Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
ShinyHunters (UNC6240) resumed mass-exploiting Oracle PeopleSoft via a WAF-bypassing variant of CVE-2026-35273, deploying web shells and SideEye to extort victims.
Mandiant and Google Threat Intelligence warn that ShinyHunters (UNC6240) modified its exploit for CVE-2026-35273 to bypass WAF rules, using URL-encoded '%50' to reach the vulnerable PSEMHUB endpoint. The new wave expands from education to agriculture, government, healthcare, IT services, technology, and transportation; the earlier June campaign hit 100+ customers including Nissan, NAIC, and University of Nottingham, and the FBI may be a recent victim. Attackers establish persistence with single-line JSP web shells, deploy the SideEye backdoor for credential theft, and use Neo-reGeorg tunneling and MeshCentral for lateral movement and remote management. Google urges customers to patch CVE-2026-35273 and prepare for data-theft extortion.