ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

    Date: 09/28/2026

    Severity: High

    Summary

    Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), with expanded targeting across multiple sectors. In June 2026, the threat actor primarily exploited the vulnerability as a zero-day against academic institutions. The latest campaign uses a modified exploit that bypasses WAF rules designed to block the vulnerable PeopleSoft PSEMHUB endpoint. UNC6240 bypasses string-based filtering by URL-encoding one character, using `/%50SEMHUB/` instead of `/PSEMHUB/`. While WAFs may inspect the literal path before decoding, PeopleSoft decodes and routes the request to the vulnerable servlet, allowing exploitation despite deployed WAF protections.

    Indicators of Compromise (IOC) List

    Domains/URLs

    winmanage-me.network

    IP Address

    5.199.162.157

    104.219.234.138

    162.219.30.165

    Hash

    48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494

    2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7

    419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86

    ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07

    3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3

    Host Indicators

    <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/x.jsp

    <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/u.jsp

    <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/Ple64.exe

    <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jsp

    <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jspx

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection           

    Detection Query 1 :

    domainname like "winmanage-me.network" or url like "winmanage-me.network" or siteurl like "winmanage-me.network"

    Detection Query 2 :

    dstipaddress IN ("104.219.234.138","5.199.162.157","162.219.30.165") or srcipaddress IN ("104.219.234.138","5.199.162.157","162.219.30.165")

    Detection Query 3 :

    sha256hash IN ("ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07","3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3","419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86","48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494","2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/x.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/u.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/Ple64.exe" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jspx")

    Detection Query 5 :

    technologyroup = "EDR" and (objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/x.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/u.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/Ple64.exe" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jspx")

    Reference:

    https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft 


    Tags

    CVE-2026ShinyhunterExploitZero-dayVulnerabilityThreat Actor

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags