ShinyHunters Resurfaces with Sophisticated WAF Bypass Tactics Targeting Oracle PeopleSoft Vulnerability

The notorious ShinyHunters extortion gang has resurfaced with a potent new tactic, employing a URL-encoding exploit to circumvent Web Application Firewall (WAF) rules designed to protect against the critical Oracle PeopleSoft CVE-2026-35273 vulnerability. This cunning maneuver has allowed the threat actors to reignite widespread exploitation of unpatched PeopleSoft servers, enabling further data theft and the deployment of sophisticated malware. Google’s Mandiant and Threat Intelligence Group (GTIG) have been instrumental in uncovering and detailing this evolving threat landscape, highlighting the persistent challenges in defending against well-resourced cybercriminal organizations.

The renewed exploitation campaign underscores a critical cat-and-mouse game between attackers and defenders. Initially, organizations that had not yet applied Oracle’s security patches attempted to mitigate the risk by implementing WAF rules to block access to the vulnerable PSEMHUB endpoint. However, ShinyHunters has adeptly adapted its attack vectors, demonstrating a deep understanding of how WAFs process web requests. By encoding the path to the vulnerable endpoint, the attackers can now bypass these protective layers, leaving potentially millions of users’ sensitive data at risk. This development signals a significant escalation in the campaign, moving beyond simple exploitation to a more stealthy and persistent infiltration strategy.

Background: The Genesis of the Threat

The initial discovery of this critical vulnerability and its exploitation by ShinyHunters sent shockwaves through the cybersecurity community. On June 10, BleepingComputer first reported on ShinyHunters’ audacious attacks, which leveraged a zero-day flaw in Oracle PeopleSoft systems. The gang claimed to have compromised servers belonging to approximately 100 organizations, initiating a wave of data exfiltration. This zero-day exploit allowed unauthenticated remote code execution, a highly coveted capability for threat actors seeking to gain unauthorized access to sensitive systems.

The speed at which Oracle responded was commendable. The very next day, on June 11, Oracle released a patch for the PeopleSoft zero-day vulnerability, assigning it the designation CVE-2026-35273. The company confirmed that the flaw indeed permitted unauthenticated remote code execution, a critical security risk. Concurrently, Google’s GTIG corroborated BleepingComputer’s findings, identifying ShinyHunters as UNC6240 and confirming their exploitation of CVE-2026-35273, with a particular focus on the education sector.

Initial Mitigation and the Emergence of the Bypass

In the immediate aftermath of the vulnerability’s disclosure and patching, Mandiant provided crucial advice to organizations. For those unable to immediately deploy the security updates or disable the Environment Management Hub, the recommendation was to block all external access to the vulnerable /PSEMHUB/* endpoint. This measure was intended to act as a temporary but effective barrier, preventing attackers from reaching the exploitable component.

However, the effectiveness of this mitigation strategy was short-lived. A recent report from Google details how ShinyHunters has evolved its approach. Instead of directly targeting the /PSEMHUB/ path, the attackers are now utilizing URL-encoded versions of the path. For instance, instead of a standard request to /PSEMHUB/, the attackers are sending requests like /%50SEMHUB/. The sequence %50 is the standard percent-encoding for the uppercase letter ‘P’.

This seemingly minor alteration has profound implications for WAF security. Mandiant explains that many WAFs and reverse proxies operate by inspecting the literal request path before it is decoded by the web server. Consequently, WAF rules specifically configured to block the string /PSEMHUB/ will fail to detect and block its URL-encoded equivalent, /%50SEMHUB/. The Oracle WebLogic server, however, correctly decodes the encoded ‘P’ and routes the request to the vulnerable PSEMHUB endpoint, thereby bypassing the WAF’s intended protection. This clever technique effectively renders a common security control obsolete, allowing attackers to operate with renewed impunity.

