search

LEMON BLOG

ShinyHunters Finds a New Way Around WAF Protections in Oracle PeopleSoft Attacks

The ShinyHunters extortion group has reportedly found a simple but effective way to bypass web application firewall protections that some organisations were using to defend vulnerable Oracle PeopleSoft systems. The attackers are exploiting CVE-2026-35273, a critical PeopleSoft vulnerability that can allow unauthenticated remote code execution, by changing how the vulnerable endpoint appears in the request URL.

Instead of directly requesting /PSEMHUB/, the attackers can use an encoded version such as /%50SEMHUB/, where %50 represents the letter "P". Some web application firewalls inspect the request before decoding the URL, meaning a rule written specifically to block /PSEMHUB/ may fail to recognise the encoded version. Oracle WebLogic, however, decodes the request before processing it, allowing the traffic to reach the vulnerable endpoint.

The Vulnerability Had Already Been Actively Exploited

CVE-2026-35273 first attracted widespread attention in June when ShinyHunters began targeting Oracle PeopleSoft environments using what was initially treated as a zero-day vulnerability. The attacks reportedly affected around 100 organisations before Oracle released a security update addressing the flaw.

The vulnerability can allow an attacker to execute code remotely without authentication, making exposed PeopleSoft systems particularly attractive targets. Google's Mandiant and Threat Intelligence Group track the group involved in these attacks as UNC6240.

For organisations unable to patch immediately, one of the temporary recommendations at the time was to block external access to the vulnerable /PSEMHUB/* path through a WAF or disable the Environment Management Hub entirely.

The problem is that ShinyHunters appears to have adapted.

A Small URL Change Can Defeat Some WAF Rules

The bypass works because different layers of an application stack may interpret the same request differently.

A WAF may look at the literal URL and see:

/%50SEMHUB/

If the security rule is searching only for /PSEMHUB/, that request may not trigger the block.

Once the request reaches Oracle WebLogic, however, %50 is decoded back into the letter "P". The application therefore sees the original /PSEMHUB/ endpoint and processes the request normally.

That creates a dangerous mismatch between what the security layer believes it blocked and what the backend application actually receives.

The technique also demonstrates why relying on a single URL pattern can provide a false sense of security. Attackers may use other percent-encoded characters, mixed-case variations, or alternative representations to bypass rules that are too literal.

Patching Is More Reliable Than Filtering Around the Flaw

Mandiant is now urging organisations to install Oracle's security updates rather than relying solely on WAF rules as a permanent defence.

A WAF remains valuable as an additional security layer, but it should not replace remediation of the underlying vulnerability. When the application itself remains vulnerable, defenders are effectively relying on every possible malicious request being recognised and blocked before it reaches the server.

Attackers only need to find one representation the filter does not understand.

Organisations running Oracle PeopleSoft should also review WebLogic access logs for requests involving /PSEMHUB/ and encoded variations such as /%50SEMHUB/. Similar patterns may indicate reconnaissance or attempted exploitation.

Attackers Probe Quietly Before Launching the Full Exploit

According to Google's analysis, ShinyHunters does not necessarily deploy malware immediately after finding a PeopleSoft server.

The attackers typically begin by sending between five and 15 POST requests to /%50SEMHUB/hub. These requests contain serialized Java objects and can return information about the underlying operating system when the server is vulnerable.

Importantly, this probing can happen without writing files to disk or causing obvious disruption. That gives the attackers a relatively quiet way to determine whether the system can be exploited before committing to more intrusive activity.

Once vulnerability is confirmed, the group can execute commands directly in memory or begin installing web shells.

Web Shells Provide Persistent Control

Mandiant observed several JSP web shells being deployed after successful exploitation. An x.jsp shell was reportedly used for command execution, while u.jsp and u2.jsp were used to upload larger files.

Web shells are particularly useful to attackers because they provide an ongoing interface into a compromised web server. Instead of repeatedly exploiting the vulnerability, the attacker can return through the shell and issue commands whenever necessary.

On compromised Windows systems, ShinyHunters reportedly used these shells to deploy an executable called Ple64.exe. Although the file masquerades as a signed Light Alloy media player installer, it installs a backdoor that Google tracks as SIDEEYE.

SIDEEYE provides capabilities including credential theft, file and process management, interactive reverse shells, and reverse proxy functionality.

Compromised PeopleSoft Servers Become a Route Into the Internal Network

The attack does not necessarily end with the PeopleSoft server itself.

