ThreatPaper
Data BreachMalwareExtortion & BlackmailCritical

ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273

By Sethu Satheesh · 29 Sept 2026 · 10 min read

Threat Actor: UNC6240 (linked to ShinyHunters), financially motivated · Target: Internet-facing Oracle PeopleSoft (PeopleTools 8.61/8.62) across higher education, technology, IT services, healthcare, agriculture, transportation and government

Source: cloud.google.com


Executive Summary

Some of the organizations breached in this campaign had, in a sense, done something about the vulnerability: rather than patch, they put a web application firewall rule in front of it. UNC6240 — the cluster Google's Threat Intelligence Group (GTIG/Mandiant) links to ShinyHunters — beat that rule by changing a single character in the URL.12

The vulnerability is CVE-2026-35273, a critical, unauthenticated remote-code-execution flaw in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools, versions 8.61 and 8.62. The National Vulnerability Database rates it CVSS 3.1 base score 9.8 and describes "takeover of PeopleSoft Enterprise PeopleTools" by an unauthenticated attacker over HTTP.3 The bug lives in the Environment Management Hub (PSEMHUB): a Java deserialization flaw in the hub servlet reachable at /PSEMHUB/hub.1 GTIG documented zero-day exploitation from May 27 to June 9, 2026 — largely against the education sector — before Oracle issued a Security Alert on June 10, 2026; the activity then broadened into a mass-exploitation campaign in September 2026 across higher education, technology, IT services, healthcare, agriculture, transportation and government.1

The WAF bypass is the detail worth internalising. Defenders who could not immediately patch blocked the vulnerable endpoint by string-matching /PSEMHUB at the WAF or reverse proxy. UNC6240 requested /%50SEMHUB/ instead — %50 is simply the percent-encoding of the letter "P."1 As GTIG puts it, "WAF and proxy rules that match the literal string /PSEMHUB before decoding do not match /%50SEMHUB/, while WebLogic decodes the path and serves the application normally."1 The firewall never sees a match; the application server decodes the path and routes the request to the vulnerable servlet anyway. GTIG warns that any percent-encoded, mixed-case, or otherwise non-normalized variant works, and that blocking must be enforced on the normalized path — which is a roundabout way of saying the WAF rule was never a substitute for the patch.1

From there, the intrusions are thorough. UNC6240 deployed JSP web shells (x.jsp for hex-encoded command execution, u.jsp/u2.jsp for chunked file upload), a signed and VMProtect-packed SIDEEYE backdoor masquerading as a Light Alloy media-player installer (Ple64.exe), Neo-reGeorg tunnels for SOCKS5 pivoting, and MeshCentral agents for persistent remote management.1 About a quarter of the observed commands ran as root or SYSTEM.1 GTIG is explicit about the endgame: UNC6240 "has a well-established pattern of data theft extortion" — steal the data, then threaten to publish it on a leak site unless paid.1 Organisations running internet-facing PeopleSoft should treat any host that answered a /%50SEMHUB/ request as compromised until proven otherwise.

Verification of Claims

  1. Claim: CVE-2026-35273 is a critical, unauthenticated RCE in PeopleSoft PeopleTools 8.61 and 8.62, rated CVSS 9.8. → Verified → The NVD entry describes a vulnerability in the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools, affected versions 8.61 and 8.62, "easily exploitable" by an "unauthenticated attacker with network access via HTTP," resulting in "takeover," with a CVSS 3.1 base score of 9.8 (vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).3

  2. Claim: UNC6240 bypassed WAF rules by URL-encoding one character of the path. → Verified (per GTIG) → GTIG states: "The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/." The WAF matches the literal path before decoding; WebLogic decodes and routes to the vulnerable servlet.1

  3. Claim: UNC6240 is ShinyHunters. → Assessed, not confirmed → GTIG tracks the activity as UNC6240 and links the cluster to ShinyHunters, whose established pattern is data-theft extortion. "UNC" designations are provisional clusters; the ShinyHunters linkage is GTIG's assessment, strong but not a courtroom-grade identification, and ShinyHunters is itself an overlapping, loosely-bounded label.1

  4. Claim: CVE-2026-35273 was exploited as a zero-day before a fix existed. → Verified (per GTIG) → GTIG documents exploitation beginning May 27, 2026 — weeks before Oracle's June 10, 2026 Security Alert — primarily against the education sector, making the initial wave genuine zero-day activity rather than post-patch opportunism.1

Timeline

Date Actor Event Source
May 27 – June 9, 2026 UNC6240 Zero-day exploitation of CVE-2026-35273, largely against education 1
June 10, 2026 Oracle Issues Security Alert for CVE-2026-35273 13
September 2026 UNC6240 Renewed mass-exploitation campaign; WAF-bypass variant /%50SEMHUB/; expanded sectors 1
September 2026 GTIG / Mandiant Publishes analysis; web shells found on dozens of systems globally 1

Attack Anatomy

Initial access — CVE-2026-35273 via the WAF-bypass path

UNC6240 sent serialized Java objects in POST requests to the PSEMHUB hub servlet, exploiting the deserialization flaw for unauthenticated RCE (T1190). Where defenders blocked /PSEMHUB at a WAF, the actor requested the percent-encoded /%50SEMHUB/ — the firewall saw no literal match, WebLogic decoded the path and served the vulnerable servlet.13

Execution and web shells

The actor either executed commands filelessly (output returned directly in the HTTP response, shells spawned by the WebLogic Java process — T1059.003/T1059.004) or dropped JSP web shells into the PSEMHUB.war directory: x.jsp, which accepts hex-encoded commands via a POST parameter and reconstructs /bin/sh from an ASCII array to dodge string signatures (T1505.003, T1027), and u.jsp/u2.jsp for chunked Base64 file upload.14

Backdoor, tunnels and remote management

UNC6240 deployed SIDEEYE — Ple64.exe, a 5.2 MB signed installer trojanising the Light Alloy media player, VMProtect-packed, decrypting a C++ backdoor in memory with raw-TCP C2 (T1219) — plus Neo-reGeorg (tunnel.jsp/tunnel.jspx) for SOCKS5 pivoting (T1090) and MeshCentral agents for persistent management.1

Discovery, credential access and the extortion endgame

Roughly a quarter of commands ran as root/SYSTEM; the actor ran host and network discovery (T1082) and targeted credentials readable by the PeopleSoft service account — database connection strings, Integration Broker and cloud credentials (T1552.001) — consistent with UNC6240's data-theft-and-extortion pattern, with exfiltration over alternate protocols (T1048).1

Loading diagram...

Threat Actor Profile

  • Cluster: UNC6240, which GTIG links to ShinyHunters — a financially motivated actor whose signature is stealing data and extorting victims with the threat of publication on a leak site.1
  • Attribution confidence: The UNC6240 activity is GTIG's own tracking; the ShinyHunters linkage is an assessment. "ShinyHunters" is a loose, overlapping label, so treat "ShinyHunters did this" as a well-supported attribution rather than a precise, singular identification.1
  • Objective: Data-theft extortion at scale. The tooling — web shells, a stealthy signed backdoor, tunnels, remote-management agents, credential harvesting from config files — is built to reach and exfiltrate high-value data (HR, payroll, student records) held in PeopleSoft deployments.1
  • Tradecraft signature: Speed to weaponise a fresh critical bug (zero-day from May 27, weeks before the June 10 alert), and a willingness to iterate the exploit — the one-character WAF bypass — to defeat the stopgap mitigations defenders reach for when they cannot patch immediately.1

MITRE ATT&CK techniques (verified on attack.mitre.org):

ID Technique
T1190 Exploit Public-Facing Application
T1505.003 Server Software Component: Web Shell
T1059.003 Command and Scripting Interpreter: Windows Command Shell
T1059.004 Command and Scripting Interpreter: Unix Shell
T1027 Obfuscated Files or Information
T1082 System Information Discovery
T1552.001 Unsecured Credentials: Credentials In Files
T1090 Proxy
T1219 Remote Access Tools
T1048 Exfiltration Over Alternative Protocol

Technical Indicators

cve: "CVE-2026-35273 (PeopleSoft PeopleTools 8.61/8.62, Updates Environment Management / PSEMHUB; unauth RCE; CVSS 9.8)"
waf_bypass_uri: "/%50SEMHUB/   # %50 = 'P'; also assume any percent-encoded/mixed-case /PSEMHUB/ variant"
web_shells:
  - "x.jsp  (hex-encoded command exec via POST param; sha256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494)"
  - "u.jsp / u2.jsp (chunked base64 upload; sha256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7)"
  - "tunnel.jsp  (Neo-reGeorg SOCKS5; sha256 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86)"
  - "tunnel.jspx (Neo-reGeorg SOCKS5; sha256 ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07)"
backdoor:
  - "Ple64.exe  SIDEEYE (5.2MB, trojanized Light Alloy installer, VMProtect3, Sectigo EV cert 'Tobias Weihmann Software Development OU' - revocation requested; sha256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3)"
c2_and_infra:
  - "162.219.30[.]165  (SIDEEYE C2; TCP/3333 control, TCP/3334 data, raw TCP)"
  - "5.199.162[.]157   (attack controller / scanner / HTTP callback receiver)"
  - "104.219.234[.]138 (exfil staging / remote management)"
  - "winmanage-me[.]network (MeshCentral staging)"
  - "meshagent masquerade domains: azurenetfiles[.]net, microsoft-entra[.]net, enroll.azuredevice[.]cloud"
host_paths:
  - "<PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/{x.jsp,u.jsp,u2.jsp,Ple64.exe,tunnel.jsp,tunnel.jspx}"