A New Era of Mass Exploitation

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The implications of this WAF bypass are significant. Mandiant explicitly warns that this allows threat actors to compromise systems whose administrators may have believed they were adequately protected by their WAF configurations. The bypass is not necessarily limited to the %50 encoding of ‘P’. Google cautions that ShinyHunters could easily adapt this tactic, employing other percent-encoded variations, mixed-case characters, or alternative encoding schemes to circumvent WAF rules in the future. This adaptability suggests a proactive and sophisticated threat actor that is continuously refining its techniques.

In light of this evolving threat, Mandiant strongly reiterates that relying solely on WAF rules to protect against CVE-2026-35273 is insufficient. The most effective and recommended defense remains the immediate installation of the latest security updates provided by Oracle. For incident response and forensic analysis, organizations are advised to meticulously review their WebLogic access logs. The presence of requests to /PSEMHUB/ and its various encoded variants, such as /%50SEMHUB/, can serve as crucial indicators of exploitation attempts.

The scope of this renewed attack campaign is concerning. Google reports that the new wave of attacks has already resulted in the deployment of web shells on dozens of systems globally. The compromised organizations span a wide range of critical sectors, including higher education, technology, IT services, healthcare, agriculture, transportation, and various government entities. This broad targeting indicates that ShinyHunters is not focused on a niche market but is broadly seeking to exploit vulnerable systems across diverse industries.

Mandiant’s report emphasizes the urgency for organizations running Oracle PeopleSoft to take immediate action. Beyond installing patches, further remediation and hardening guidance are being provided to bolster defenses against future attacks.

Attack Methodology: A Step-by-Step Breach

Understanding the precise methodology employed by ShinyHunters provides valuable insight into their operational tactics. Before attempting to exploit the vulnerability, the attackers typically initiate their reconnaissance by sending between five and 15 POST requests to /%50SEMHUB/hub. These requests are crafted to contain serialized Java objects.

On vulnerable systems, these initial probes yield critical information about the host operating system without leaving obvious traces or disrupting the service. This reconnaissance phase allows ShinyHunters to quietly determine if a server is susceptible to exploitation, enabling them to proceed with greater confidence and stealth.

Once a vulnerable system is identified, the threat actors re-exploit the CVE-2026-35273 flaw. This time, their objective is to execute commands directly in memory or to deploy malicious web shells. The attackers have been observed deploying a primary web shell named x.jsp for direct command execution. Additionally, they utilize u.jsp and u2.jsp web shells specifically designed for uploading larger files, suggesting a multi-stage approach to data exfiltration and system compromise.

Post-Compromise Tooling and Lateral Movement

The sophistication of ShinyHunters’ post-compromise activities is a significant concern. On compromised Windows servers, the attackers have been observed deploying an executable named Ple64.exe. This executable is designed to masquerade as a legitimate signed installer for the Light Alloy media player. However, its true purpose is to install a backdoor that Google tracks as the SIDEEYE malware.

The SIDEEYE backdoor is a multi-functional tool designed for persistent access and further exploitation. Its capabilities include stealing credentials, managing processes and files, establishing interactive reverse shells for remote command and control, and providing reverse proxy functionality. This allows attackers to pivot within the compromised network and mask their activities.

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Furthermore, ShinyHunters has demonstrated an understanding of advanced network tunneling techniques by deploying the open-source Neo-reGeorg tunneling toolkit. Files named tunnel.jsp and tunnel.jspx are used to facilitate this. Neo-reGeorg enables the tunneling of SOCKS5 proxy traffic over standard HTTP and HTTPS connections. This allows the compromised PeopleSoft server to be used as a pivot point, enabling lateral movement into the internal network, bypassing network segmentation and perimeter defenses.

For compromised Linux systems, Mandiant has observed ShinyHunters leveraging legitimate remote management software. Specifically, the attackers have been seen using MeshAgent to maintain persistent access to these Linux environments. The use of legitimate tools highlights an attacker’s attempt to blend in with normal network traffic, making detection more challenging.

A History of Bold Claims and Exploits

This latest wave of attacks is not ShinyHunters’ first foray into exploiting Oracle PeopleSoft vulnerabilities. In the past, the group gained notoriety for claiming responsibility for a breach of FBI systems, which they alleged was facilitated by a previously unknown zero-day vulnerability in Oracle PeopleSoft.

