Oracle PeopleSoft New Security Threat as ShinyHunters Resurfaces

www.news4hackers.com-oracle-peoplesoft-new-security-threat-as-shinyhunters-resurfaces-oracle-peoplesoft-new-security-threat-as-shinyhunters-resurfaces

Oracle PeopleSoft systems face a new cyberattack wave linked to ShinyHunters, targeting critical vulnerabilities and exploiting temporary mitigation strategies.

Attack Overview and Vulnerability Exploitation

ShinyHunters has initiated a large-scale exploitation campaign targeting Oracle PeopleSoft environments, with Google alerting over 100 global entities about active exploitation of a previously compromised critical vulnerability. The attack sequence involves advanced techniques to bypass security measures, deployment of web shells, and use of a novel backdoor mechanism.

CVE-2026-35273 Exploitation

The campaign specifically exploits CVE-2026-35273, a high-severity flaw in Oracle PeopleSoft that was previously abused in June 2026. Google’s threat intelligence team confirmed that the group, attributed to the threat actor UNC6240, is focusing on organizations that implemented temporary mitigation strategies rather than applying full patches.

Attack Lifecycle and Techniques

Researchers observed a structured attack lifecycle beginning with reconnaissance, followed by exploitation, web shell deployment, and direct adversary interaction. Attackers have adapted their methods to circumvent web application firewall (WAF) configurations designed to block access to the vulnerable PeopleSoft Environment Management Hub endpoint.

Targeted Industries and Scope

The campaign’s scope spans multiple industries, including technology, healthcare, government, and transportation, with educational institutions also reported as targets.

FBI Involvement and Zero-Day Claims

ShinyHunters has asserted that the FBI was among its victims, claiming to have exploited a newly discovered zero-day in Oracle PeopleSoft. The group alleged unauthorized access to sensitive data involving FBI personnel and cited an FBI advisory issued in May as a motive for the attack. While the FBI acknowledged disruptions to online services, no confirmation has been provided regarding the validity of the claims or the extent of system compromises.

“The FBI acknowledged disruptions to online services, but no confirmation has been provided regarding the validity of the claims or the extent of system compromises.”

SIDEEYE Backdoor Deployment

A newly identified backdoor called SIDEEYE has been deployed by attackers on compromised Windows-based PeopleSoft servers. This multi-stage malware communicates with adversary-controlled command-and-control servers and masquerades as a legitimate “Light Alloy” media player installer. The malicious payload was initially signed with a revoked digital certificate, allowing it to evade initial detection.

Capabilities of SIDEEYE

SIDEEYE enables threat actors to extract credentials, manipulate files and processes, establish reverse shells, and route network traffic through infected systems.

Security Recommendations

Security experts advise immediate action to mitigate risks. Organizations are urged to apply patches for CVE-2026-35273, conduct thorough inspections for web shells and SIDEEYE indicators, and rotate credentials potentially exposed during the breach. Network traffic analysis and log reviews should focus on anomalies linked to the campaign.

Implications and Lessons Learned

The incident underscores the risks of relying on temporary WAF adjustments instead of addressing underlying vulnerabilities. Attackers in this case specifically tailored their techniques to exploit gaps in organizations’ patching processes. The incident highlights the persistent threat of cybercriminal groups leveraging unpatched systems for large-scale intrusions. Enterprises must prioritize proactive vulnerability management and continuous monitoring to counter evolving attack methodologies.



About Author

en_USEnglish