ShinyHunters Exploits Oracle PeopleSoft Bug Despite WAF Defenses

Attackers linked to UnclearedNet <: UNC6240, also known as ShinyHunters, have resumed large-scale assaults against Oracle PeopleSoft systems by bypassing web application firewalls (WAFs) and installing web shells, despite prior mitigation efforts. Their focus remains on CVE-2026-35273—a recently disclosed critical remote code execution vulnerability previously leveraged in university-targeted zero-day attacks.

Organizations across technology, healthcare, IT services, agriculture, transportation, and government are now being targeted. The attackers gain potential access to confidential human resources, payroll, operational, or student data. Google Cloud analysts uncovered evidence of dozens of systems worldwide compromised with web shells, followed by hands-on intrusion activity. These findings reinforce that filtering traffic at the perimeter is not enough — patching vulnerabilities remains essential.

How WAF Bypass Works

The attack innovates by encoding just one character in the request path—transforming the endpoint name so certain WAFs and reverse proxies no longer match their blocking rules. However, PeopleSoft’s application server decodes requests before routing them to vulnerable functions, allowing the attack to slip through defenses.

Initially, attackers dispatch POST requests containing serialized Java objects to test whether exploitation is possible. Even when the system does not write a file—responding with only system details—these reconnaissance steps give clues that the environment is vulnerable. Monitoring logs across all servers, especially where load-balancing hides extensive internal traffic, is critical.

Web Shells, Backdoors, and What Follows

After verifying access, the attackers proceed in one of two ways: deploying durable JSP-based web shells, or executing code directly in memory, which avoids creating detectable files. On Windows servers, a second web shell stages a trojanized installer in tiny fragments to evade request size limits. It delivers a memory-resident backdoor dubbed SIDEEYE that can grab credentials, control processes, and act as a reverse shell or proxy.

On Linux, attackers apply remote-management tools to maintain persistence. Because once internal servers or databases are reached, damage may continue even post-remediation. Privileges observed range from SYSTEM or root to configuration and database credentials tied to PeopleSoft.

Key mitigation recommendations include applying the Oracle patch for CVE-2026-35273, disabling unnecessary components like the Environment Management Hub, and removing vulnerable modules entirely where feasible. Security teams should hunt in access logs for weird URL encodings relating to “/PSEMHUB/”, review for unexpected .jsp/.jspx or executable files, and watch for shells spawned by the WebLogic Java process. If a compromise is found, preserve evidence, rotate credentials, and examine outbound data transfer patterns to detect data theft, especially involving HR, payroll, or student records.

Here are indicators of compromise (IoCs) to watch for:

  • IP addresses: 5.199.162.157 (controller), 104.219.234.138 (exfiltration/staging), 162.219.30.165 (C2 for SIDEEYE)
  • Domain: winmanage-me.network (MeshCentral-based staging)
  • URI pattern: “/%50SEMHUB/” — percent-encoded bypass path
  • Web shell file paths under PSEMHUB.war including x.jsp, u.jsp, tunnel.jsp/.jspx and others
  • SHA-256 hashes for the common web shells and the SIDEEYE backdoor executable

Administrators are warned that treating any found web shell as a full system compromise—not just a website-level issue—is vital for containment. The risk includes long-term extortion or data theft, especially for databases holding sensitive employee or student information.

Analysts emphasize that delaying patching in favor of relying on perimeter defenses creates windows of exposure. The misuse of PeopleSoft via CVE-2026-35273 shows that adaptive evasion techniques, like minor URL encoding tricks, can render firewall rules ineffective. What matters now is coordinated response: patch, monitor, hunt, and assume breach.