
ShinyHunters Weaponizes Oracle PeopleSoft Zero-Day CVE-2026-35273 in Massive Global Extortion Campaign
Mandiant identifies a critical unauthenticated RCE vulnerability in Oracle PeopleSoft exploited by UNC6240 to breach over 100 organizations, focusing on higher education and enterprise sectors.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-35273
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary
Intelligence reports from Mandiant and Oracle security teams confirm a massive, automated exploitation campaign targeting Oracle PeopleSoft instances globally. Between May and mid-July 2026, the cybercriminal syndicate known as ShinyHunters (tracked as UNC6240) successfully leveraged a critical zero-day vulnerability, now identified as CVE-2026-35273, to infiltrate at least 100 organizations. The campaign has resulted in the theft of sensitive institutional data, most notably impacting the University of Nottingham, where over 450,000 student and staff records were compromised and subsequently leaked. The scale of this operation indicates a highly industrialized approach to vulnerability research and exploitation by criminal actors.
Threat Analysis
The threat actor, UNC6240, has evolved beyond traditional opportunistic phishing, demonstrating the capability to discover and weaponize high-impact zero-day vulnerabilities in enterprise resource planning (ERP) systems. The group’s methodology centers on the industrialization of exploitation: utilizing high-speed scanning to identify vulnerable Environment Management Hub endpoints across the public internet. This campaign is primarily motivated by financial extortion, with the group demanding significant ransoms to prevent the publication of stolen data. The targeting of higher education institutions (68% of known victims) suggests an assessment of these environments as having lower security maturity compared to financial services, despite holding equally sensitive personal and research data. The group's speed—exploiting systems within minutes of their appearance on the public internet—suggests the integration of AI-assisted scanning and automated payload generation.
Technical Details
CVE-2026-35273 is a critical remote code execution (RCE) flaw with a CVSS score of 9.8. It resides in the Environment Management component of Oracle PeopleTools versions 8.61 and 8.62. The vulnerability allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted HTTP POST request to the EnvironmentManagementHub service. This request exploits a logic error in how the hub processes serialized objects, leading to immediate server-side execution.
Upon successful exploitation, UNC6240 deploys a lightweight C2 framework using MeshCentral, an open-source tool they obfuscate to appear as legitimate Azure management traffic. They then deploy a post-exploitation utility named [victim]_fanout.sh to automate the discovery of internal systems and perform lateral movement via SSH credential spraying. Data is exfiltrated using zstd compression to reduce network footprints and evade detection by legacy traffic monitoring systems. The attackers also maintained persistence by creating rogue administrative accounts within the PeopleSoft application layer.
Attribution Assessment
Mandiant attributes this campaign to UNC6240, a group synonymous with the ShinyHunters brand. Their tactics, including the use of MeshCentral for C2 and the specific 'README' file naming conventions, align with previously documented extortion operations. While the group shows technical sophistication comparable to nation-state actors, their operational security and clear focus on data monetization confirm their status as a high-tier cybercriminal entity. There is no evidence currently linking this campaign to geopolitical espionage; however, the group's acquisition of zero-day capabilities represents a significant shift in the cybercrime landscape.
Implications
The compromise of ERP systems is a "worst-case scenario" for enterprise security. Because PeopleSoft manages payroll, student records, and financial operations, the blast radius of a single successful exploit is enormous. The delay in the public disclosure of the patch (Oracle released the advisory on June 10, weeks after active exploitation began) highlights the extreme risk of zero-day vulnerabilities in critical business software. Organizations that failed to implement defense-in-depth measures, such as network-level isolation of administrative interfaces, suffered complete data loss and significant reputational damage.
Recommendations
-
Apply Security Updates: Immediately upgrade PeopleTools to the latest version (8.61.05 or 8.62.01) which includes the fix for CVE-2026-35273.
-
Network Isolation: Ensure that the PeopleSoft Environment Management Hub is not accessible from the public internet; use a VPN or zero-trust access proxy.
-
Search for IoCs: Audit all systems for the presence of unauthorized MeshCentral installations and the marker file
README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. -
Credential Rotation: Rotate all SSH keys and administrative passwords across the PeopleSoft infrastructure to mitigate the risk from lateral movement scripts.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Entra ID Zero-Day Exploited in the Wild: Immediate Patching Required

PaperCut Issues Emergency Patch for Actively Exploited Zero-Day Vulnerability in NG/MF Print Management Software

