infrastructure.Neo-reGeorgThe campaign expanded beyond education into technology, IT services, healthcare, agriculture, transportation, and government, and also involved SIDEEYE, Neo-reGeorg, and MeshCentral infrastructure.VMProtect 3When executed, Ple64.exe (Stage 1) decompresses and loads a VMProtect 3 (VMP3)-protected second-stage launcher into memory.