Mandiant and GTIG identified an active extortion campaign by UNC6240 (ShinyHunters) exploiting CVE-2026-35273 as a zero-day against Oracle PeopleSoft Environment Management Hub endpoints. The attackers used MeshCentral staging servers, masquerading Azure-related binaries, and a propagation script to move laterally and leak stolen data to the ShinyHunters Data Leak Site. #UNC6240 #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #MeshCentral
Keypoints
- UNC6240 targeted Oracle PeopleSoft with zero-day exploitation of CVE-2026-35273.
- The campaign focused on Environment Management Hub endpoints and began before Oracleβs advisory.
- Attackers used MeshCentral agents and azurenetfiles.net to stage command-and-control infrastructure.
- A custom script, [victim_abbreviation]_fanout.sh, automated lateral movement and defacement actions.
- Stolen data from compromised organizations was published on the ShinyHunters Data Leak Site.