Threat reportVulnerabilityTL-2026-0779

ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations

criticalACTIVE

ShinyHunters (UNC6240) Exploits Oracle PeopleSoft (TL-2026-0779), also tracked as ShinyHunters PeopleSoft Campaign, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-11 and last reviewed 2026-09-29. It is attributed to ShinyHunters with high confidence, affects Oracle PeopleSoft Enterprise PeopleTools, references 1 CVE (CVE-2026-35273), maps to 58 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 56 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
58MITRE ATT&CK
Actors
1ShinyHunters
Detection rules
9SPL · KQL · Sigma
IOCs
56Indicators of compromise

Key facts for TL-2026-0779

Threat ID
TL-2026-0779
Also known as
ShinyHunters PeopleSoft Campaign, PSEMHUB Zero-Day Campaign
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
ShinyHunters
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
education, higher education, government
Target regions
North America, United States, Europe, United Kingdom
Detection rules
9
Indicators of compromise
56
Updates
2026-09-29 · 9 updates · revalidated 8× · latest source

Malware and tooling in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

Malware and tooling: MeshCentral, acme-client, sshpass

How ShinyHunters (UNC6240) Exploits Oracle PeopleSoft works

ShinyHunters (UNC6240) exploited CVE-2026-35273, a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools' Environment Management component (PSEMHUB), as a zero-day between May 27 and June 9, 2026. The campaign breached 100+ organizations — roughly 68% in higher education and mostly U.S.-based — deploying MeshCentral agents for C2, extracting credentials from PeopleSoft config files, spraying SSH credentials for lateral movement, exfiltrating data with zstd, and extorting victims via the ShinyHunters Data Leak Site.

Mandiant and the Google Threat Intelligence Group (GTIG) identified an active compromise-and-extortion campaign by UNC6240 (publicly self-identifying as ShinyHunters) that exploited Oracle PeopleSoft PeopleTools as a zero-day. The core vulnerability, CVE-2026-35273, is a critical unauthenticated RCE (CVSS 3.1 base score 9.8) in the Environment Management component of PeopleTools (officially affected versions 8.61 and 8.62, with earlier/unsupported releases warned as potentially affected). Attackers reached the vulnerable PSEMHUB (Environment Management Hub) via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector endpoints. Reporting characterizes the intrusion as a 'gadget chain' combining older issues with the zero-day, consistent with Java deserialization / XMLDecoder abuse, achieving full takeover of cloud and on-premises PeopleSoft instances.

Following initial access, the actors installed MeshCentral (open-source remote management, v1.1.59) agents named to masquerade as Azure operations tooling (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe, and a Linux meshagent), and beaconed over WebSocket Secure (wss://azurenetfiles.net:443/agent.ashx) to infrastructure mimicking Microsoft Azure NetApp Files. They installed acme-client for SSL certificate automation and used meshctrl.js for command execution. Recovered .bash_history and exposed Python SimpleHTTP staging servers (port 8888 on 142.11.200.186-190) revealed deep PeopleSoft familiarity: extracting addresses/hostnames and credentials from psappsrv.cfg, mapping web/app/batch tiers via config.xml and /etc/hosts, and inspecting NFS mount points.

Lateral movement used a per-victim '<abbrev>_fanout.sh' script performing SSH credential spraying (via sshpass) against enumerated PeopleSoft nodes using hardcoded usernames (e.g., psoft, oracle, linuxadm) and passwords, with SSH key-based authentication as a fallback. The actors deployed defacement/extortion marker files named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into webserv and appserv directories, archived staged data with zstd (pv | zstd -3 -T0), and exfiltrated it over SSH to a ShinyHunters DLS mirror at 176.120.22.24, publishing stolen data on June 9, 2026. Oracle released an out-of-band Security Alert for CVE-2026-35273 on June 10, 2026. Confirmed and reported victims include the University of Nottingham; the actors also claimed an unsuccessful attempt against an FBI portal running PeopleSoft.

MITRE ATT&CK techniques used in TL-2026-0779

Collection

T1005 Data from Local System; T1074 Data Staged; T1560 Archive Collected Data; T1560.001 Archive Collected Data: Archive via Utility

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services; T1021.004 Remote Services: SSH; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account

Execution

T1059 Command and Scripting Interpreter; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools

Persistence

T1078 Valid Accounts; T1133 External Remote Services; T1505 Server Software Component; T1505.003 Server Software Component: Web Shell

Credential Access

T1110 Brute Force; T1187 Forced Authentication; T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files; T1557 Adversary-in-the-Middle

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1491 Defacement; T1491.001 Defacement: Internal Defacement; T1491.002 Defacement: External Defacement; T1657 Financial Theft

Resource Development

T1553.002 Subvert Trust Controls: Code Signing Certificates; T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1587 Develop Capabilities; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning; T1596.003 Search Open Technical Databases: Digital Certificates; T1596.005 Search Open Technical Databases: Scan Databases

Affected products and versions in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

  • Oracle — PeopleSoft Enterprise PeopleTools
    Vulnerable versions: 8.61; 8.62; earlier/unsupported versions (warned, untested)
    Fixed in: 8.61 with Security Alert CVE-2026-35273 patch; 8.62 with Security Alert CVE-2026-35273 patch

