Google Warns of ShinyHunters’ New Oracle PeopleSoft Security Threat
Google and Mandiant report a new ShinyHunters campaign targeting Oracle PeopleSoft systems, exploiting vulnerabilities to deploy web shells and backdoors.
Overview of the ShinyHunters Campaign
Google Threat Intelligence Group (GTIG) and Mandiant have identified a new large-scale exploitation campaign by the extortion group ShinyHunters, targeting Oracle PeopleSoft systems. The enterprise resource planning (ERP) software, critical for financial management, human resources, and supply chain operations, has become a focal point for this attack. This follows a prior incident where the group exploited a zero-day vulnerability, CVE-2026-35273, to achieve remote code execution without authentication.
Targeted Systems and Previous Attacks
In June, ShinyHunters compromised over 100 PeopleSoft instances, with confirmed victims including the University of Nottingham, the National Association of Insurance Commissioners (NAIC), and Nissan. The campaign includes deploying web shells on compromised systems, using POST requests to ensure deployment across load-balanced environments. In some cases, command outputs are returned directly in HTTP responses to establish shell access.
Exploit Techniques and WAF Evasion
The latest activity involves modifications to the exploit framework to evade web application firewall (WAF) protections. Attackers are using URL-encoded characters, such as ‘%50’ (representing the letter ‘P’), in requests targeting the Environment Management Hub (PSEMHUB) endpoint. This technique exploits the discrepancy between how WAFs and PeopleSoft application servers process URLs, allowing the threat actor to bypass existing defenses.
Google highlighted that many WAF rules are designed to block literal paths before URL decoding, whereas the PeopleSoft server decodes the request and routes it to the vulnerable servlet.
Tools and Tactics Used by ShinyHunters
Mandiant and GTIG observed the use of two single-line JSP web shells for persistence, alongside the SideEye backdoor for credential theft and system control. Additional tools deployed include the Neo-reGeorg tunneling toolkit for internal network exploration and the MeshCentral remote management platform. Attackers leveraged elevated privileges to execute host and user discovery, utilizing PeopleSoft and WebLogic service accounts to access application data, configuration files, and database credentials.
Indicators of Compromise and Mitigation
Google emphasized that UNC6240, the tracking designation for ShinyHunters, follows a known pattern of data exfiltration and extortion. Affected organizations are urged to apply Oracle’s patches for CVE-2026-35273, conduct thorough threat hunting for indicators of compromise, and prepare for potential ransom demands. The group’s recent efforts have expanded beyond the education sector to include agriculture, government, healthcare, IT services, technology, and transportation entities.
Broader Implications and Recommendations
While ShinyHunters claimed to have exploited a PeopleSoft zero-day in an attack on the FBI, the evidence suggests the use of the updated exploit rather than a newly discovered vulnerability. Customers are advised to monitor for signs of data leaks and implement robust mitigation strategies to address the evolving threat landscape.
