ShinyHunters Evade Web Filters to Reactivate PeopleSoft Exploits
Cyber‑crime group ShinyHunters has resumed attacks against Oracle PeopleSoft applications by sidestepping web‑application firewalls (WAFs) with a URL‑encoding technique that masks the vulnerable request.
The campaign leverages the recently disclosed CVE‑2026‑35273 flaw, which allows unauthenticated attackers to inject malicious code into PeopleSoft web interfaces. By encoding the exploit payload, the threat actors avoid detection by common WAF rule sets that would otherwise block the malicious request.
Once the initial breach is achieved, the attackers drop web shells onto the compromised server. These shells serve as footholds for further activity, including the deployment of the SIDEEYE backdoor—a tool that enables persistent remote access and lateral movement across the network.
Security researchers who first reported the activity, citing Hackread, note that the use of SIDEEYE marks an escalation in the group’s toolkit. The backdoor is designed to be modular, allowing operators to load additional modules for data exfiltration, credential harvesting, or command‑and‑control communications.
Oracle PeopleSoft, a suite used by many large enterprises for human resources, finance, and campus management, has been a frequent target for attackers seeking to harvest sensitive employee data or disrupt business operations. The CVE‑2026‑35273 vulnerability specifically affects the PeopleTools component, which processes web requests and can be tricked into executing arbitrary commands when supplied with crafted input.
Organizations running PeopleSoft are advised to review their WAF configurations and ensure that rule sets are updated to recognize encoded attack vectors. Applying Oracle’s latest security patches, which address CVE‑2026‑35273, remains a critical mitigation step.
Experts also recommend network segmentation and strict outbound traffic monitoring to detect the command‑and‑control traffic associated with the SIDEEYE backdoor. Incident response teams should prioritize the identification and removal of unauthorized web shells, which are often hidden in obscure directories or disguised as legitimate scripts.
As threat actors continue to refine evasion techniques, the broader cybersecurity community is watching for signs of similar tactics being applied to other enterprise platforms. The ongoing evolution of attack methods underscores the need for continuous monitoring, timely patch management, and layered defenses to protect against sophisticated intrusion campaigns.
Comments (0)
Be the first to comment.
Join the discussion