# ShinyHunters (UNC6240) Exploits Oracle PeopleSoft PeopleTools CVE-2026-35273 Zero-Day to Compromise 100+ Higher-Education Organizations

> ShinyHunters (UNC6240) exploited CVE-2026-35273, a critical (CVSS 9.8) unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools' Environment Management component (PSEMHUB), as a zero-day between May 27 and June 9, 2026. The campaign breached 100+ organizations — roughly 68% in higher education and mostly U.S.-based — deploying MeshCentral agents for C2, extracting credentials from PeopleSoft config files, spraying SSH credentials for lateral movement, exfiltrating data with zstd, and extorting victims via the ShinyHunters Data Leak Site.

- **Published:** 2026-06-11T00:00:00Z
- **Last reviewed:** 2026-09-29T00:38:53.686Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0779
- **ID:** TL-2026-0779
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 56 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-35273

## Description

Mandiant and the Google Threat Intelligence Group (GTIG) identified an active compromise-and-extortion campaign by UNC6240 (publicly self-identifying as ShinyHunters) that exploited Oracle PeopleSoft PeopleTools as a zero-day. The core vulnerability, CVE-2026-35273, is a critical unauthenticated RCE (CVSS 3.1 base score 9.8) in the Environment Management component of PeopleTools (officially affected versions 8.61 and 8.62, with earlier/unsupported releases warned as potentially affected). Attackers reached the vulnerable PSEMHUB (Environment Management Hub) via the /PSEMHUB/hub and /PSIGW/HttpListeningConnector endpoints. Reporting characterizes the intrusion as a 'gadget chain' combining older issues with the zero-day, consistent with Java deserialization / XMLDecoder abuse, achieving full takeover of cloud and on-premises PeopleSoft instances.

Following initial access, the actors installed MeshCentral (open-source remote management, v1.1.59) agents named to masquerade as Azure operations tooling (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe, and a Linux meshagent), and beaconed over WebSocket Secure (wss://azurenetfiles.net:443/agent.ashx) to infrastructure mimicking Microsoft Azure NetApp Files. They installed acme-client for SSL certificate automation and used meshctrl.js for command execution. Recovered .bash_history and exposed Python SimpleHTTP staging servers (port 8888 on 142.11.200.186-190) revealed deep PeopleSoft familiarity: extracting addresses/hostnames and credentials from psappsrv.cfg, mapping web/app/batch tiers via config.xml and /etc/hosts, and inspecting NFS mount points.

Lateral movement used a per-victim '<abbrev>_fanout.sh' script performing SSH credential spraying (via sshpass) against enumerated PeopleSoft nodes using hardcoded usernames (e.g., psoft, oracle, linuxadm) and passwords, with SSH key-based authentication as a fallback. The actors deployed defacement/extortion marker files named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT into webserv and appserv directories, archived staged data with zstd (pv | zstd -3 -T0), and exfiltrated it over SSH to a ShinyHunters DLS mirror at 176.120.22.24, publishing stolen data on June 9, 2026. Oracle released an out-of-band Security Alert for CVE-2026-35273 on June 10, 2026. Confirmed and reported victims include the University of Nottingham; the actors also claimed an unsuccessful attempt against an FBI portal running PeopleSoft.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1036 Masquerading
- T1552 Unsecured Credentials
- T1110 Brute Force
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1018 Remote System Discovery
- T1021 Remote Services
- T1560 Archive Collected Data
- T1219 Remote Access Tools
- T1071 Application Layer Protocol
- T1048 Exfiltration Over Alternative Protocol
- T1491 Defacement
- T1657 Financial Theft
- T1595 Active Scanning
- T1070 Indicator Removal
- T1046 Network Service Discovery
- T1187 Forced Authentication
- T1005 Data from Local System
- T1041 Exfiltration Over C2 Channel
- T1587 Develop Capabilities
- T1203 Exploitation for Client Execution
- T1133 External Remote Services
- T1078 Valid Accounts
- T1068 Exploitation for Privilege Escalation
- T1140 Deobfuscate/Decode Files or Information
- T1557 Adversary-in-the-Middle
- T1016 System Network Configuration Discovery
- T1570 Lateral Tool Transfer
- T1090 Proxy
- T1537 Transfer Data to Cloud Account
- T1485 Data Destruction
- T1087 Account Discovery
- T1518 Software Discovery
- T1583.001 Acquire Infrastructure: Domains
- T1588.002 Obtain Capabilities: Tool
- T1059.004 Command and Scripting Interpreter: Unix Shell

## Sources

- [ShinyHunters Targets Education Sector via Oracle PeopleSoft Exploit (Mandiant / Google Threat Intelligence Group)](https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/)
- [Oracle Security Alert Advisory - CVE-2026-35273](https://www.oracle.com/security-alerts/alert-cve-2026-35273.html)
- [Security Alert CVE-2026-35273 Released (Oracle Security Blog)](https://blogs.oracle.com/security/security-alert-cve-2026-35273-released)
- [NVD - CVE-2026-35273](https://nvd.nist.gov/vuln/detail/CVE-2026-35273)
- [Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks (BleepingComputer)](https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/)
- [Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert (Help Net Security)](https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/)
- [ShinyHunters claims it hacked 100 orgs by exploiting an Oracle PeopleSoft 0-day (The Register)](https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/)
- [Critical PeopleSoft PeopleTools Unauthenticated Takeover (CVE-2026-35273) (TheHackerWire)](https://www.thehackerwire.com/critical-peoplesoft-peopletools-unauthenticated-takeover-cve-2026-35273/)
- [Cybercriminals claim breach of Oracle PeopleSoft servers at 100-plus organizations (TechCrunch)](https://techcrunch.com/2026/06/10/cybercriminals-claim-breach-of-oracle-peoplesoft-servers-at-100-plus-organizations/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0779
