ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells.

The campaign shows how a small change in an attack request can reopen exposure that administrators believed had been contained. The activity targets CVE-2026-35273, a critical PeopleSoft flaw previously used as a zero-day against universities.

The latest wave has widened to technology, IT services, healthcare, agriculture, transport, and government organizations, putting systems that hold HR, payroll, and operational data at risk.

Analysts from Google Cloud identified the renewed mass exploitation and linked it to UNC6240, also known as ShinyHunters.

Google Cloud said in a report shared with Cyber Security News (CSN) that attackers placed web shells on dozens of systems worldwide, then used them for direct hands-on activity.

The development is a warning that perimeter controls cannot replace software updates. Earlier reporting on the PeopleSoft zero-day RCE attacks documented how the same flaw gave unauthenticated attackers a route into exposed enterprise applications before a patch was released.

ShinyHunters Bypasses WAF Protections

The attackers changed the vulnerable request path by encoding one character rather than sending the normal endpoint name. Some WAFs and reverse proxies compare the request as written.

The PeopleSoft application server, however, decodes it before routing it to the affected service. That mismatch lets the request reach the target despite a literal blocking rule.

Before moving further, the group typically sent several POST requests carrying a serialized Java object to check whether a server could be exploited.

A vulnerable system returned operating-system details without necessarily writing a file. A failed-looking event may still be evidence of reconnaissance, so defenders should review logs across all nodes, particularly where load balancing is used.

PSEMHUB WAF bypass (Source - Google Cloud)
PSEMHUB WAF bypass (Source – Google Cloud)

Once access was confirmed, the attackers either created JSP-based web shells or executed commands directly in memory. The first method creates a durable route back into the server; the second can leave no new file for file-based security tools to detect.

This gap reinforces why organizations should examine application and process activity together. The campaign also reflects a broader extortion risk.

Previous coverage of the Nissan PeopleSoft breach confirmation showed the potential consequences when attackers reach systems containing employee information.

In this campaign, some observed commands ran with root or SYSTEM-level permissions, while others still had access to PeopleSoft configuration and database connection information.

Web Shells Lead to Backdoors

On compromised Windows servers, the operators used a second web shell to transfer a trojanized installer in small chunks, avoiding request-size limits.

The resulting SIDEEYE backdoor was loaded in memory and could steal browser and desktop credentials, manage processes and files, and provide an interactive reverse shell or proxy connection.

The group also used tunneling software to route internal traffic through ordinary web connections, enabling discovery and movement beyond the initial PeopleSoft host.

On Linux systems, it deployed remote-management tooling for persistence. This pattern should prompt teams to investigate whether a PeopleSoft compromise has spread to connected databases or other internal servers.

A foothold there can expose data even after the original server is secured. Organizations should apply the Oracle security patch for CVE-2026-35273 and keep supported PeopleTools versions.

Administrators should disable the Environment Management Hub when it is not needed, or remove the affected application where appropriate. The Oracle emergency security update explains why rapid patching matters for internet-facing PeopleSoft deployments.

Security teams should search access logs for the encoded route and related external POST activity, then inspect PeopleSoft web application directories for unapproved JSP, JSPX, or executable files.

They should also alert on command shells spawned by the WebLogic Java process. If a shell is found, they should preserve evidence, rotate credentials available to the application account, and watch for unusually large outbound transfers.

Affected organizations should also prepare for possible data-theft extortion and review database audit logs for bulk exports of HR, payroll, or student records. Treating a detected web shell as a full system compromise, rather than a simple website issue, is essential to containing this campaign.

Indicators of compromise (IoCs):-

Type Indicator Description
IPv4 5.199.162.157 Attack controller, scanner, and HTTP callback receiver
IPv4 104.219.234.138 Exfiltration staging and remote-management host
IPv4 162.219.30.165 Command-and-control server for the SIDEEYE backdoor
Domain winmanage-me.network Resolves to staging host and associated MeshCentral infrastructure
URI pattern /%50SEMHUB/ Percent-encoded WAF-bypass path
File path <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/x.jsp Primary command-execution web shell path
File path <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/u.jsp File-transfer and execution web shell path
File path <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/Ple64.exe SIDEEYE backdoor delivery path
File path <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jsp Neo-reGeorg tunnel path
File path <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/tunnel.jspx Neo-reGeorg JSPX tunnel path
SHA-256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 x.jsp primary execution web shell
SHA-256 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 u.jsp execution stager servlet
SHA-256 419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86 tunnel.jsp Neo-reGeorg JSP tunnel
SHA-256 ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07 tunnel.jspx Neo-reGeorg JSPX tunnel
SHA-256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 Ple64.exe trojanized installer delivering SIDEEYE

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells appeared first on Cyber Security News.