ShinyHunters Resume Mass Exploitation of Oracle PeopleSoft Vulnerability CVE-2026-35273

· Original article ↗

Summary

Mandiant and Google report UNC6240 exploiting Oracle PeopleSoft CVE-2026-35273 with an URL-encoded WAF bypass, deploying web shells and remote-access tools across organizations worldwide.

Key points

  • UNC6240 (ShinyHunters) used /%50SEMHUB/ to bypass literal-path WAF rules and reach the vulnerable PeopleSoft endpoint.
  • The campaign affected dozens of systems worldwide across education, technology, IT services, healthcare, agriculture, transportation, and government.
  • Attackers deployed JSP web shells for command execution and chunked file uploads, and also used fileless command execution.
  • On Windows systems, Ple64.exe delivered the SIDEEYE backdoor; Neo-reGeorg tunneling and MeshCentral agents supported access and movement.
  • Some observed commands ran as root or SYSTEM; compromised service accounts could also expose PeopleSoft configuration, credentials, and application data.
  • Organizations should apply Oracle's security alert patch, disable or remove PSEMHUB where appropriate, inspect logs and systems for encoded paths and attacker files, and rotate accessible credentials.

Article Details

Attack Vectors
  • UNC6240 sent POST requests containing serialized Java objects to the Oracle PeopleSoft PSEMHUB hub servlet to exploit CVE-2026-35273.
  • Requests used /%50SEMHUB/ instead of /PSEMHUB/ to bypass WAF rules that matched the literal path before URL decoding.
  • Exploitation either deployed JSP web shells or returned command output directly in HTTP responses without writing a file.
  • The actor used web shells to upload and execute the SIDEEYE backdoor, deploy Neo-reGeorg tunnels, and establish MeshAgent access.
Defensive Notes
  • Apply Oracle’s security patch for CVE-2026-35273; WAF path rules are not a substitute for patching.
  • Disable Environment Management Hub where appropriate or remove the PSEMHUB application, following Oracle’s guidance. Restrict administrative components from public internet access.
  • Search WebLogic access logs for /PSEMHUB/ and encoded variants, POST requests to /hub, and unexpected JSP or JSPX requests. Enforce path blocking after normalization.
  • Inspect all WebLogic nodes for unexpected files in PSEMHUB.war and PORTAL.war, and alert on shell processes spawned by WebLogic Java processes.
  • Check for unexpected MeshCentral agents and outbound connections to the listed network indicators. Preserve evidence and rotate credentials accessible from the PeopleSoft tier if a web shell is found.
  • Review for large archives, bulk database exports, and sustained outbound transfers; prepare for possible data-theft extortion.

Indicators of compromise

TypeIndicatorContext
DOMAINazurenetfiles[.]netMicrosoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions.
DOMAINenroll[.]azuredevice[.]cloudMicrosoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions.
DOMAINmicrosoft-entra[.]netMicrosoft-masquerading domain used for outbound MeshAgent connections in earlier intrusions.
DOMAINwinmanage-me[.]networkDomain resolving to the listed staging host and associated with MeshCentral infrastructure.
IPV4104[.]219[.]234[.]138Listed exfiltration staging and remote management host.
IPV4162[.]219[.]30[.]165Listed SIDEEYE backdoor C2 server.
IPV45[.]199[.]162[.]157Listed attack controller, scanner, and HTTP callback receiver.
SHA2562bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7Listed hash of the u.jsp upload and execution servlet.
SHA2563ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3Listed hash of the trojanized Ple64.exe installer delivering SIDEEYE.
SHA256419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86Listed hash of a deployed Neo-reGeorg tunnel.jsp servlet.
SHA25648b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494Listed hash of the x.jsp command-execution web shell.
SHA256ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07Listed hash of a deployed Neo-reGeorg tunnel.jspx servlet.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe x.jsp shell accepted hex-encoded commands and reconstructed the /bin/sh string from character codes; the exploit path also used percent encoding to evade literal-path WAF rules.T1036 · MasqueradingPle64.exe masqueraded as a signed Light Alloy media-player installer while loading the SIDEEYE backdoor.T1059.003 · Windows Command ShellThe deployed web shells spawned cmd.exe on Windows to execute actor-supplied commands.T1059.004 · Unix ShellThe x.jsp web shell spawned /bin/sh on Linux to execute actor-supplied commands.T1082 · System Information DiscoveryExploit-verification requests elicited the host operating system, and post-exploitation commands included hostname and uname.T1090 · ProxyNeo-reGeorg routed SOCKS5 proxy traffic through HTTP or HTTPS connections to the compromised web tier.T1105 · Ingress Tool TransferThe u.jsp servlet received Base64-encoded file chunks and reassembled the Ple64.exe backdoor on compromised Windows hosts.T1190 · Exploit Public-Facing ApplicationUNC6240 exploited CVE-2026-35273 in the internet-accessible PeopleSoft PSEMHUB servlet.T1219 · Remote Access ToolsUNC6240 deployed MeshAgent on Linux systems to maintain remote interactive access.T1505.003 · Web ShellUNC6240 placed JSP web shells in the PeopleSoft PSEMHUB.war directory for continued access and payload staging.T1595.002 · Vulnerability ScanningRepeated POST requests to the PSEMHUB hub servlet checked whether targeted servers were exploitable.

CVE

Threat Actors

Malware

Vendors

Products

Tools

Related Articles