Changing one letter to its URL code let attackers walk past firewall rules meant to block a critical Oracle flaw. According to a new report from Mandiant and Google Threat Intelligence Group, that trick has fueled a fresh wave of ShinyHunters PeopleSoft attacks. This time, the group planted web shells on dozens of systems worldwide.
At a Glance
| Actor | ShinyHunters, tracked by Google as UNC6240 |
| Activity | Mass exploitation of CVE-2026-35273, web shells, backdoors, suspected data theft for extortion |
| Targets | Education, technology, IT services, healthcare, agriculture, transportation, government |
| Scale | Web shells on “dozens of systems” (GTIG); group claimed 300+ instances at 100+ organizations in June (unverified) |
| Law enforcement | No arrests tied to this campaign announced |
| Sources | Mandiant and Google Threat Intelligence Group; Arctic Wolf |
TL;DR
ShinyHunters is again exploiting a critical PeopleSoft flaw, this time with a simple WAF bypass. The group hit unpatched servers across many sectors and deployed web shells and a new backdoor. Google warns victims to expect extortion demands.
What Happened
From Zero-Day to Round Two
The flaw, CVE-2026-35273, sits in PeopleSoft’s Environment Management Hub. Arctic Wolf rates it 9.8 out of 10 and notes that it needs no login. ShinyHunters first used it as a zero-day between May 27 and June 9, 2026. Most of those victims were universities. Oracle then shipped an emergency fix on June 10.
Many organizations chose WAF rules over patching. However, GTIG says the group “adapted to published defensive guidance.” It now targets firms that “implemented WAF rules but did not patch the vulnerability.”
How the WAF Bypass Works
The trick is simple. The attackers swapped the letter P in the vulnerable path for its URL-encoded form. Many firewalls check the raw text before decoding it, so the rule never matched. Meanwhile, the PeopleSoft server decoded the path and served the flawed endpoint as normal.
GTIG urges defenders to block the normalized path instead. In its words, attackers “may use any percent-encoded, mixed-case, or otherwise non-normalized variant” of the path.

Test, Then Strike
Before each attack, the group sent five to 15 probe requests. Unpatched servers replied with their operating system, which confirmed they were open. Next, the attackers either dropped web shells or ran commands without writing files. In load-balanced setups, they sent bursts of requests so every node got a shell.
Tools Left Behind
On Windows servers, the group uploaded a fake media player installer called Ple64.exe. GTIG found that it hides a new backdoor it tracks as SIDEEYE. The backdoor can steal browser and app credentials, manage files, and open a reverse shell. Notably, the installer carried a valid code-signing certificate. GTIG has asked Sectigo to revoke it.
The group also used the Neo-reGeorg tunneling kit to move deeper into networks. On Linux, it installed MeshAgent, a legitimate remote management tool, for lasting access. Arctic Wolf had spotted MeshCentral agents on attacker servers back in June as well.
Who Is Behind It
Google attributes the activity to UNC6240, the cluster it links to the ShinyHunters name. The same group ran the June zero-day wave. GTIG ties the two waves together through the same flaw, tools, and methods. Still, this is a vendor attribution, and GTIG does not state a formal confidence level. No authority has charged anyone over these specific attacks.
Impact and Scale
GTIG saw web shells on dozens of systems in at least seven sectors. About a quarter of the attackers’ commands ran as root or SYSTEM. That level of access gives full control of the host. The rest ran under PeopleSoft service accounts. Even so, those accounts can still reach database passwords, HR data, payroll, and student records.
In June, ShinyHunters claimed it had hit over 300 instances at more than 100 organizations. That figure comes from the group and remains unverified. Google has not published a victim count for the new wave.
How to Stay Protected
Mandiant is blunt: “WAF rules and path-based blocking are not a substitute for patching.” To guard against ShinyHunters PeopleSoft attacks, teams should:
- Apply Oracle’s Security Alert patch for CVE-2026-35273 now.
- Disable or remove the Environment Management Hub if it is not needed.
- Search WebLogic logs for the hub path in any encoded or mixed-case form.
- Scan PeopleSoft web folders for unknown JSP or EXE files on every node.
- Rotate all credentials the PeopleSoft service account can read.
- Check hosts for unexpected MeshCentral agents and large archive files.
Finally, GTIG warns that ShinyHunters has “a well-established pattern of data theft extortion.” Any affected organization should prepare for ransom emails and possible leak-site posts.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!