Google warns of new ShinyHunters campaign against Oracle PeopleSoft
Mandiant and GTIG warned of a fresh mass-exploitation campaign by ShinyHunters (UNC6240) targeting Oracle PeopleSoft customers. Attackers bypass WAF rules using the URL-encoded '%50' for 'P' in the /PSEMHUB path, deploying web shells and the SideEye backdoor. In June the group hit over 100 PeopleSoft customers, including Nissan and NAIC.
- Attacks expanded from education to government, healthcare, IT and transport
- WAF bypass via %50 in the /PSEMHUB path reaches the vulnerable servlet
- JSP web shells, SideEye backdoor and MeshCentral deployed
- Google advises patching CVE-2026-35273 and preparing for extortion
Read next
Security