Ethical Hacking News
ShinyHunters, a notorious threat actor, has renewed its mass exploitation campaign targeting Oracle PeopleSoft, compromising hundreds of systems worldwide. This latest escalation marks a significant threat to organizations relying on PeopleSoft, as ShinyHunters has demonstrated a sophisticated approach to bypassing security measures and compromising systems. To mitigate this threat, organizations should prioritize patching, reducing exposure, and implementing additional security measures to protect themselves against evolving threats.
ShinyHunters has renewed its mass exploitation campaign targeting Oracle PeopleSoft, a popular enterprise resource planning software. The threat actor has adapted its exploit to bypass web application firewall (WAF) rules, allowing it to reach vulnerable systems. ShinyHunters has employed sophisticated tactics, tactics, and procedures (TTPs) to establish persistent access, stage follow-on payloads, and maintain control over compromised systems. The attack campaign involves the deployment of web shells, Neo-reGeorg tunneling toolkit, MeshCentral agents, and a Trojanized installer, Ple64.exe, to deliver a sophisticated backdoor. Organizations relying on PeopleSoft should prioritize patching and reducing exposure, and implement additional security measures to mitigate the threat.
ShinyHunters, a notorious threat actor, has renewed its mass exploitation campaign targeting Oracle PeopleSoft, a popular enterprise resource planning software. This latest escalation marks a significant threat to organizations relying on PeopleSoft, as ShinyHunters has demonstrated a sophisticated approach to bypassing security measures and compromising systems.
According to Mandiant, a leading threat intelligence firm, ShinyHunters has adapted its exploit to bypass web application firewall (WAF) rules, allowing it to reach the vulnerable Environment Management Hub (PSEMHUB) endpoint. This vulnerability, CVE-2026-35273, was initially identified in June 2026, and Oracle had released an out-of-band security alert to address the issue. However, ShinyHunters has modified its exploit to evade WAF detection, rendering traditional security measures ineffective.
The threat actor's tactics, tactics, and procedures (TTPs) have become increasingly sophisticated, as evidenced by the deployment of web shells, the use of Neo-reGeorg tunneling toolkit, and the exploitation of MeshCentral agents. These TTPs enable ShinyHunters to establish persistent access, stage follow-on payloads, and maintain control over compromised systems.
The attack campaign began with the deployment of web shells, which allowed ShinyHunters to execute malicious code on vulnerable systems. The threat actor then deployed Neo-reGeorg tunneling toolkit, which enables the routing of SOCKS5 proxy traffic through ordinary HTTP and HTTPS connections. This allows ShinyHunters to maintain control over compromised systems and establish a backdoor for future attacks.
In addition, ShinyHunters has deployed MeshCentral agents, which enable the threat actor to establish persistent access to compromised systems. MeshCentral is a legitimate remote management platform, but ShinyHunters has exploited its functionality to maintain control over compromised systems.
The attack campaign has also involved the deployment of a Trojanized installer, Ple64.exe, which delivers a backdoor called SIDEEYE. SIDEEYE is a sophisticated backdoor that enables ShinyHunters to steal credentials, maintain control over compromised systems, and establish a persistent presence.
To mitigate this threat, organizations relying on PeopleSoft should prioritize patching and reducing exposure. They should also implement additional security measures, such as blocking external access to PSEMHUB, disabling EMHub, and searching for suspicious files and activities.
The threat landscape has become increasingly complex, and organizations must remain vigilant to protect themselves against evolving threats. As ShinyHunters continues to adapt and evolve, it is essential for organizations to stay informed and take proactive measures to defend against these threats.
Related Information:
https://www.ethicalhackingnews.com/articles/ShinyHunters-Escalated-Attack-Campaign-A-Threat-to-PeopleSoft-Users-ehn.shtml
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft/
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
https://tech-insider.org/shinyhunters-oracle-peoplesoft-breach-2026/
https://nvd.nist.gov/vuln/detail/CVE-2026-35273
https://www.cvedetails.com/cve/CVE-2026-35273/
https://attack.mitre.org/software/S1189/
https://boteraser.com/malware/neo-regeorg/
https://www.huntress.com/threat-library/malware/spyeye-malware
https://en.wikipedia.org/wiki/SpyEye
Published: Fri Sep 25 19:16:05 2026 by llama3.2 3B Q4_K_M