{"id":13562,"date":"2026-06-12T10:03:40","date_gmt":"2026-06-12T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/06\/12\/oracle-peoplesoft-0-day-rce-vulnerability-exploited-in-attacks-by-shinyhunters\/"},"modified":"2026-06-12T10:03:40","modified_gmt":"2026-06-12T10:03:40","slug":"oracle-peoplesoft-0-day-rce-vulnerability-exploited-in-attacks-by-shinyhunters","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/06\/12\/oracle-peoplesoft-0-day-rce-vulnerability-exploited-in-attacks-by-shinyhunters\/","title":{"rendered":"Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters"},"content":{"rendered":"<p>    Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Mandiant and Google Threat Intelligence Group (GTIG) have issued a critical warning after identifying an active compromise-and-extortion campaign targeting Oracle PeopleSoft infrastructure, attributed to the notorious threat actor UNC6240, also known as ShinyHunters.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cybersecuritynews.com\/oracle-security-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">The campaign exploited CVE-2026-35273<\/a>, a critical unauthenticated remote code execution (RCE) vulnerability with a CVSS score of 9.8, as a zero-day before Oracle published its advisory on June 10, 2026.<\/p>\n<p class=\"wp-block-paragraph\">The malicious activity was observed between May 27 and June 9, 2026, with attacks targeting the Environment Management Hub (PSEMHUB) component of Oracle PeopleSoft PeopleTools versions 8.61 and 8.62.<\/p>\n<p class=\"wp-block-paragraph\">Google Threat Intelligence Group notified over 100 global organizations whose IP addresses correlated with potentially vulnerable endpoints, with 68% of victims concentrated in the higher education sector, including universities and colleges worldwide.<\/p>\n<p class=\"wp-block-paragraph\">The University of Nottingham confirmed unauthorized activity on its systems, with reports indicating approximately 40 gigabytes of stolen data, including student records, financial aid data, health records, and immigration details.<\/p>\n<h2 id=\"h-oracle-peoplesoft-0-day-rce-vulnerability\" class=\"wp-block-heading\"><strong>Oracle PeopleSoft 0-Day RCE Vulnerability<\/strong><\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-targets-education-sector-oracle-exploit\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GTIG triaged five sequential attacker-controlled staging IP addresses<\/a>, 142.11.200.186 through 142.11.200.190, each hosting a Python SimpleHTTP server on port 8888.<\/p>\n<p class=\"wp-block-paragraph\">These exposed directory contents included attacker command histories, staging materials, and pre-configured MeshCentral remote management agents.<\/p>\n<p class=\"wp-block-paragraph\">The Windows agent binaries were disguised as legitimate Microsoft Azure services (<code>meshagent32-azure-ops.exe<\/code>, <code>meshagent64-azure-ops.exe<\/code>, <code>meshagent64-v2.exe<\/code>) and hardcoded to establish C2 communications with <code>wss:\/\/azurenetfiles.net:443\/agent.ashx<\/code> \u2014 a domain crafted to mimic legitimate Microsoft Azure NetApp Files endpoints.<\/p>\n<p class=\"wp-block-paragraph\">The attackers established their staging environment on May 27, 2026, at 22:14 UTC by installing MeshCentral v1.1.59, followed at 22:25 UTC by the <code>acme-client<\/code> npm package to automate Let\u2019s Encrypt SSL certificate provisioning for the masquerading domain.<\/p>\n<p class=\"wp-block-paragraph\">Using the <code>meshctrl.js<\/code> CLI, they executed targeted reconnaissance commands on compromised hosts, mapping Oracle PeopleSoft configurations by inspecting <code>psappsrv.cfg<\/code>, auditing active NFS mounts, and reading WebLogic <code>config.xml<\/code> files to map internal application servers.<\/p>\n<p class=\"wp-block-paragraph\">Lateral movement was automated via a custom propagation script <code>[victim_abbreviation]_fanout.sh<\/code> deployed to <code>\/tmp<\/code>, which performed SSH credential spraying against internal hosts parsed from <code>\/etc\/hosts<\/code>.<\/p>\n<p class=\"wp-block-paragraph\">Upon successful authentication, the script dropped a defacement and extortion marker file <code>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT<\/code> into WebLogic and Process Scheduler directories.<\/p>\n<p class=\"wp-block-paragraph\">Exfiltrated data was compressed using <code>zstd<\/code> before the attackers established an outbound SSH connection to 176.120.22.24, the IP hosting the public mirror of the ShinyHunters Data Leak Site (DLS). Stolen data archives were published on the DLS on June 9, 2026.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" height=\"1700\" width=\"1700\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/storage.googleapis.com\/gweb-cloudblog-publish\/images\/peoplesoft-shinyhunters.max-1700x1700.png?resize=1700%2C1700&#038;ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ShinuHunters Claim (Source: Google)<\/figcaption><\/figure>\n<h2 id=\"h-key-iocs\" class=\"wp-block-heading\">Key IOCs<\/h2>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Indicator<\/th>\n<th>Type<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>142.11.200.186\u2013.190<\/td>\n<td>IP Addresses<\/td>\n<td>Attacker staging servers<\/td>\n<\/tr>\n<tr>\n<td><code>azurenetfiles.net<\/code><\/td>\n<td>Domain<\/td>\n<td>C2 masquerading domain<\/td>\n<\/tr>\n<tr>\n<td><code>meshagent64-azure-ops.exe<\/code><\/td>\n<td>SHA-256: <code>f02a924c...<\/code>\n<\/td>\n<td>Pre-configured Windows agent<\/td>\n<\/tr>\n<tr>\n<td><code>meshagent32-azure-ops.exe<\/code><\/td>\n<td>SHA-256: <code>c7e93327...<\/code>\n<\/td>\n<td>Pre-configured Windows agent<\/td>\n<\/tr>\n<tr>\n<td><code>.bash_history<\/code><\/td>\n<td>SHA-256: <code>2ab684d9...<\/code>\n<\/td>\n<td>Attacker command history<\/td>\n<\/tr>\n<tr>\n<td><code>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT<\/code><\/td>\n<td>Filename<\/td>\n<td>Extortion marker<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Organizations are strongly advised to apply Oracle\u2019s emergency advisory for CVE-2026-35273 and remain on actively supported PeopleSoft versions with all Critical Patch Updates applied without delay.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/oracle-peoplesoft-0-day-rce-vulnerability\/\">Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/oracle-peoplesoft-0-day-rce-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters Mandiant and Google Threat Intelligence Group (GTIG) have issued a critical warning after identifying an active compromise-and-extortion campaign targeting Oracle PeopleSoft infrastructure, attributed to the notorious threat actor UNC6240, also known as ShinyHunters. The campaign exploited CVE-2026-35273, a critical unauthenticated remote code execution (RCE) vulnerability [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-13562","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13562"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13562"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13562\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13562"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13562"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}