Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

ShinyHunters’ Fresh Oracle PeopleSoft Campaign Sparks Widespread Concern

Google’s Threat Intelligence Group and Mandiant have sounded the alarm on a new wave of attacks by the notorious extortion group ShinyHunters, targeting Oracle PeopleSoft customers worldwide. This campaign marks a significant escalation in the group’s activities, with over 100 organizations affected so far.

PeopleSoft is an integrated enterprise resource planning (ERP) software suite used by numerous large enterprises for managing core business functions such as finance, HR, payroll, and supply chain. The platform’s widespread adoption makes it a prime target for attackers seeking to exploit vulnerabilities and gain access to sensitive data. In June, ShinyHunters launched a mass-exploitation campaign using a zero-day vulnerability in PeopleSoft (CVE-2026-35273), which allowed them to gain remote code execution without authentication.

The new wave of attacks by ShinyHunters has seen the group modifying its exploit to bypass web application firewall (WAF) rules, allowing it to reach the vulnerable Environment Management Hub (PSEMHUB) endpoint. This modification has enabled the attackers to deploy web shells on dozens of systems, giving them a foothold in the targeted organizations. The hackers have also been using URL-encoded characters and POST requests to access web shells behind load-balanced environments.

ShinyHunters’ tactics have expanded beyond education sector targets, with the new campaign affecting organizations across various industries, including agriculture, government, healthcare, IT services, technology, and transportation. The group’s primary goal is data theft and extortion, as evidenced by its previous attacks on high-profile targets such as the FBI.

In addition to deploying web shells and backdoors, ShinyHunters has also been using open-source tools like Neo-reGeorg for internal discovery and lateral movement, and MeshCentral for remote management. The attackers have executed commands with root or System privileges to perform host and user discovery, process verification, and abused PeopleSoft and WebLogic service accounts to gain access to application data, configuration files, and database connection strings.

PeopleSoft customers are advised to apply Oracle’s patches for CVE-2026-35273, harden their environments, hunt for potential indicators of compromise (IoCs) and data theft, and prepare for extortion in the event of a compromise. Organizations should also be on high alert for potential public exposure of stolen data and monitor for extortion communications.

In light of this new wave of attacks, it is essential for organizations to remain vigilant and take proactive measures to protect themselves against ShinyHunters’ tactics. This includes keeping software up-to-date, implementing robust security protocols, and regularly monitoring systems for signs of compromise. By staying informed and taking a proactive approach to cybersecurity, organizations can minimize the risk of falling victim to this type of attack.


Source: SecurityWeek — 2026-09-28