On September 22, ShinyHunters informed BleepingComputer that they had exploited what they described as a "new Oracle PeopleSoft zero-day vulnerability" to gain access to the FBI Jobs platform. They further claimed that this exploit enabled them to spread laterally into the FBI’s AWS GovCloud infrastructure. The group asserted that they had exfiltrated between 2TB and 3TB of data, encompassing information related to current and former FBI employees, job applicants, and other internal systems.

At the time of those claims, BleepingComputer could not independently verify the existence of the alleged zero-day, the extent of the lateral movement, or the volume of data reportedly stolen. The FBI acknowledged that it was investigating claims of unauthorized activity affecting FBIjobs.gov but did not confirm a breach or data theft.

Crucially, ShinyHunters has since confirmed to BleepingComputer that they indeed utilized the WAF bypass technique against FBI Jobs. However, they maintain that they also exploited a separate, "NEW unknown vulnerability in the same PSEMHUB component," suggesting a continued focus on this particular area of PeopleSoft. This assertion raises the possibility of multiple vulnerabilities existing within the PSEMHUB component, or a sophisticated effort to create a narrative of broader compromise.

Implications and Future Concerns

The ongoing exploitation of CVE-2026-35273, coupled with the sophisticated WAF bypass, highlights several critical concerns for organizations relying on Oracle PeopleSoft:

  • Evolving Threat Landscape: Cybercriminals are continuously innovating. The ability of ShinyHunters to adapt their attack methods to bypass common security controls demonstrates the need for dynamic and multi-layered security strategies.
  • Patch Management is Paramount: The most effective defense remains timely patching. Organizations that delay security updates remain exceptionally vulnerable to known exploits.
  • WAF Limitations: While WAFs are a valuable component of a security posture, they are not infallible. Attackers can find ways to circumvent them, necessitating a broader approach to network security.
  • Data Breach Risks: The sensitive nature of data processed by PeopleSoft systems (HR, payroll, financial information) means that breaches can have severe financial, reputational, and regulatory consequences.
  • Lateral Movement and Persistent Access: The use of web shells, backdoors like SIDEEYE, and tunneling tools like Neo-reGeorg indicates that attackers aim for deep and persistent access, allowing them to move freely within an organization’s network.

Mandiant’s recommendations to prioritize patching and to actively monitor WebLogic logs for indicators of compromise are crucial. As organizations continue to navigate an increasingly complex threat environment, vigilance, proactive security measures, and rapid response capabilities are more critical than ever. The actions of groups like ShinyHunters serve as a stark reminder that cybersecurity is an ongoing battle requiring constant adaptation and reinforcement of defenses.

Related Posts

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

The U.S. Treasury Department has imposed sanctions on eight key members of the notorious Venezuelan criminal organization, Tren de Aragua (TdA), for their central roles in orchestrating a sophisticated and…

GitLab Issues Urgent Patch for Critical AI Gateway Vulnerability Enabling Arbitrary Code Execution

GitLab has issued a critical security advisory, urging its customers to immediately apply patches for a severe vulnerability within its AI Gateway service. This flaw, identified as CVE-2026-90970, poses a…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Patient Privacy Under Scrutiny as Nurse Allegedly Uses ChatGPT for Medical Notes Without Full Consent

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

Free Metro Redux Updates Pave the Way for Metro 2039 as Franchise Surpasses 50 Million Sales Milestone

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

White House Convenes Tech Giants for Landmark AI Safety Pledge, Officially Redefining the Technology as ‘Super Intelligence’

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

The Dark Side of AI: How a Startup Aims to Prevent Psychological Harm from Conversational Agents

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

U.S. Treasury Sanctions Eight Members of Venezuelan Gang Tren de Aragua for Widespread ATM Jackpotting Fraud

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience

How to Adjust the Audio Quality in Apple Music and Maximize Your High-Fidelity Listening Experience