Google Cloud BlogMandiant11 min readadvanced
ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft
Summary
ShinyHunters (UNC6240) renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273, bypassing WAFs by URL-encoding a single character in the request path. This campaign expanded global targeting across multiple sectors, deploying web shells and a multi-stage backdoor.
- Threat actors bypassed WAFs blocking /PSEMHUB/ by URL-encoding 'P' to /%50SEMHUB/, as WAFs often match literal paths before decoding.
- Patching CVE-2026-35273 is critical; WAF rules are not a substitute and can be bypassed by simple encoding.
- Exploitation abuses Java deserialization in PSEMHUB, leading to web shell deployment (x.jsp, u.jsp) or fileless command execution.
- x.jsp provides cross-platform command execution using hex-encoded commands and OS detection to evade WAFs.
Organizations using Oracle PeopleSoft must immediately patch and review their WAF configurations, as an active, sophisticated threat actor is exploiting a known vulnerability with WAF bypass techniques.
8/10



