News Room
16
Share
ShinyHunters Weaponizes Oracle PeopleSoft Zero-Day CVE-2026-35273 in Massive Global Extortion Campaign
criticalZero-Day Exploits

ShinyHunters Weaponizes Oracle PeopleSoft Zero-Day CVE-2026-35273 in Massive Global Extortion Campaign

Mandiant identifies a critical unauthenticated RCE vulnerability in Oracle PeopleSoft exploited by UNC6240 to breach over 100 organizations, focusing on higher education and enterprise sectors.

14 July 2026Last updated 20 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-35273
Source:
Mandiant
Read Time:
5 min

Executive Summary

Intelligence reports from Mandiant and Oracle security teams confirm a massive, automated exploitation campaign targeting Oracle PeopleSoft instances globally. Between May and mid-July 2026, the cybercriminal syndicate known as ShinyHunters (tracked as UNC6240) successfully leveraged a critical zero-day vulnerability, now identified as CVE-2026-35273, to infiltrate at least 100 organizations. The campaign has resulted in the theft of sensitive institutional data, most notably impacting the University of Nottingham, where over 450,000 student and staff records were compromised and subsequently leaked. The scale of this operation indicates a highly industrialized approach to vulnerability research and exploitation by criminal actors.

Threat Analysis

The threat actor, UNC6240, has evolved beyond traditional opportunistic phishing, demonstrating the capability to discover and weaponize high-impact zero-day vulnerabilities in enterprise resource planning (ERP) systems. The group’s methodology centers on the industrialization of exploitation: utilizing high-speed scanning to identify vulnerable Environment Management Hub endpoints across the public internet. This campaign is primarily motivated by financial extortion, with the group demanding significant ransoms to prevent the publication of stolen data. The targeting of higher education institutions (68% of known victims) suggests an assessment of these environments as having lower security maturity compared to financial services, despite holding equally sensitive personal and research data. The group's speed—exploiting systems within minutes of their appearance on the public internet—suggests the integration of AI-assisted scanning and automated payload generation.

Technical Details

CVE-2026-35273 is a critical remote code execution (RCE) flaw with a CVSS score of 9.8. It resides in the Environment Management component of Oracle PeopleTools versions 8.61 and 8.62. The vulnerability allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted HTTP POST request to the EnvironmentManagementHub service. This request exploits a logic error in how the hub processes serialized objects, leading to immediate server-side execution.

Upon successful exploitation, UNC6240 deploys a lightweight C2 framework using MeshCentral, an open-source tool they obfuscate to appear as legitimate Azure management traffic. They then deploy a post-exploitation utility named [victim]_fanout.sh to automate the discovery of internal systems and perform lateral movement via SSH credential spraying. Data is exfiltrated using zstd compression to reduce network footprints and evade detection by legacy traffic monitoring systems. The attackers also maintained persistence by creating rogue administrative accounts within the PeopleSoft application layer.

Attribution Assessment

Mandiant attributes this campaign to UNC6240, a group synonymous with the ShinyHunters brand. Their tactics, including the use of MeshCentral for C2 and the specific 'README' file naming conventions, align with previously documented extortion operations. While the group shows technical sophistication comparable to nation-state actors, their operational security and clear focus on data monetization confirm their status as a high-tier cybercriminal entity. There is no evidence currently linking this campaign to geopolitical espionage; however, the group's acquisition of zero-day capabilities represents a significant shift in the cybercrime landscape.

Implications

The compromise of ERP systems is a "worst-case scenario" for enterprise security. Because PeopleSoft manages payroll, student records, and financial operations, the blast radius of a single successful exploit is enormous. The delay in the public disclosure of the patch (Oracle released the advisory on June 10, weeks after active exploitation began) highlights the extreme risk of zero-day vulnerabilities in critical business software. Organizations that failed to implement defense-in-depth measures, such as network-level isolation of administrative interfaces, suffered complete data loss and significant reputational damage.

Recommendations

  • Apply Security Updates: Immediately upgrade PeopleTools to the latest version (8.61.05 or 8.62.01) which includes the fix for CVE-2026-35273.

  • Network Isolation: Ensure that the PeopleSoft Environment Management Hub is not accessible from the public internet; use a VPN or zero-trust access proxy.

  • Search for IoCs: Audit all systems for the presence of unauthorized MeshCentral installations and the marker file README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

  • Credential Rotation: Rotate all SSH keys and administrative passwords across the PeopleSoft infrastructure to mitigate the risk from lateral movement scripts.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo