ThreatBeaconXThreatBeaconXSubscribe
CriticalAPT · 4 min read

ShinyHunters’ Renewed Mass Exploitation Targets Oracle PeopleSoft

A renewed cyberattack campaign linked to UNC6240 is targeting vulnerable Oracle PeopleSoft environments through CVE-2026-35273, a critical remote code execution vulnerability in the PeopleSoft Environment Management Hub. Attackers are using a URL-encoding technique to bypass certain WAF protections before deploying web shells, executing commands, establishing network tunnels and deploying additional malware. The campaign has expanded across multiple sectors, creating potential risks involving sensitive data exposure, credential theft, lateral movement and data exfiltration.

Written by Aswini Devi Medisetti·Published Sep 29, 2026

Description

Oracle PeopleSoft environments are being targeted in a renewed exploitation campaign associated with UNC6240, a threat actor linked to the ShinyHunters ecosystem. The campaign abuses CVE-2026-35273, a critical vulnerability affecting the PeopleSoft Environment Management Hub (PSEMHUB), which can allow remote unauthenticated code execution.

Attackers have adapted their exploitation technique by using a URL-encoded representation of the PSEMHUB path. This can bypass certain WAF rules that rely on literal URL matching, allowing vulnerable systems to remain accessible despite perimeter protections.

Technical Description

CVE-2026-35273 affects Oracle PeopleSoft PeopleTools and the PeopleSoft Environment Management Hub. The vulnerability can be remotely exploited without authentication and may result in remote code execution.

The renewed campaign uses requests such as:

/%50SEMHUB/hub

The %50 value represents the letter P. After URL normalization, the application can interpret the request as:

/PSEMHUB/hub

This difference in URL processing can allow attackers to bypass security controls that inspect the request before normalization.

Attack Overview

The attack begins with POST requests targeting the encoded PSEMHUB path. Attackers can use these requests to determine whether a PeopleSoft server is vulnerable.

After successful exploitation, attackers have been observed deploying JSP web shells and executing commands directly through the vulnerable servlet. Additional tooling has been used for network tunneling, remote access and persistence.

Observed activity includes web shells such as x.jsp, u.jsp and u2.jsp, Neo-ReGeorg tunneling components, the SIDEEYE backdoor and MeshAgent on Linux systems.

Technical Analysis

The primary technique observed in the renewed campaign is URL encoding of the first character in the PSEMHUB path.

Instead of directly requesting:

/PSEMHUB/

attackers use:

/%50SEMHUB/

Security devices that perform literal string matching may fail to identify the encoded representation, while the downstream PeopleSoft application can decode the request and route it to the vulnerable servlet.

Attackers also sent multiple POST requests to /%50SEMHUB/hub containing serialized Java objects. Responses can provide information about the target environment and help attackers determine whether exploitation can proceed.

Following successful exploitation, attackers used JSP-based web shells for command execution and file uploads. Fileless command execution was also observed, meaning that malicious activity may occur without a web shell being written to disk.

On Windows systems, defenders may observe cmd.exe being launched by the WebLogic Java process. Linux systems may show /bin/sh or bash activity associated with the PeopleSoft/WebLogic process.

The campaign also involved the deployment of Ple64.exe, which masqueraded as a Light Alloy media player installer and was associated with the SIDEEYE backdoor. SIDEEYE supports capabilities including credential theft, process and file management, reverse shells and reverse-proxy functionality.

Neo-ReGeorg components such as tunnel.jsp and tunnel.jspx were also used for network tunneling. On Linux systems, attackers deployed MeshAgent, a legitimate remote-management component associated with MeshCentral.

Potential Impact

Successful exploitation may provide attackers with operating-system-level access to vulnerable PeopleSoft servers.

Potential consequences include:

  • Unauthorized access to PeopleSoft application data

  • Exposure of HR, payroll, financial and student information

  • Credential theft

  • Web-shell persistence

  • Remote command execution

  • Network tunneling

  • Lateral movement

  • Data collection and exfiltration

  • Potential extortion following data theft

The impact may be greater when PeopleSoft or WebLogic services operate with elevated privileges.

Recommendations & Immediate Actions

  1. Apply the appropriate Oracle security update for CVE-2026-35273.

  2. Disable or remove the Environment Management Hub where it is not required.

  3. Review WAF and reverse-proxy rules for encoded versions of the PSEMHUB path.

  4. Search WebLogic logs for /PSEMHUB/, /%50SEMHUB/ and POST requests to /hub.

  5. Inspect all WebLogic nodes for unexpected JSP, JSPX and executable files.

  6. Search for x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx and Ple64.exe.

  7. Investigate cmd.exe, /bin/sh or bash processes spawned by WebLogic.

  8. Rotate credentials accessible from compromised PeopleSoft systems.

  9. Review database and network logs for evidence of data access or exfiltration.

Preventive Actions

  • Keep PeopleTools and PeopleSoft components fully patched.

  • Minimize public exposure of EMHub.

  • Restrict unnecessary external access to PeopleSoft administration and integration interfaces.

  • Normalize URLs before applying security rules where technically possible.

  • Monitor unexpected JSP and JSPX file creation.

  • Deploy endpoint monitoring on PeopleSoft and WebLogic servers.

  • Apply least privilege to PeopleSoft and WebLogic service accounts.

  • Avoid running WebLogic with root or SYSTEM privileges where possible.

  • Monitor outbound connections from application servers.

  • Maintain database auditing for sensitive records.

  • Conduct regular threat hunting for exploitation attempts and web shells.

Indicators of Compromise

  • IPv4: 5.199.162.157

  • IPv4: 104.219.234.138

  • IPv4: 162.219.30.165

  • Domain: winmanage-me.network

Conclusion

The renewed exploitation of CVE-2026-35273 demonstrates how attackers can adapt quickly when organizations introduce perimeter defenses without addressing the underlying vulnerability.

By encoding a single character in the PSEMHUB path, attackers can potentially bypass WAF rules based on literal URL matching and continue targeting vulnerable PeopleSoft environments.

Organizations should prioritize patching, reduce unnecessary exposure of EMHub, review historical WebLogic logs and inspect all application nodes for web shells, command execution and unauthorized remote-management tools. WAF protections and URL-based controls should be treated as additional defensive layers rather than replacements for vulnerability remediation.

MITRE ATT&CK Mapping

T1190 — Exploit Public-Facing ApplicationT1505.003 — Web ShellT1059.003 — Windows Command ShellT1059.004 — Unix ShellT1219 — Remote Access SoftwareT1090 — ProxyT1552.001 — Credentials In FilesT1074.001 — Local Data StagingT1041 — Exfiltration Over C2 Channel