The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

The ShinyHunters-affiliated threat group UNC6240 launched a renewed mass exploitation campaign in September 2026, targeting Oracle PeopleSoft systems globally across education, healthcare, government, and technology sectors. The attackers weaponized CVE-2026-35273, a critical remote code execution vulnerability, by developing a WAF bypass technique using URL-encoded characters to evade security controls. The campaign deployed web shells on dozens of systems, established persistent access through legitimate RMM tools like MeshAgent, and deployed the SIDEEYE backdoor for credential theft and data exfiltration, ultimately leading to ransomware deployment and data extortion threats.

This incident highlights the evolving sophistication of ransomware groups in bypassing modern security architectures, particularly the limitations of signature-based WAF protection against adaptive threat actors who can rapidly modify exploits to evade detection rules.

Why This Matters Now

The ShinyHunters campaign exposes critical gaps in WAF-based security strategies, demonstrating how threat actors can trivially bypass string-matching rules through simple encoding techniques, making traditional perimeter defenses insufficient against determined adversaries.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The threat actors used URL encoding to replace the character 'P' with '%50' in the request path, changing '/PSEMHUB/' to '/%50SEMHUB/', which bypassed string-based WAF rules that matched literal paths before URL decoding.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain UNC6240's lateral movement and data exfiltration capabilities by enforcing workload segmentation and controlled egress paths, reducing the attacker's ability to pivot between PeopleSoft systems and exfiltrate terabytes of sensitive data.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The initial compromise would likely still occur, but CNSF microsegmentation may constrain the attacker's ability to establish persistent network access and limit their reach to adjacent cloud workloads and resources.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely limit the web shell's ability to access system-level resources and reduce the scope of privileged operations available to the attackers within the compromised workload environment.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely block or significantly constrain SSH-based lateral movement between PeopleSoft systems, preventing the attackers from establishing persistent access across multiple internal Linux machines and reducing their operational foothold.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls may detect and limit the SIDEEYE backdoor's ability to establish reliable command and control channels, constraining the attackers' remote access capabilities and reducing their operational control over compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement would likely detect and constrain large-scale data transfers, significantly reducing the volume of sensitive data the attackers could successfully exfiltrate from HR and payroll systems to external destinations.

Impact (Mitigations)

While extortion campaigns would likely still proceed with any successfully exfiltrated data, the constrained lateral movement and reduced data exfiltration scope may limit the attackers' leverage and reduce the overall impact to affected organizations.

Impact at a Glance

Affected Business Functions

  • Human Resources Management
  • Payroll Processing
  • Student Information Systems
  • Financial Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

HR records, payroll data, student records across multiple sectors including higher education, healthcare, government, and technology organizations. Data theft involved bulk queries against sensitive database tables containing personally identifiable information.

Recommended Actions

  • • Deploy Inline IPS with Suricata signatures to detect and block CVE-2026-35273 exploitation attempts and malicious payloads before they reach vulnerable applications
  • • Implement Zero Trust Segmentation with least privilege policies to prevent lateral movement between PeopleSoft systems and limit SSH access to authorized identities only
  • • Enable Egress Security & Policy Enforcement to block unauthorized outbound connections to C2 servers like 162.219.30[.]165 and prevent data exfiltration through covert channels
  • • Deploy Multicloud Visibility & Control to detect anomalous database queries, bulk data exports, and suspicious file staging activities across PeopleSoft environments
  • • Utilize Cloud Native Security Fabric for real-time inspection of application traffic to identify web shell deployment attempts and unauthorized file uploads to web directories

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image