Cybersecurity

ShinyHunters Extortion Gang Bypasses Oracle PeopleSoft WAF Mitigations Using URL-Encoding Trick to Resume Global Attacks

The notorious cybercrime syndicate known as ShinyHunters has launched a renewed global offensive against enterprise infrastructure, exploiting a sophisticated URL-encoding trick to bypass web application firewall (WAF) rules designed to mitigate a critical Oracle PeopleSoft security flaw. Cybersecurity researchers from Google’s Mandiant and Threat Intelligence Group (GTIG) revealed that the extortion group is successfully weaponizing this bypass technique to target vulnerable servers whose administrators previously believed they were protected by perimeter defenses.

The renewed exploitation campaign highlights the persistent cat-and-mouse game between sophisticated threat actors and enterprise defenders. By leveraging minor discrepancies in how reverse proxies and backend servers handle uniform resource identifier (URI) encoding, UNC6240—the internal tracking designation used by Google for the ShinyHunters threat cluster—has managed to compromise dozens of high-profile organizations across multiple sectors globally. The attacks demonstrate an advanced understanding of network architecture and edge-security implementation flaws, raising fresh alarms for Chief Information Security Officers (CISOs) worldwide.

Anatomy of the WAF Bypass and the CVE-2026-35273 Vulnerability

The current wave of intrusions centers around CVE-2026-35273, a critical unauthenticated remote code execution (RCE) vulnerability residing within the Oracle PeopleSoft Environment Management Hub. The flaw initially surfaced as a zero-day exploit in early June, when BleepingComputer first reported that ShinyHunters was weaponizing the vulnerability to extract proprietary data from approximately 100 organizations. Responding rapidly to the crisis, Oracle issued an emergency patch on June 11, officially designating the issue as CVE-2026-35273.

Because immediate patching is frequently unfeasible in complex enterprise environments due to mandatory change-management cycles and regression testing, security vendors offered interim mitigations. Prominent among these was a recommendation by Mandiant and other security advisory boards: if organizations could not immediately apply official patches or disable the vulnerable Environment Management Hub, they should configure their WAFs or reverse proxies to block external HTTP requests directed at the /PSEMHUB/* endpoint.

While this defensive measure effectively shielded organizations from literal path requests, it contained a critical blind spot that threat actors quickly identified. Many standard WAF implementations and edge proxies inspect request paths in their raw, unnormalized form before passing them downstream. Consequently, security rules formulated to block the exact string /PSEMHUB/ fail to recognize percent-encoded variations of the same path.

Capitalizing on this behavior, ShinyHunters modified its exploitation framework to substitute standard alphanumeric characters with their hexadecimal percent-encoded equivalents. For example, instead of transmitting standard requests destined for /PSEMHUB/, the threat actors began dispatching requests utilizing the format /%50SEMHUB/, where %50 represents the standard percent-encoded hexadecimal value for the ASCII capital letter ‘P’.

When these obfuscated requests reach an improperly configured edge device, the WAF fails to flag the path because the literal string /PSEMHUB/ does not appear in the raw headers. The request is subsequently permitted to pass through the perimeter and is routed to the underlying Oracle WebLogic server. Oracle WebLogic natively decodes the incoming URI path—translating %50 back into ‘P’—and successfully dispatches the payload to the vulnerable endpoint. This architectural nuance allows attackers to quietly breach systems whose network operators operated under the false sense of security provided by perimeter firewalls.

Chronology of the Campaign: From Zero-Day to WAF Evasion

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The timeline of the ShinyHunters PeopleSoft campaign illustrates a rapid evolution in adversary tactics, techniques, and procedures (TTPs):

  • June 10: BleepingComputer breaks the story that the ShinyHunters extortion group is actively exploiting an unpatched zero-day vulnerability in Oracle PeopleSoft servers, impacting roughly 100 corporate and institutional entities.
  • June 11: Oracle officially patches the vulnerability, assigning it the identifier CVE-2026-35273. Google’s Threat Intelligence Group publicly attributes the attacks to the UNC6240 threat cluster, noting heavy concentration within the education sector.
  • Mid-June: Cybersecurity firms issue guidance recommending that organizations block external access to the /PSEMHUB/* endpoint via WAF rules as an interim defense for systems awaiting scheduled patch deployment.
  • Late Summer: ShinyHunters adjusts its automated scanning and exploitation scripts to incorporate percent-encoding variations, successfully bypassing edge WAF rules designed to catch literal endpoint paths.
  • September 22: ShinyHunters publicly claims responsibility for a high-profile breach of the Federal Bureau of Investigation (FBI), asserting that they leveraged a new PeopleSoft zero-day to access the FBI Jobs portal and pivot into the bureau’s AWS GovCloud infrastructure.
  • Current Operations: Google releases a comprehensive threat intelligence report detailing the active, global WAF-bypass campaign, urging organizations to abandon perimeter-only mitigations and immediately apply core software patches.

Global Impact Across Multiple Critical Sectors

The scope of the ongoing exploitation campaign extends far beyond any single industry or geographic region. According to telemetry gathered by Mandiant, the renewed wave of attacks has successfully deployed persistent backdoors and web shells across dozens of systems globally. The targeted sectors reflect a diverse cross-section of the global economy, including higher education, advanced technology, IT professional services, healthcare, agriculture, transportation, and government administration.

The operational methodology employed by UNC6240 during these intrusions is methodical and designed to minimize noise while maximizing intelligence gathering. Before executing destructive or disruptive payloads, the threat actors typically dispatch a preliminary batch of five to fifteen HTTP POST requests directed at /%50SEMHUB/hub. These requests contain carefully crafted serialized Java objects designed to query the underlying host operating system.

Crucially, this reconnaissance phase executes without writing malicious files to disk or generating system anomalies that might trigger traditional endpoint detection and response (EDR) solutions. By reviewing the responses returned by these probing requests, ShinyHunters can accurately determine whether a target host is vulnerable before committing deeper resources.

Once a server is confirmed vulnerable, the attackers pivot to full-scale compromise. Threat actors leverage the flaw to execute arbitrary system commands directly within server memory or to plant persistent web shells. Investigators have identified multiple malicious artifacts deployed during these phases, including an x.jsp web shell utilized for routine command execution, alongside u.jsp and u2.jsp variants engineered specifically for uploading larger malicious binaries.

Malware Deployment and Lateral Movement

On compromised Microsoft Windows servers, the attackers frequently utilize these initial web shells to drop an executable binary named Ple64.exe. This file has been observed masquerading as a legitimate, digitally signed installer for the Light Alloy media player; however, its true purpose is to install a sophisticated custom backdoor tracked by Google as SIDEEYE.

The SIDEEYE malware functions as a powerful post-exploitation Swiss Army knife, granting the threat actors capabilities for comprehensive credential harvesting, fine-grained process and file management, interactive reverse shell generation, and encrypted reverse proxy tunneling. Furthermore, operators have been documented deploying the open-source Neo-reGeorg tunneling toolkit—via files named tunnel.jsp and tunnel.jspx—to encapsulate standard SOCKS5 proxy traffic inside routine HTTP and HTTPS web flows. This technique allows attackers to mask their lateral movement, blending malicious traffic seamlessly with legitimate organizational web activity and navigating deeper into internal corporate networks.

In environments running Linux operating systems, Mandiant observed threat actors bypassing traditional malware binaries in favor of dual-use, legitimate administrative tools. Specifically, ShinyHunters leveraged the authorized MeshAgent remote management software to establish resilient, long-term persistence and maintain uninhibited access to compromised enterprise environments.

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

The FBI Breach Claims and Ongoing Investigations

The technical sophistication demonstrated in the WAF-bypass campaign closely aligns with broader claims made by ShinyHunters regarding high-profile government targets. On September 22, representatives from the extortion group contacted media outlets, asserting that they had successfully infiltrated systems belonging to the Federal Bureau of Investigation.

According to ShinyHunters, the alleged breach utilized an advanced Oracle PeopleSoft zero-day vulnerability to compromise the public-facing FBI Jobs platform (FBIjobs.gov). The threat actors claimed they subsequently utilized this foothold to pivot laterally into the bureau’s internal AWS GovCloud infrastructure, exfiltrating between two and three terabytes of sensitive data. The stolen repository purportedly contained comprehensive records concerning current and former FBI personnel, employment applicants, and various internal operational systems.

While independent cybersecurity journalists and researchers were initially unable to independently verify the existence of a novel zero-day, the scope of data theft, or the precise mechanics of the lateral movement, the FBI acknowledged that it had initiated a formal investigation into reported unauthorized activity affecting its recruitment portal. Federal law enforcement agencies have not formally confirmed whether data exfiltration occurred or whether internal cloud environments were successfully compromised.

Significantly, members of the ShinyHunters syndicate later confirmed to security researchers that they deployed the same percent-encoded WAF-bypass technique against the FBI Jobs infrastructure, though they continue to maintain that the initial vector involved an independent, undisclosed vulnerability within the identical PSEMHUB architectural component.

Expert Analysis and Strategic Implications for Enterprise Security

The resurgence of the ShinyHunters extortion campaign via simple URI obfuscation underscores a foundational truth in modern information security: perimeter-based defenses are fundamentally insufficient substitutes for rigorous vulnerability patch management. Relying on web application firewalls to block malicious traffic streams by matching literal strings creates an illusion of safety that sophisticated adversaries can dismantle with trivial encoding modifications.

Security analysts emphasize that as threat actors increasingly automate the discovery of WAF rule gaps, organizations must adopt a defense-in-depth posture centered on asset visibility, rapid patch deployment, and proactive log analysis. Security operations centers (SOCs) and incident response teams are strongly urged to immediately audit their WebLogic and application server access logs. Specifically, defenders must search historical and real-time logs for anomalous requests containing the literal string /PSEMHUB/ as well as any encoded variants, such as /%50SEMHUB/, mixed-case strings, or alternative hexadecimal representations.

Ultimately, the events surrounding CVE-2026-35273 serve as a sobering reminder for enterprise IT leaders. Temporary workarounds and firewall mitigations should be viewed strictly as emergency stopgaps designed to buy limited time, rather than permanent security fixes. Until comprehensive software updates are applied directly to vulnerable systems, organizations remain unacceptably exposed to automated, highly organized criminal enterprises capable of turning defensive perimeters against the networks they were built to protect.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Jar Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.