IT Brief Asia - Technology news for CIOs & IT decision-makers
Asia
UNC6240 hits PeopleSoft flaw in global renewed attacks

UNC6240 hits PeopleSoft flaw in global renewed attacks

Tue, 29th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Mandiant and Google Threat Intelligence Group have identified a renewed campaign by UNC6240, also known as ShinyHunters, exploiting an Oracle PeopleSoft vulnerability. The activity has affected dozens of systems globally.

The campaign targets CVE-2026-35273, a flaw in PeopleSoft's Environment Management Hub that Oracle rates 9.8 out of 10. It affects supported PeopleTools versions 8.61 and 8.62 and can be exploited remotely without authentication to execute code.

The latest wave differs from earlier activity because the attackers changed the request path from /PSEMHUB/ to /%50SEMHUB/. That encoded character can let requests slip past some web application firewall and reverse proxy rules that check the literal path before decoding it.

The finding suggests a gap in defensive measures adopted after the first known wave of attacks earlier this year, when the same flaw was used as a zero-day. That earlier activity was seen mainly at higher education institutions.

Bypass method

Targeted servers commonly received between five and 15 POST requests to /%50SEMHUB/hub carrying a serialised Java object. On an unpatched server, the response could reveal the operating system, allowing the attackers to verify exposure without writing a file to disk.

From there, the same vulnerable servlet could be used to deploy a web shell or execute commands that returned output in the web response. In some load-balanced environments, researchers saw repeated requests that appeared intended to place a shell on more than one node.

A probe in an access log does not by itself prove a server was compromised. Some organisations may find evidence of scanning or test requests without later signs of follow-on activity.

Even so, Mandiant observed web shells deployed on dozens of systems worldwide during the renewed campaign. Affected sectors included higher education, technology, IT services, healthcare, agriculture, transportation and government.

The researchers did not provide a country-by-country breakdown and said the published findings did not identify an Australian victim.

Post-entry tools

On compromised systems, the group used two JSP web shells: x.jsp for command execution and u.jsp for uploading files in chunks. Mandiant also documented a trojanised installer, Ple64.exe, which loaded a newly tracked backdoor called SIDEEYE in memory on Windows servers.

Initial analysis found that SIDEEYE can steal browser and desktop application credentials, manage files and processes, and provide a reverse shell or proxy. Researchers also saw the use of Neo-reGeorg tunnelling tools and MeshAgent remote management software, the latter used for persistent access on Linux systems.

Some exploitation involved command execution without placing a web shell on disk. That means file searches alone may miss malicious activity on an affected PeopleSoft server.

The report does not say every compromised system included all of those tools, or that every victim suffered data theft. But the breadth of follow-on activity suggests the attackers sought sustained access after the initial breach.

Patch urgency

Oracle issued a security alert for CVE-2026-35273 after the earlier wave of attacks. Organisations running vulnerable PeopleSoft environments should apply Oracle's update immediately rather than rely on firewall rules or path-based blocking.

The researchers also recommended disabling the Environment Management Hub service in multi-server deployments, or removing the PSEMHUB application in single-server deployments where appropriate. Defenders should review WebLogic access logs for both standard and encoded PSEMHUB paths, especially POST requests to /hub, and inspect every node behind a load balancer.

Application directories should be checked for unexpected JSP, JSPX or executable files, including x.jsp, u.jsp, tunnel.jsp and Ple64.exe. Investigators should also look for WebLogic spawning shell processes, since the absence of a web shell does not rule out command execution.

If an organisation identifies signs of compromise, it should preserve evidence, investigate access to connected systems and rotate credentials reachable from the PeopleSoft environment, including database and integration credentials.

The researchers warned that path-blocking measures are not a substitute for patching. Teams that relied on an exact-match firewall rule should verify patch status and examine logs and hosts for earlier access, because %50 represents the letter P and the server processes the decoded path.

For Australian organisations, the findings are relevant to any institution or company running a vulnerable, internet-reachable PeopleSoft environment, particularly in the sectors named in the global research. Mandiant's count of dozens of systems refers to worldwide web-shell deployments and should not be treated as an Australian figure or a count of confirmed data breaches.