Mandiant and Google’s Threat Intelligence Group (GTIG) have recently alerted organizations about a renewed cyber offensive by ShinyHunters, targeting Oracle PeopleSoft users. This notorious group is known for its extortion techniques and has now set its sights on a wide array of industries using this enterprise resource planning software.
Understanding the PeopleSoft Threat
Oracle’s PeopleSoft, an ERP suite crucial for managing functions like finance, HR, and supply chain, is widely used by major enterprises. Google has raised concerns following an incident four months ago where ShinyHunters exploited a zero-day vulnerability, identified as CVE-2026-35273, allowing unauthorized remote code execution.
In June, over 100 PeopleSoft clients were targeted, including entities such as the University of Nottingham, NAIC, and Nissan. The attackers have adapted their methods to bypass existing web application firewall rules, enhancing their exploit’s effectiveness.
Scope and Impact of the Cyber Campaign
The latest attacks have broadened from the initial focus on educational institutions to include sectors like agriculture, government, healthcare, IT, and transportation. By circumventing firewall rules using encoded URL paths, ShinyHunters have managed to deploy web shells on numerous systems, thus compromising their security.
These cybercriminals have been observed using POST requests to either deploy web shells across load-balanced environments or execute commands directly. Additionally, they have maintained persistence through JSP web shells and installed the SideEye backdoor on Windows servers for further exploitation.
Mitigation and Prevention Strategies
Organizations using PeopleSoft are strongly advised to install Oracle’s patches for the CVE-2026-35273 vulnerability. Strengthening security measures, searching for indicators of compromise, and preparing for potential extortion attempts are crucial steps to safeguard against this threat.
ShinyHunters have a history of data theft and ransom demands, threatening to leak data unless paid. Companies should be vigilant for any signs of their data appearing on leak sites and prepare for possible extortion communications.
By applying these preventive measures, organizations can better protect themselves against the ongoing threat posed by ShinyHunters and similar cybercriminal groups.