The formal response so far is vendor-and-researcher, not governmental: Oracle issued a Security Alert for CVE-2026-35273 on June 10, 2026, and GTIG/Mandiant published the campaign analysis with full indicators.13 No public indictment or sanctions action specific to this campaign had been issued as of this writing, which is unsurprising for an in-progress mass-exploitation campaign by a financially motivated extortion cluster. The practical "response" is remediation guidance: patch, disable or remove the Environment Management Hub, hunt for the listed artifacts, rotate any credentials the PeopleSoft service account could read, and prepare for extortion contact if data theft is found.1

Impact Assessment

  • Confirmed (per GTIG): UNC6240 mass-exploited CVE-2026-35273 in a September 2026 campaign, using a one-character URL-encoding trick (/%50SEMHUB/) to bypass WAF rules, and placed web shells on dozens of systems across seven sectors, following zero-day exploitation that began May 27, 2026.1
  • Confirmed: Post-exploitation included the SIDEEYE backdoor, Neo-reGeorg tunnels and MeshCentral agents, with ~25% of commands run as root/SYSTEM and credential harvesting from PeopleSoft config files, consistent with data-theft extortion.1
  • Verified (NVD): CVE-2026-35273 is a CVSS 9.8 unauthenticated RCE in PeopleTools 8.61/8.62.3
  • Assessed: The ShinyHunters attribution of UNC6240 is GTIG's assessment; "ShinyHunters" is a loose label.1
  • Unknown: The full count of breached organisations and confirmed data-theft victims; which victims will face extortion; and the total dwell time on long-compromised hosts.1

Lessons and Defensive Recommendations

For anyone running internet-facing PeopleSoft:

  • Patch CVE-2026-35273 — a WAF rule is not a substitute, and this campaign exists specifically to prove that. If you blocked /PSEMHUB at a WAF, that rule was bypassed by /%50SEMHUB/; enforce blocking on the normalized, post-decode path, and understand it is a stopgap until Oracle's fix is applied.
  • Disable or remove the Environment Management Hub. GTIG notes EMHub can be disabled on multi-server deployments and PSEMHUB removed on single-server ones without breaking standard PIA sessions — removing the reachable attack surface entirely is stronger than filtering requests to it.

For SOC and IR teams:

  • Hunt the specific artifacts now. Search PSEMHUB.war/ and PORTAL.war/ for unexpected .jsp/.jspx/.exe files (the listed hashes and paths), review PIA/WebLogic access logs for /PSEMHUB/ and percent-encoded variants and for POST requests to /hub from external IPs, and alert on shell processes spawned by the WebLogic Java process — especially invoking base64 -d, curl, /dev/tcp or tasklist.
  • Assume credential exposure. Rotate database connection strings in psappsrv.cfg, Integration Broker credentials, and any cloud credentials reachable from the web tier; a root/SYSTEM foothold on the PeopleSoft host means the service account's secrets should be treated as compromised.

The transferable lesson:

  • Path-based WAF rules that match before URL decoding are defeated by encoding. Any control that inspects a request path as a literal string must normalise (decode, fold case, canonicalise) before matching, or an attacker will find the encoding that slips past it. This bug is PeopleSoft's; the pattern — "the filter and the application disagree about what the path is" — is everywhere.

Sources

Footnotes

  1. ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft — Google Threat Intelligence Group (Mandiant), September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30

  2. ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks — BleepingComputer, September 2026 ↩

  3. CVE-2026-35273 — National Vulnerability Database (NIST) ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  4. Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells — The Hacker News, September 2026 ↩

Topics: #shinyhunters#unc6240#cve-2026-35273#peoplesoft#waf-bypass#web-shell#sideeye#mandiant#url-encoding
Original Incident Report →

Related Research

Dutch police arrested a 24-year-old Amsterdam man on Sept 15, 2026 in the ShinyHunters investigation; a Rotterdam court remanded him 90 days, and the FBI called him an 'alleged leader.' A separate inquiry into two planned murders abroad is, police say, not part of the ShinyHunters case.

Data BreachExtortion & Blackmail

ShinyHunters claims it breached the FBI, defaced FBIjobs.gov, and stole ~2TB on almost all agents via a PeopleSoft zero-day. The defacement is observed and 404 Media matched a data sample to public records — but the FBI says the breach point is undetermined and most is unverified.

Data BreachExtortion & Blackmail

Mandiant documents an intrusion where an AI coding assistant recommended attacker-poisoned software; a developer accepted it, and the attacker used the live session to steal GitHub OAuth tokens and spread the Shai-Hulud worm across ~100 internal repos. How the session was taken over is undisclosed.

Supply Chain AttackAI & Machine LearningMalware