INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Exploits Oracle PeopleSoft Flaw to Deploy Web Shells

| 2026-09-28 13:55 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
On September 28, 2026, ShinyHunters bypassed web application firewall protections to exploit a critical PeopleSoft flaw (CVE-2026-35273) and deploy web shells. The APT Group behind the attacks is ShinyHunters, also tracked as UNC6240 by Google. Confirmed victims include over 100 Oracle PeopleSoft customers, including universities such as the University of Nottingham in the UK, insurance regulators group NAIC, and Nissan. The attack works by using a modified exploit to bypass WAF rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint. As of now, ShinyHunters continues to deploy web shells on dozens of systems after successfully exploiting the vulnerability.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-61882, CVE-2026-35273 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

wi•••••.network
fb•••••.gov
ap•••••.gov
ba1441••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
419c57••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3ba215••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
2bee94••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
104.219.•••.•••
162.219.•••.•••
5.199.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHuntersScattered SpiderScattered Spider UmbreonUmbreonNeo-reGeorgNeo-reGeorg CVE-2025-61882CVE-2025-61882 CVE-2026-35273CVE-2026-35273
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation financefinance transportationtransportation
Incident Timeline
‎August 2020
ShinyHunters reused the Umbreon artwork from their 2020 HackForums defacement on a leak site associated with Clop.
threat_actor ShinyHunters
tactic Defacement
malware Umbreon
organisation Cybersecurity
organisation VXDB
organisation HackForums
‎2025/09/19
ShinyHunters allegedly used spear-phishing tactics to target individuals, including a threat actor from the Russian Federation identified as cl0p.
organisation EBS
target_region Russian Federation
organisation cl0p
threat_actor ShinyHunters
‎October 2025
Threat actors, identified as Clop, exploited multiple vulnerabilities in Oracle E-Business Suite servers to steal data from organizations in extortion campaigns.
tactic Extortion
vulnerability CVE-2025-61882
‎December 2025
Threat actors known as ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft, which was exploited to carry out a ransomware attack and data breach against the University of Phoenix.
tactic Ransomware
tactic Data Breach
organisation the University of Phoenix
general_metric 3.5 people
‎May 2026
ShinyHunters published a statement claiming the attack on Oracle PeopleSoft was retaliation for an FBI report detailing their activities in May 2026.
threat_actor ShinyHunters
tactic Data Leak
attribution FBI
attribution Retaliation
‎2026/09/14
ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft, potentially exposing victim organizations to additional risks due to their involvement with rival ransomware gang Clop.
threat_actor ShinyHunters
tactic Ransomware
‎2026/09/15
ShinyHunters launched a spear-phishing campaign targeting Oracle PeopleSoft users.
threat_actor ShinyHunters
tactic Data Leak
organisation Tor
‎18 September
ShinyHunters defaced Clop's dark web data leak site with a message claiming they had taken control of the site.
tactic Data Leak
‎Sept. 19
Threat actors known as ShinyHunters sent a spear-phishing message to Clop on September 19, demanding an eight-figure payment in Bitcoin and providing contact information via Onionmail.
threat_actor ShinyHunters
organisation Onionmail
‎Sept. 20
Threat actors, identified as ShinyHunters, used spear-phishing tactics to target Oracle PeopleSoft on September 20.
organisation EBS
‎2026/09/21
ShinyHunters' spear-phishing campaign against Oracle PeopleSoft did not result in a ransom payment as of the date mentioned on their defacement message.
threat_actor ShinyHunters
attribution FBI
tactic Defacement
organisation Ransomware
‎2026/09/28
ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution without authentication, targeting over 100 customers.
organisation CVE-2026-35273
organisation PeopleSoft
organisation Oracle
organisation Google
threat_actor ShinyHunters
organisation Oracle PeopleSoft
organisation Cyber Security News
victims 100 PeopleSoft customers
data_breach 2 TB
data_breach 3 TB
organisation Oracle E-Business Suite
victims 40,000 corporate customers
organisation Feud Between Hacking Gangs
organisation Canvas Learning Management System
organisation IP
organisation AttackIQ
organisation Tor
organisation Grav CMS
organisation BleepingComputer
organisation DataBreaches
organisation the University of Nottingham
organisation Nissan
infrastructure Windows
organisation JSP
organisation SideEye
organisation ERP
organisation CVE-2025-61882
organisation MeshCentral
organisation ShinyHunter
data_breach 5,000 purported FBI employee records
organisation POST
organisation WebLogic
organisation US Department of Justice
organisation 0APT
organisation KryBit
organisation NFL
organisation CHANEL
organisation ASCII
organisation KnowBe4
threat_actor Scattered Spider
organisation Lapsus$
organisation Fortra GoAnywwhere
organisation Vectra AI Launches Ascent
organisation Help Address New Era
organisation Keeper Security
organisation Guccione
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
100
Peoplesoft Customers
Metrics
data_breach
5,000
Purported Fbi Employee Records
Metrics
data_breach
2
Tb
Metrics
data_breach
3
Tb
Metrics
victims
40,000
Corporate Customers