Threat reportVulnerabilityTL-2026-0779
ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations
ShinyHunters (UNC6240) Exploits Oracle PeopleSoft (TL-2026-0779), also tracked as ShinyHunters PeopleSoft Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-11 and last reviewed 2026-09-29. It is attributed to ShinyHunters with high confidence, affects Oracle PeopleSoft Enterprise PeopleTools, references 1 CVE (CVE-2026-35273), maps to 58 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 56 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 58MITRE ATT&CK
- Actors
- 1ShinyHunters
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 56Indicators of compromise
Key facts for TL-2026-0779
- Threat ID
- TL-2026-0779
- Also known as
- ShinyHunters PeopleSoft Campaign, PSEMHUB Zero-Day Campaign
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- education, higher education, government
- Target regions
- North America, United States, Europe, United Kingdom
- Detection rules
- 9
- Indicators of compromise
- 56
- Updates
- 2026-09-29 · 9 updates · revalidated 8× · latest source
Malware and tooling in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
Malware and tooling: MeshCentral, acme-client, sshpass
How ShinyHunters (UNC6240) Exploits Oracle PeopleSoft works
ShinyHunters (UNC6240) exploited CVE-2026-35273, a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools' Environment Management component (PSEMHUB), as a zero-day between May 27 and June 9, 2026. The campaign breached 100+ organizations — roughly 68% in higher education and mostly U.S.-based — deploying MeshCentral agents for C2, extracting credentials from PeopleSoft config files, spraying SSH credentials for lateral movement, exfiltrating data with zstd, and extorting victims via the ShinyHunters Data Leak Site.
Mandiant and the Google Threat Intelligence Group (GTIG) identified an active compromise-and-extortion campaign by UNC6240 (publicly self-identifying as ShinyHunters) that exploited Oracle PeopleSoft PeopleTools as a zero-day. The core vulnerability, CVE-2026-35273, is a critical unauthenticated RCE (CVSS 3.1 base score 9.8) in the Environment Management component of PeopleTools (officially affected versions 8.61 and 8.62, with earlier/unsupported releases warned as potentially affected). Attackers reached the vulnerable PSEMHUB (Environment Management Hub) via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector endpoints. Reporting characterizes the intrusion as a 'gadget chain' combining older issues with the zero-day, consistent with Java deserialization / XMLDecoder abuse, achieving full takeover of cloud and on-premises PeopleSoft instances.
Following initial access, the actors installed MeshCentral (open-source remote management, v1.1.59) agents named to masquerade as Azure operations tooling (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe, and a Linux meshagent), and beaconed over WebSocket Secure (wss://azurenetfiles.net:443/agent.ashx) to infrastructure mimicking Microsoft Azure NetApp Files. They installed acme-client for SSL certificate automation and used meshctrl.js for command execution. Recovered .bash_history and exposed Python SimpleHTTP staging servers (port 8888 on 142.11.200.186-190) revealed deep PeopleSoft familiarity: extracting addresses/hostnames and credentials from psappsrv.cfg, mapping web/app/batch tiers via config.xml and /etc/hosts, and inspecting NFS mount points.
Lateral movement used a per-victim '<abbrev>_fanout.sh' script performing SSH credential spraying (via sshpass) against enumerated PeopleSoft nodes using hardcoded usernames (e.g., psoft, oracle, linuxadm) and passwords, with SSH key-based authentication as a fallback. The actors deployed defacement/extortion marker files named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into webserv and appserv directories, archived staged data with zstd (pv | zstd -3 -T0), and exfiltrated it over SSH to a ShinyHunters DLS mirror at 176.120.22.24, publishing stolen data on June 9, 2026. Oracle released an out-of-band Security Alert for CVE-2026-35273 on June 10, 2026. Confirmed and reported victims include the University of Nottingham; the actors also claimed an unsuccessful attempt against an FBI portal running PeopleSoft.
MITRE ATT&CK techniques used in TL-2026-0779
Collection
T1005 Data from Local System; T1074 Data Staged; T1560 Archive Collected Data; T1560.001 Archive Collected Data: Archive via Utility
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery
Lateral Movement
T1021 Remote Services; T1021.004 Remote Services: SSH; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account
Execution
T1059 Command and Scripting Interpreter; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Persistence
T1078 Valid Accounts; T1133 External Remote Services; T1505 Server Software Component; T1505.003 Server Software Component: Web Shell
Credential Access
T1110 Brute Force; T1187 Forced Authentication; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files; T1557 Adversary-in-the-Middle
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1491 Defacement; T1491.001 Defacement: Internal Defacement; T1491.002 Defacement: External Defacement; T1657 Financial Theft
Resource Development
T1553.002 Subvert Trust Controls: Code Signing Certificates; T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1587 Develop Capabilities; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning; T1596.003 Search Open Technical Databases: Digital Certificates; T1596.005 Search Open Technical Databases: Scan Databases
Affected products and versions in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
- Oracle — PeopleSoft Enterprise PeopleTools
Vulnerable versions: 8.61; 8.62; earlier/unsupported versions (warned, untested)
Fixed in: 8.61 with Security Alert CVE-2026-35273 patch; 8.62 with Security Alert CVE-2026-35273 patch
Remediation for ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
Patches
- Oracle Security Alert CVE-2026-35273 (out-of-band, 2026-06-10) — apply to PeopleTools 8.61 and 8.62
Immediate actions
- Apply the Oracle out-of-band Security Alert patch for CVE-2026-35273 immediately on all PeopleTools 8.61/8.62 (and earlier/unsupported) instances, cloud and on-premises
- Disable the Environment Management Hub: disable the Environment Management Hub Service on multi-server deployments, or remove the PSEMHUB application entirely on single-server deployments
- Block external/internet access to /PSEMHUB/*, /PSEMHUB/hub, and /PSIGW/HttpListeningConnector at the perimeter and WAF
- Block/sinkhole the C2 domain azurenetfiles.net and the IOC IP ranges (142.11.200.186-190, 108.174.202.99, 176.120.22.24)
Workarounds
- Disable or remove PSEMHUB until patched
- Restrict PSEMHUB and PSIGW listener endpoints to internal management networks only
Longer-term hardening
- Place PeopleSoft web/app/batch tiers behind network segmentation and restrict SSH between PeopleSoft hosts to jump-host-only
- Rotate all credentials stored in psappsrv.cfg and other PeopleSoft config files; eliminate shared/hardcoded service passwords
- Deploy EDR with behavioral detection for MeshCentral/remote-management agents and unauthorized SSH credential spraying
CVEs associated with ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
Weaknesses (CWE) in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
Timeline of ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
Showing the 20 most recent tracked events.
- National Association of Insurance Commissioners (NAIC) identifies unauthorized access to its PeopleSoft-based systems.
- Mandiant / Google Threat Intelligence Group published technical analysis attributing the campaign to UNC6240 with IOCs and TTPs.
- CISA adds CVE-2026-35273 to its Known Exploited Vulnerabilities (KEV) catalog, mandating emergency remediation for federal agencies.
- Cyber Security Agency of Singapore (CSA) issues an alert on the critical Oracle PeopleSoft PeopleTools vulnerability.
- Council of Europe breach publicly reported: ShinyHunters claims 429,000 files (~297-300GB) of HR, payroll, tax, banking, and medical data, and sets a June 16, 2026 negotiation deadline.
- CISA BOD 26-04 remediation deadline for federal agencies running affected PeopleSoft PeopleTools versions.
- Trend Micro publishes detailed technical analysis of a PSIGW SSRF-to-RCE exploit chain executing inside the JVM.
- ShinyHunters' negotiation deadline for the Council of Europe passes; the Council refuses to pay or negotiate.
- Qualys ThreatPROTECT publishes independent technical defense guidance for the PSEMHUB authentication bypass, corroborating exploitation mechanics.
- Medtronic notifies customers of a ShinyHunters data breach tied to the same PeopleSoft campaign, exposing SSNs and health-related information.
- ShinyHunters publicly claims possession of NAIC data via cyber-risk press outlets.
- NAIC confirms it was the victim of a cyber incident via its PeopleSoft system and states no PII or payment data was accessed, partly disputing ShinyHunters' later data claims.
- ShinyHunters publishes roughly 3.1TB / 105,000+ files of claimed NAIC data on its leak site.
- Nissan Americas publicly confirms a data breach of current and former employee data (SSNs, banking, tax, dependent/beneficiary information) across the US, Canada, Mexico, and Brazil, attributing root cause to the PeopleSoft PSEMHUB zero-day exploitation.
- Mandiant observes continued intrusions reusing the unencrypted MeshAgent deployment pattern from the May zero-day wave.
- UNC6240 begins a renewed mass-exploitation wave using a WAF-bypass technique (percent-encoded /%50SEMHUB/ path) and expands targeting beyond education into technology, IT services, healthcare, agriculture, transportation, and government sectors globally.
- ShinyHunters claims a breach of the FBI's job-application portals (apply.fbijobs.gov, fbijobs.gov/special-agents) via the PeopleSoft PSEMHUB flaw, pivoting into an Amazon-hosted government cloud system and claiming theft of 2-3TB of data on agents, applicants, and spouses; the FBI says it is aware and investigating.
- Mandiant/GTIG publish 'ShinyHunters' Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft,' detailing the WAF-bypass mechanism, JSP web shells, Neo-reGeorg tunneling, rebranded MeshCentral infrastructure, and the new SIDEEYE backdoor delivered via a trojanized, EV-signed Light Alloy installer.
- The Hacker News publishes broad coverage of the renewed WAF-bypass campaign, one day after the Mandiant/GTIG report.
- FBI job-application portals remain offline; 404 Media verifies sample stolen data (names, addresses, phone numbers) against public records, though scope remains actor-asserted and journalist-verified rather than FBI-confirmed.
Update history for TL-2026-0779
- 2026-09-29 — ShinyHunters (UNC6240) claims FBI breach via alleged Oracle PeopleSoft zero-day; FBI job portals offline amid renewed CVE-2026-35273 WAF-bypass campaign: What changed No severity, exploitability, status or CVSS change: all are already CRITICAL / ACTIVE / 9.8. New indicators (2) apply.fbijobs.gov tracked as a claimed/unconfirmed victim entity; u2.jsp web shell filename added. All other IOCs i
- 2026-09-28 — ShinyHunters (UNC6240) renews mass exploitation of Oracle PeopleSoft CVE-2026-35273 with a WAF-bypass against workaround-only systems: What changed No field escalation — severity/exploitability/status/CVSS/attribution confidence are unchanged (still CRITICAL/ACTIVE/ACTIVE/9.8/HIGH). Material addition is the actor's claimed FBI job-portal breach and its current status. New
- 2026-09-27 — CVE-2026-35273: WAF-Bypass Exploitation of Oracle PeopleSoft EMHub Flaw Deploys Web Shells and SIDEEYE Backdoor: What changed No escalation: severity/exploitability/status/CVSS/attribution are unchanged (CRITICAL/ACTIVE/ACTIVE, 9.8, HIGH) and match the existing record exactly. New indicators (1) 1 new artifact location: /tmp/meshagent (unconfigured Li
- 2026-09-27 — ShinyHunters (UNC6240) Renewed Mass Exploitation of Oracle PeopleSoft via CVE-2026-35273 WAF Bypass: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (9.8), and attribution confidence (HIGH) were already at their ceiling. The campaign itself resumed/renewed: UNC6240 now bypasses WAF st
- 2026-09-27 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 1 newly-corroborated indicator(s).
- 2026-09-12 — Oracle PeopleSoft Zero-Day (CVE-2026-35273) Exploited by ShinyHunters/UNC6240 in Cloud/SaaS Supply-Chain Extortion Campaign: What changed No escalation to severity/exploitability/status/CVSS/attribution — all already at CRITICAL/ACTIVE/9.8/HIGH in the existing record. The change is scope: three additional confirmed extortion victims (Council of Europe, University
- 2026-08-28 — ShinyHunters (UNC6240) Exploit Oracle PeopleSoft Zero-Day CVE-2026-35273 to Breach 100+ Higher Education Institutions: What changed No escalation — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (9.8), and attribution confidence (HIGH) are unchanged and corroborated by the newer report. New indicators (0) None — all IOCs in the newer re
- 2026-07-11 — Nissan Employee Data Breach via Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) — ShinyHunters/UNC6240: What changed No field escalations — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (9.8), and attribution (HIGH, ShinyHunters/UNC6240) are unchanged. The campaign's disclosed victim scope is expanded. New indicators (3)
- 2026-07-11 — Nissan Americas Employee Data Breach via Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273): What changed No severity/exploitability/status escalation — both records already CRITICAL/ACTIVE. Root-cause detail refined: newer analysis (Trend Micro) frames part of the chain as an SSRF via /PSIGW/HttpListeningConnector feeding the dese
Sources cited for ShinyHunters (UNC6240) Exploits Oracle PeopleSoft
- ShinyHunters Targets Education Sector via Oracle PeopleSoft Exploit (Mandiant / Google Threat Intelligence Group)
- Oracle Security Alert Advisory - CVE-2026-35273
- Security Alert CVE-2026-35273 Released (Oracle Security Blog)
- NVD - CVE-2026-35273
- Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks (BleepingComputer)
- Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert (Help Net Security)
- ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day (The Register)
- Critical PeopleSoft PeopleTools Unauthenticated Takeover (CVE-2026-35273) (TheHackerWire)
- Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations (TechCrunch)
Detection coverage for TL-2026-0779
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0779 across Splunk SPL, Microsoft KQL and Sigma, covering 56 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-0779
6 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.