$ techbeacon▋
Ransomware

ShinyHunters Resurfaces, Targeting Oracle PeopleSoft Servers Across Multiple Sectors

ShinyHunters Resurfaces, Targeting Oracle PeopleSoft Servers Across Multiple Sectors

The threat cluster identified as UNC6240 and linked to the ShinyHunters extortion group has resumed large‑scale attacks on Oracle PeopleSoft installations, exploiting the newly disclosed CVE‑2026‑35273 vulnerability. The campaign, first noted in higher‑education environments, now spans a broader set of industries, prompting renewed alerts from security researchers.

CVE‑2026‑35273 is a remote‑code‑execution flaw in a core PeopleSoft component that allows an unauthenticated attacker to execute arbitrary commands on vulnerable servers. Oracle released a security patch shortly after the vulnerability was disclosed, but many organizations have yet to apply the update, leaving a sizable attack surface for opportunistic actors.

ShinyHunters, which has built a reputation for high‑profile data‑theft and ransomware‑style extortion, is expanding its focus beyond universities into technology firms, healthcare providers, government agencies, transportation operators, agricultural enterprises, and broader IT service providers. The group’s typical pattern involves compromising a system, harvesting sensitive data, and then demanding payment to prevent public release or further exploitation.

PeopleSoft platforms are widely used for enterprise resource planning, handling financial records, human‑resources information, and supply‑chain logistics. A breach of these systems can expose personally identifiable information, financial statements, and operational details, potentially disrupting critical business processes and eroding stakeholder trust.

Cybersecurity firms, including the researchers at GBHackers who first reported the renewed activity, are urging organizations to verify that the Oracle patch has been applied, to enforce network segmentation that limits PeopleSoft exposure, and to monitor for indicators of compromise associated with UNC6240. Incident‑response teams are also recommending regular backups and a clear communication plan for any potential data‑leak disclosures.

Analysts caution that the UNC6240 cluster is likely to continue probing for unpatched PeopleSoft installations as the vulnerability remains publicly known. Law‑enforcement agencies are tracking the extortion attempts, but the dispersed nature of the targeted sectors may complicate coordinated takedowns. Organizations that act swiftly to remediate the flaw and bolster monitoring stand the best chance of avoiding costly data breaches and extortion demands.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related