ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAFs via percent-encoded paths and deploying web shells and the SIDEEYE backdoor.
Google Cloud analysts linked renewed mass exploitation of Oracle PeopleSoft flaw CVE-2026-35273 to UNC6240, also known as ShinyHunters, now targeting technology, IT services, healthcare, agriculture, transport and government organizations. Attackers bypass WAF blocking rules by percent-encoding a single character in the request path (/%50SEMHUB/), which the PeopleSoft application server decodes before routing. They then deploy JSP-based web shells or execute commands in memory, some with root or SYSTEM-level permissions, and install the SIDEEYE backdoor that steals browser and desktop credentials, plus Neo-reGeorg tunneling for lateral movement. IoCs include C2 IPs 5.199.162.157, 104.219.234.138, 162.219.30.165 and domain winmanage-me.network.
- CVE-2026-35273 exploited on dozens of systems worldwide after WAF bypass via percent-encoded request path
- JSP web shells and in-memory command execution evade file-based security tools
- SIDEEYE backdoor steals browser and desktop credentials and offers reverse shell and proxy
- Neo-reGeorg tunneling enables internal discovery and movement beyond the initial host
- Extortion risk for HR, payroll and student records; Oracle patch urged immediately
Vulnerabilities mentionedAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | winmanage-me.network | Command-and-control server for the SIDEEYE backdoor Domain winmanage-me.network Resolves to staging host and associated MeshCentral infrast |
| ipv4 | 104.219.234.138 | Attack controller, scanner, and HTTP callback receiver IPv4 104.219.234.138 Exfiltration staging and remote-management host IPv4 162.21 |
| ipv4 | 162.219.30.165 | 34.138 Exfiltration staging and remote-management host IPv4 162.219.30.165 Command-and-control server for the SIDEEYE backdoor Domain |
| ipv4 | 5.199.162.157 | tors of compromise (IoCs):- Type Indicator Description IPv4 5.199.162.157 Attack controller, scanner, and HTTP callback receiver IPv4 |
| sha256 | 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 | 06c0bfb4b1c3fe494 x.jsp primary execution web shell SHA-256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 u.jsp execution stager servlet SHA-256 419c571ee38b7e7266d1 |
| sha256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 |
Full article880 words · extracted from cybersecuritynews.com · click to collapse
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.
The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained. The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.
The latest wave has widened to technology, IT services, healthcare, agriculture, transport, and government organizations, putting systems that hold HR, payroll, and operational data at risk.
Analysts from Google Cloud identified the renewed mass exploitation and linked it to UNC6240, also known as ShinyHunters.
Google Cloud said in a report shared with Cyber Security News (CSN) that attackers placed web shells on dozens of systems worldwide, then used them for direct hands-on activity.
The development is a warning that perimeter controls cannot replace software updates. Earlier reporting on the PeopleSoft zero-day RCE attacks documented how the same flaw gave unauthenticated attackers a route into exposed enterprise applications before a patch was released.
ShinyHunters Bypasses WAF Protections
The attackers changed the vulnerable request path by encoding one character rather than sending the normal endpoint name. Some WAFs and reverse proxies compare the request as written.
The PeopleSoft application server, however, decodes it before routing it to the affected service. That mismatch lets the request reach the target despite a literal blocking rule.
Before moving further, the group typically sent several POST requests carrying a serialized Java object to check whether a server could be exploited.
A vulnerable system returned operating-system details without necessarily writing a file. A failed-looking event may still be evidence of reconnaissance, so defenders should review logs across all nodes, particularly where load balancing is used.
.webp)
Once access was confirmed, the attackers either created JSP-based web shells or executed commands directly in memory. The first method creates a durable route back into the server; the second can leave no new file for file-based security tools to detect.
This gap reinforces why organizations should examine application and process activity together. The campaign also reflects a broader extortion risk.
Previous coverage of the Nissan PeopleSoft breach confirmation showed the potential consequences when attackers reach systems containing employee information.
In this campaign, some observed commands ran with root or SYSTEM-level permissions, while others still had access to PeopleSoft configuration and database connection information.
Web Shells Lead to Backdoors
On compromised Windows servers, the operators used a second web shell to transfer a trojanized installer in small chunks, avoiding request-size limits.
The resulting SIDEEYE backdoor was loaded in memory and could steal browser and desktop credentials, manage processes and files, and provide an interactive reverse shell or proxy connection.
The group also used tunneling software to route internal traffic through ordinary web connections, enabling discovery and movement beyond the initial PeopleSoft host.
On Linux systems, it deployed remote-management tooling for persistence. This pattern should prompt teams to investigate whether a PeopleSoft compromise has spread to connected databases or other internal servers.
A foothold there can expose data even after the original server is secured. Organizations should apply the Oracle security patch for CVE-2026-35273 and keep supported PeopleTools versions.
Administrators should disable the Environment Management Hub when it is not needed, or remove the affected application where appropriate. The Oracle emergency security update explains why rapid patching matters for internet-facing PeopleSoft deployments.
Security teams should search access logs for the encoded route and related external POST activity, then inspect PeopleSoft web application directories for unapproved JSP, JSPX, or executable files.
They should also alert on command shells spawned by the WebLogic Java process. If a shell is found, they should preserve evidence, rotate credentials available to the application account, and watch for unusually large outbound transfers.
Affected organizations should also prepare for possible data-theft extortion and review database audit logs for bulk exports of HR, payroll, or student records. Treating a detected web shell as a full system compromise, rather than a simple website issue, is essential to containing this campaign.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 5.199.162.157 | Attack controller, scanner, and HTTP callback receiver |
| IPv4 | 104.219.234.138 | Exfiltration staging and remote-management host |
| IPv4 | 162.219.30.165 | Command-and-control server for the SIDEEYE backdoor |
| Domain | winmanage-me.network | Resolves to staging host and associated MeshCentral infrastructure |
| URI pattern | /%50SEMHUB/ | Percent-encoded WAF-bypass path |
| File path | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/x.jsp | Primary command-execution web shell path |
| File path | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/u.jsp | File-transfer and execution web shell path |
| File path | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/Ple64.exe | SIDEEYE backdoor delivery path |
| File path | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jsp | Neo-reGeorg tunnel path |
| File path | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jspx | Neo-reGeorg JSPX tunnel path |
| SHA-256 | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 | x.jsp primary execution web shell |
| SHA-256 | 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 | u.jsp execution stager servlet |
| SHA-256 | 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86 | tunnel.jsp Neo-reGeorg JSP tunnel |
| SHA-256 | ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07 | tunnel.jspx Neo-reGeorg JSPX tunnel |
| SHA-256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 | Ple64.exe trojanized installer delivering SIDEEYE |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.