Date: 09/28/2026
Severity: High
Summary
Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), with expanded targeting across multiple sectors. In June 2026, the threat actor primarily exploited the vulnerability as a zero-day against academic institutions. The latest campaign uses a modified exploit that bypasses WAF rules designed to block the vulnerable PeopleSoft PSEMHUB endpoint. UNC6240 bypasses string-based filtering by URL-encoding one character, using `/%50SEMHUB/` instead of `/PSEMHUB/`. While WAFs may inspect the literal path before decoding, PeopleSoft decodes and routes the request to the vulnerable servlet, allowing exploitation despite deployed WAF protections.
Indicators of Compromise (IOC) List
Domains/URLs | winmanage-me.network |
IP Address | 5.199.162.157 104.219.234.138 162.219.30.165 |
Hash | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494
2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7
419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86
ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07
3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3
|
Host Indicators | <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/x.jsp <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/u.jsp <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/Ple64.exe <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jsp <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jspx |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "winmanage-me.network" or url like "winmanage-me.network" or siteurl like "winmanage-me.network" |
Detection Query 2 : | dstipaddress IN ("104.219.234.138","5.199.162.157","162.219.30.165") or srcipaddress IN ("104.219.234.138","5.199.162.157","162.219.30.165") |
Detection Query 3 : | sha256hash IN ("ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07","3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3","419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86","48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494","2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4663" and (objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/x.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/u.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/Ple64.exe" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jspx") |
Detection Query 5 : | technologyroup = "EDR" and (objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/x.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/u.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/Ple64.exe" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jsp" or objectname like "%/webserv/%/applications/peoplesoft/PSEMHUB.war/tunnel.jspx") |
Reference:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft