ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog

Mandiant and GTIG identified an active extortion campaign by UNC6240 (ShinyHunters) exploiting CVE-2026-35273 as a zero-day against Oracle PeopleSoft Environment Management Hub endpoints. The attackers used MeshCentral staging servers, masquerading Azure-related binaries, and a propagation script to move laterally and leak stolen data to the ShinyHunters Data Leak Site. #UNC6240 #ShinyHunters #OraclePeopleSoft #CVE-2026-35273 #MeshCentral

Keypoints

  • UNC6240 targeted Oracle PeopleSoft with zero-day exploitation of CVE-2026-35273.
  • The campaign focused on Environment Management Hub endpoints and began before Oracle’s advisory.
  • Attackers used MeshCentral agents and azurenetfiles.net to stage command-and-control infrastructure.
  • A custom script, [victim_abbreviation]_fanout.sh, automated lateral movement and defacement actions.
  • Stolen data from compromised organizations was published on the ShinyHunters Data Leak Site.

Read More: https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit