ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAFs via percent-encoded paths and deploying web shells and the SIDEEYE backdoor.
Google Cloud analysts linked renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273 to UNC6240, also known as ShinyHunters, now targeting technology, IT services, healthcare, agriculture, transport and government organizations. Attackers bypass WAF blocking rules by percent-encoding a single character in the request path (/%50SEMHUB/), which the PeopleSoft application server decodes before routing. They then deploy JSP-based web shells or execute commands in memory, some with root or SYSTEM-level permissions, and install the SIDEEYE backdoor that steals browser and desktop credentials, plus Neo-reGeorg tunneling for lateral movement. IoCs include C2 IPs 5.199.162.157, 104.219.234.138, 162.219.30.165 and domain winmanage-me.network.