Remediation for ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

Patches

  • Oracle Security Alert CVE-2026-35273 (out-of-band, 2026-06-10) — apply to PeopleTools 8.61 and 8.62

Immediate actions

  • Apply the Oracle out-of-band Security Alert patch for CVE-2026-35273 immediately on all PeopleTools 8.61/8.62 (and earlier/unsupported) instances, cloud and on-premises
  • Disable the Environment Management Hub: disable the Environment Management Hub Service on multi-server deployments, or remove the PSEMHUB application entirely on single-server deployments
  • Block external/internet access to /PSEMHUB/*, /PSEMHUB/hub, and /PSIGW/HttpListeningConnector at the perimeter and WAF
  • Block/sinkhole the C2 domain azurenetfiles.net and the IOC IP ranges (142.11.200.186-190, 108.174.202.99, 176.120.22.24)

Workarounds

  • Disable or remove PSEMHUB until patched
  • Restrict PSEMHUB and PSIGW listener endpoints to internal management networks only

Longer-term hardening

  • Place PeopleSoft web/app/batch tiers behind network segmentation and restrict SSH between PeopleSoft hosts to jump-host-only
  • Rotate all credentials stored in psappsrv.cfg and other PeopleSoft config files; eliminate shared/hardcoded service passwords
  • Deploy EDR with behavioral detection for MeshCentral/remote-management agents and unauthorized SSH credential spraying

CVEs associated with ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

CVE-2026-35273

Weaknesses (CWE) in ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

CWE-502, CWE-306, CWE-918

Timeline of ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

Showing the 20 most recent tracked events.

  • National Association of Insurance Commissioners (NAIC) identifies unauthorized access to its PeopleSoft-based systems.
  • Mandiant / Google Threat Intelligence Group published technical analysis attributing the campaign to UNC6240 with IOCs and TTPs.
  • CISA adds CVE-2026-35273 to its Known Exploited Vulnerabilities (KEV) catalog, mandating emergency remediation for federal agencies.
  • Cyber Security Agency of Singapore (CSA) issues an alert on the critical Oracle PeopleSoft PeopleTools vulnerability.
  • Council of Europe breach publicly reported: ShinyHunters claims 429,000 files (~297-300GB) of HR, payroll, tax, banking, and medical data, and sets a June 16, 2026 negotiation deadline.
  • CISA BOD 26-04 remediation deadline for federal agencies running affected PeopleSoft PeopleTools versions.
  • Trend Micro publishes detailed technical analysis of a PSIGW SSRF-to-RCE exploit chain executing inside the JVM.
  • ShinyHunters' negotiation deadline for the Council of Europe passes; the Council refuses to pay or negotiate.
  • Qualys ThreatPROTECT publishes independent technical defense guidance for the PSEMHUB authentication bypass, corroborating exploitation mechanics.
  • Medtronic notifies customers of a ShinyHunters data breach tied to the same PeopleSoft campaign, exposing SSNs and health-related information.
  • ShinyHunters publicly claims possession of NAIC data via cyber-risk press outlets.
  • NAIC confirms it was the victim of a cyber incident via its PeopleSoft system and states no PII or payment data was accessed, partly disputing ShinyHunters' later data claims.
  • ShinyHunters publishes roughly 3.1TB / 105,000+ files of claimed NAIC data on its leak site.
  • Nissan Americas publicly confirms a data breach of current and former employee data (SSNs, banking, tax, dependent/beneficiary information) across the US, Canada, Mexico, and Brazil, attributing root cause to the PeopleSoft PSEMHUB zero-day exploitation.
  • Mandiant observes continued intrusions reusing the unencrypted MeshAgent deployment pattern from the May zero-day wave.
  • UNC6240 begins a renewed mass-exploitation wave using a WAF-bypass technique (percent-encoded /%50SEMHUB/ path) and expands targeting beyond education into technology, IT services, healthcare, agriculture, transportation, and government sectors globally.
  • ShinyHunters claims a breach of the FBI's job-application portals (apply.fbijobs.gov, fbijobs.gov/special-agents) via the PeopleSoft PSEMHUB flaw, pivoting into an Amazon-hosted government cloud system and claiming theft of 2-3TB of data on agents, applicants, and spouses; the FBI says it is aware and investigating.
  • Mandiant/GTIG publish 'ShinyHunters' Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft,' detailing the WAF-bypass mechanism, JSP web shells, Neo-reGeorg tunneling, rebranded MeshCentral infrastructure, and the new SIDEEYE backdoor delivered via a trojanized, EV-signed Light Alloy installer.
  • The Hacker News publishes broad coverage of the renewed WAF-bypass campaign, one day after the Mandiant/GTIG report.
  • FBI job-application portals remain offline; 404 Media verifies sample stolen data (names, addresses, phone numbers) against public records, though scope remains actor-asserted and journalist-verified rather than FBI-confirmed.

Update history for TL-2026-0779

Sources cited for ShinyHunters (UNC6240) Exploits Oracle PeopleSoft

Detection coverage for TL-2026-0779

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0779 across Splunk SPL, Microsoft KQL and Sigma, covering 56 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
56 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0779

6 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats