bleeping-computer · Crawled Sep 26, 2026
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
7 IoCs 1 Actors
Read original article ↗
AI Summary
The ShinyHunters threat actor, tracked as UNC6240, is exploiting CVE-2026-35273 in Oracle PeopleSoft systems using a WAF bypass technique involving URL-encoded paths (e.g., '/%50SEMHUB/') to evade detection. This allows continued exploitation of unpatched servers where WAF rules were expected to block access. The attackers deploy JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), execute in-memory commands, and deploy the SIDEEYE backdoor via 'Ple64.exe' on Windows systems. They also use Neo-reGeorg for tunneling and MeshAgent for persistence on Linux systems, targeting sectors including education, government, healthcare, and technology.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 7 extracted
MITRE ATT&CK TTPs 90 techniques
T1003 OS Credential Dumping · Credential Access T1003.002 Security Account Manager · Credential Access T1020 Automated Exfiltration · Exfiltration T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1021.004 SSH · Lateral Movement T1040 Network Sniffing · Credential Access T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1078.002 Domain Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087 Account Discovery · Discovery T1087.003 Email Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1098 Account Manipulation · Persistence T1102 Web Service · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.001 Password Guessing · Credential Access T1113 Screen Capture · Collection T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1133 External Remote Services · Persistence T1135 Network Share Discovery · Discovery T1190 Exploit Public-Facing Application · Initial Access T1192 T1192 T1195 Supply Chain Compromise · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1202 Indirect Command Execution · Defense Evasion T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1212 Exploitation for Credential Access · Credential Access T1213 Data from Information Repositories · Collection T1400 T1400 T1480 Execution Guardrails · Defense Evasion T1482 Domain Trust Discovery · Discovery T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1489 Service Stop · Impact T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1495 Firmware Corruption · Impact T1496 Resource Hijacking · Impact T1499 Endpoint Denial of Service · Impact T1529 System Shutdown/Reboot · Impact T1530 Data from Cloud Storage · Collection T1531 Account Access Removal · Impact T1538 Cloud Service Dashboard · Discovery T1538.001 T1538.001 T1542 Pre-OS Boot · Defense Evasion T1543.003 Windows Service · Persistence T1557 Adversary-in-the-Middle · Credential Access T1558 Steal or Forge Kerberos Tickets · Credential Access T1558.003 Kerberoasting · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1567 Exfiltration Over Web Service · Exfiltration T1567.001 Exfiltration to Code Repository · Exfiltration T1567.002 Exfiltration to Cloud Storage · Exfiltration T1568 Dynamic Resolution · Command And Control T1568.002 Domain Generation Algorithms · Command And Control T1570 Lateral Tool Transfer · Lateral Movement T1573 Encrypted Channel · Command And Control T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1588.002 Tool · Resource Development T1595 Active Scanning · Reconnaissance T1595.002 Vulnerability Scanning · Reconnaissance T1611 Escape to Host · Privilege Escalation T1659 Content Injection · Initial Access