ShinyHunters has also been observed deploying the open-source Neo-reGeorg tunnelling toolkit through files such as tunnel.jsp and tunnel.jspx. The tool can tunnel SOCKS5 proxy traffic through normal HTTP or HTTPS connections.

This effectively turns the compromised PeopleSoft system into a gateway.

Once the attacker can proxy traffic through the server, they may be able to reach internal systems that are not directly exposed to the internet. That significantly increases the potential impact of the initial compromise because an externally accessible enterprise application can become the starting point for lateral movement deeper into the organisation.

Legitimate Remote Management Software Is Also Being Used

On compromised Linux systems, Mandiant observed the attackers deploying MeshAgent, a legitimate remote-management tool.

The use of legitimate RMM software has become increasingly common in modern attacks because these tools already provide functionality attackers need: persistent remote access, command execution, file transfer, and system management.

Their legitimate nature can also make detection more difficult. Security teams cannot assume that every instance of remote-management software is malicious, but unexpected deployments should still be investigated carefully.

An RMM tool appearing on a server where it has never previously been used deserves particular attention.

The New Campaign Has Reached Multiple Industries

Google says the latest wave of activity has resulted in web shells being deployed on dozens of systems worldwide.

Affected organisations reportedly span several sectors, including:

The diversity of victims suggests the attackers are not concentrating on one particular industry. Instead, any exposed PeopleSoft installation that remains vulnerable could be considered a potential target.

This also makes internet-facing enterprise software especially important to patch quickly. Attackers can scan large numbers of systems automatically, meaning a newly disclosed vulnerability can become widely exploited in a short period.

ShinyHunters Also Claimed a Separate PeopleSoft Zero-Day

The renewed activity comes shortly after ShinyHunters claimed it had compromised FBI systems through what the group described as another unknown Oracle PeopleSoft vulnerability.

The attackers alleged that they gained access through the FBI Jobs platform before moving laterally into AWS GovCloud infrastructure. They also claimed to have stolen between 2TB and 3TB of data relating to employees, applicants, and internal systems.

Those claims have not been independently verified.

The FBI confirmed that it was investigating reports of unauthorised activity affecting FBIjobs.gov, but did not confirm that broader systems had been breached or that the claimed volume of data had been stolen.

ShinyHunters later said it had used the WAF bypass technique described above against FBI Jobs while continuing to claim that a separate, previously unknown vulnerability also existed within the same PSEMHUB component.

Until independent evidence or vendor confirmation emerges, those additional zero-day claims should be treated cautiously.

Why the WAF Bypass Matters

The most important lesson from this campaign is not that WAFs are ineffective. They remain an important defence layer and can block enormous amounts of malicious traffic.

The problem is relying on them as a substitute for fixing a vulnerable application.

A rule designed around one exact URL representation may work perfectly against the exploit observed today and fail tomorrow when attackers change one character into an encoded equivalent.

This is particularly risky when dealing with a vulnerability that enables unauthenticated remote code execution. The potential impact is simply too high to depend indefinitely on request filtering.

What Organisations Should Do

Organisations using Oracle PeopleSoft should first determine whether their systems are affected by CVE-2026-35273 and apply the latest Oracle security updates as quickly as possible.

Security teams should also search web-server and WebLogic logs for suspicious requests to the PSEMHUB endpoint, including percent-encoded and mixed-case variations rather than looking only for the exact /PSEMHUB/ string.

Unexpected JSP files, unusual processes, MeshAgent installations, tunnelling tools, or outbound connections should be investigated. Systems believed to have been exposed while vulnerable may also require deeper compromise assessment rather than simply being patched and returned to production.

A patch prevents future exploitation. It does not automatically remove access that an attacker may already have established.

Final Thoughts

ShinyHunters' latest PeopleSoft activity is a useful reminder of how quickly attackers adapt once defenders begin responding to a vulnerability.

Blocking /PSEMHUB/ through a WAF may have provided temporary protection, but changing the path to /%50SEMHUB/ was enough to bypass some implementations because the firewall and backend application interpreted the URL differently.

From there, the attack can escalate quickly: reconnaissance, remote code execution, JSP web shells, SIDEEYE deployment, tunnelling, credential theft, and lateral movement into internal networks.

The broader lesson is straightforward. Temporary mitigations should remain temporary.

When a security update exists for an actively exploited remote-code-execution vulnerability, patching the underlying system remains far more reliable than trying to predict every variation an attacker might send through the front door.

Simba Data Breach Exposes Personal Details of More...
How to Build a Presentation Strategy That Actually...

Related Posts

 

Comments 0

Loading latest comments...
Monday, 28 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection