GTIG says UNC6240 (ShinyHunters) is again exploiting PeopleSoft CVE-2026-35273, using /%50SEMHUB/ to slip past WAF rules. Patch, then hunt.
Google Threat Intelligence Group (GTIG, Mandiant) reported on 26 September 2026 that UNC6240, which it tracks as ShinyHunters, is again exploiting CVE-2026-35273 in Oracle PeopleSoft PeopleTools. GTIG describes web shells deployed on dozens of systems globally. The campaign runs months after Oracle's out-of-band fix and gets past perimeter rules with a one-character trick: percent-encoding the letter P in the request path. GTIG says the actor targeted organisations that put WAF rules in place but did not patch.
What is affected
CVE-2026-35273 is a flaw in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Per the CVE record, an unauthenticated attacker with HTTP access can take over the product. The record lists PeopleTools 8.61 and 8.62 as affected and carries a CVSS v3.1 base score of 9.8 (Critical), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, supplied by Oracle as the CVE Numbering Authority. CISA's ADP data in the same record classifies it as CWE-306, missing authentication for a critical function. GTIG identifies the vulnerable code as the Environment Management Hub (PSEMHUB) servlet.
The timeline, as reported by GTIG and the CVE record:
- 27 May to 9 June 2026: zero-day exploitation, predominantly against higher education (GTIG).
- 10 June 2026: Oracle issues an out-of-band Security Alert (GTIG).
- 12 June 2026: CISA adds the flaw to its Known Exploited Vulnerabilities catalog. CISA's SSVC data in the CVE record rates exploitation as active, the flaw as automatable, and technical impact as total.
- 26 September 2026: GTIG publishes its report on the renewed campaign, covering intrusions in September.
The renewed wave is broader than the original. GTIG lists higher education, technology, IT services, healthcare, agriculture, transportation and government among the targets.
The bypass
Defenders who blocked /PSEMHUB/ at a WAF or reverse proxy were not protected. The actor requests /%50SEMHUB/ instead, where %50 is the URL encoding of P. GTIG explains why it works: many WAF and reverse-proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet. GTIG tells defenders to assume the actor may use any percent-encoded, mixed-case or otherwise non-normalised variant of /PSEMHUB/, and to enforce blocking on the normalised path.
Attack chain
GTIG describes a consistent sequence. First comes verification: five to 15 POST requests to /%50SEMHUB/hub carrying a serialized Java object. Unpatched servers respond with the host operating system without writing files or disrupting the service, so the check is quiet.
Exploitation then follows one of two routes:
- Web shell. Further
POSTrequests to the same endpoint drop JSP files, includingx.jsp,u.jspand sequentially numbered files, into thePSEMHUB.wardirectory. GTIG notes the repetition likely ensures every node behind a load balancer gets a copy.x.jspis a cross-platform command shell that accepts hex-encoded commands viaPOST(c) with an optional timeout (t).u.jspdecodes Base64 file chunks and writes or appends them to a target path in 150 KB increments. - Fileless. Command output returns directly in the HTTP response with no file written to disk. The only host trace is shell processes (
cmd.exeor/bin/sh) spawned by the WebLogic Java process, so detections built on JSP file creation will miss it.
Follow-on tooling includes Ple64.exe, a trojanized installer that masquerades as a signed installer for the Light Alloy media player. GTIG says it runs a three-stage chain that loads the SIDEEYE C++ backdoor in memory. SIDEEYE supports browser and desktop credential theft, process and file management, and an interactive reverse shell and reverse proxy, and it talks to its command server over raw TCP. The actor also deploys the open-source Neo-reGeorg toolkit (tunnel.jsp or tunnel.jspx), which carries SOCKS5 proxy traffic over ordinary HTTP and HTTPS to the web tier, and on Linux uses the legitimate remote management tool MeshAgent for persistence. A quarter of the actor's commands ran as root or NT Authority\SYSTEM.
Indicators from GTIG (defanged)
| Indicator | Role |
|---|---|
5[.]199[.]162[.]157 | Attack controller, scanner, HTTP callback receiver |
104[.]219[.]234[.]138 | Exfiltration staging, remote management |
162[.]219[.]30[.]165 (TCP/3333 control, TCP/3334 data) | SIDEEYE C2 |
winmanage-me[.]network | Resolves to the staging host; MeshCentral infrastructure |
x.jsp SHA-256 | 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494 |
u.jsp SHA-256 | 2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7 |
Ple64.exe SHA-256 | 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3 |
Web shells appear under <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/.
What defenders should do
- Patch. Apply the patch in Oracle's Security Alert for CVE-2026-35273. WAF rules were the stopgap this actor walked around.
- Reduce exposure. GTIG advises disabling the EMHub service in multi-server configurations and removing PSEMHUB entirely in single-server ones. Keep it off the internet either way.
- Hunt. Search PIA WebLogic access logs for
/PSEMHUB/and percent-encoded variants, especiallyPOSTrequests to/hub. Inspect thePSEMHUB.wardirectory, includingenvmetadata/transactions/, for unexpected.jsp,.jspxand.exefiles, and check for unexpected MeshCentral agents. Check every WebLogic node behind a load balancer, not only the first one you find. Monitor outbound traffic to the indicators above. - Watch for fileless activity. Alert on shells (
cmd.exe,/bin/sh,bash) spawned by the WebLogic Java process, particularly those invokingbase64 -d,curl,/dev/tcp,tasklistorstart /b. Review PeopleSoft and database hosts for large.tar,.tar.gzand.zstarchives in temporary or web-accessible directories. - Rotate credentials. Replace credentials readable by the PeopleSoft application service account: database connection strings in
psappsrv.cfg, Integration Broker credentials and any cloud credentials reachable from the web tier. - Plan for extortion. GTIG notes UNC6240's well-established pattern of stealing data and threatening to leak it unless the victim pays, so prepare legal and communications teams.
The lesson
A WAF rule keyed to a literal path is a virtual patch, and a virtual patch is only as good as its normalisation. The same lesson applies in the WebLogic proxy-bypass case: when the fix exists, the front-end filter is a stopgap, not the remedy.