Back to Intelligence

ShinyHunters (UNC6240) Mass Exploitation of Oracle PeopleSoft CVE-2026-35273: SIDEEYE Backdoor, Neo-reGeorg Tunnels & MeshAgent — OTX Detection Pack

SA
Security Arsenal Team
September 28, 2026
10 min read

AlienVault OTX pulse data confirms that UNC6240, the intrusion set publicly tracked as ShinyHunters, has resumed a mass-exploitation campaign targeting internet-facing Oracle PeopleSoft environments globally. Victimology spans education, technology, healthcare, agriculture, transportation, and government — a classic opportunistic sweep aimed at maximizing extortion leverage rather than selective espionage.

The campaign is built around CVE-2026-35273, a vulnerability in the PeopleSoft Environment Management components. The most tactically significant detail in this pulse is the WAF bypass technique: UNC6240 URL-encoded a single character in the request path, which was sufficient to evade web application firewall rulesets while still being normalized correctly by the PeopleSoft application server. This means organizations that believed themselves protected behind a WAF without applying the patch are exposed.

Post-exploitation follows a three-stage tooling chain:

  1. Web shell / SIDEEYE backdoor deployment — initial foothold and persistent access on the compromised PeopleSoft web tier.
  2. Neo-reGeorg — a tunneling tool that pivots HTTP/S traffic through the compromised web server into the internal network, bypassing egress restrictions.
  3. MeshAgent — the MeshCentral remote management agent, repurposed as a legitimate-signed RMM tool for hands-on-keyboard access, blending malicious activity with normal administrative traffic.

The objective is consistent with ShinyHunters' historical tradecraft: bulk data theft followed by extortion, typically advertised on dark web leak channels. Organizations running PeopleSoft — which commonly houses HR, payroll, student records, and financial data — should treat any exposure as a probable data-breach event, not merely an intrusion attempt.

Threat Actor / Malware Profile

UNC6240 / ShinyHunters

ShinyHunters is a financially motivated extortion group with a long history of mass exploitation of enterprise SaaS and web platforms. UNC6240 is the associated intrusion cluster. Their model is scale: exploit a single high-impact CVE across thousands of unpatched instances, harvest databases, then monetize via extortion and dark web data sales.

SIDEEYE Backdoor

  • Distribution method: Dropped to the PeopleSoft web root following successful CVE-2026-35273 exploitation.
  • Payload behavior: Provides persistent remote command execution and file staging capability on the web tier; acts as the primary fallback access mechanism.
  • C2 communication: HTTP/S-based tasking; observed infrastructure includes the domain azurenetfiles.net, masquerading as legitimate Azure file services traffic, and the IPv4 address 104.219.234.138.
  • Persistence mechanism: Web shell placement within application-served directories, surviving application restarts.
  • Anti-analysis techniques: Blends into application traffic patterns; cloud-themed C2 naming designed to pass casual proxy review.

Neo-reGeorg

  • Distribution method: Uploaded as a JSP/web-accessible tunnel endpoint post-exploitation.
  • Payload behavior: Establishes a SOCKS-like proxy tunnel over HTTP/S through the compromised web server, enabling internal network pivoting despite restrictive egress filtering.
  • C2 communication: Encapsulated inside normal-looking HTTP requests to the web shell endpoint — no direct outbound C2 connection required from internal assets.

MeshAgent

  • Distribution method: Staged after initial access as a hands-on-keyboard remote administration channel.
  • Payload behavior: Signed, legitimate MeshCentral agent binary — provides full interactive desktop and shell access.
  • C2 communication: Outbound TLS to MeshCentral infrastructure; frequently allowlisted by default in environments that don't explicitly restrict RMM tooling.
  • Anti-analysis techniques: Living-off-the-land via legitimate software; signature-based AV detection is unreliable against the signed binary.

IOC Analysis

The pulse contains three actionable indicator types:

TypeIndicatorOperationalization
IPv4104.219.234.138Block at egress firewall/proxy; retro-hunt netflow, DNS, and proxy logs for 90 days
Domainazurenetfiles.netDNS sinkhole/block; hunt DNS query logs, TLS SNI in proxy and EDR telemetry
CVECVE-2026-35273Asset inventory query: identify all PeopleSoft instances; verify patch state; review WAF logs for URL-encoded path anomalies against Environment Management endpoints
SHA256 (x5)2bee941f..., 3ba21569..., 419c571e..., 48b4a082..., ba14419b...EDR hash-block; sweep file telemetry across web-tier servers, particularly PeopleSoft web root and temp directories

SOC operationalization guidance:

  • Prioritize the network IOCs over hashes. The SIDEEYE hashes are trivially recompiled; the C2 domain and IP have longer dwell value for retro-hunting.
  • Cloud-themed domain abuse (azurenetfiles.net) means simple keyword allowlisting of "azure" in proxy rules is a detection gap. Alert on DNS resolution of this exact domain and flag any newly-registered azure-lookalike domains resolving from PeopleSoft servers.
  • The PeopleSoft web tier should have near-zero outbound internet initiation. Any egress from these servers to non-Oracle/non-update infrastructure is inherently suspicious.
  • Tooling: EDR hash sweeps (Defender/CrowdStrike/SentinelOne), DNS log analytics (Sentinel/Zeek), and WAF log review for single-character URL-encoding in request paths.

Detection Engineering

YAML
---
title: PeopleSoft WAF Bypass - URL-Encoded Path Exploitation Attempt (CVE-2026-35273)
id: 8a1f3c2e-9d4b-4e6a-b1c7-2f5d8a9e3b01
status: experimental
description: Detects URL-encoded request paths targeting Oracle PeopleSoft Environment Management endpoints, consistent with UNC6240/ShinyHunters WAF bypass technique observed in OTX pulse
date: 2026/09/28
author: Security Arsenal Threat Intelligence
references:
  - https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
logsource:
  category: webserver
product: windows
service: iis
detection:
  selection_encoded_path:
    cs-uri-stem|contains:
      - '%2e'
      - '%2f'
      - '%5c'
      - '%25'
  selection_peoplesoft:
    cs-uri-stem|contains:
      - '/psc/'
      - '/psp/'
      - 'emhub'
      - 'PSEMHUB'
      - 'EnvironmentManager'
  condition: selection_encoded_path and selection_peoplesoft
falsepositives:
  - Legitimate application URLs with encoded characters (rare on these endpoints)
level: high
tags:
  - attack.initial_access
  - attack.t1190
---
title: SIDEEYE C2 Communication to ShinyHunters Infrastructure
id: 7b2e4d1f-6c3a-5f7b-c2d8-3e6f9b0c4d12
status: experimental
description: Detects network connections from PeopleSoft server processes to known UNC6240 SIDEEYE C2 infrastructure or unexpected outbound connections from Java web-tier processes
date: 2026/09/28
author: Security Arsenal Threat Intelligence
logsource:
  category: network_connection
  product: windows
detection:
  selection_c2:
    DestinationHostname: 'azurenetfiles.net'
  selection_c2_ip:
    DestinationIp: '104.219.234.138'
  selection_webtier_egress:
    Image|endswith:
      - '\java.exe'
      - '\javaw.exe'
      - '\w3wp.exe'
    DestinationPort:
      - 443
      - 80
  condition: selection_c2 or selection_c2_ip or selection_webtier_egress
falsepositives:
  - Legitimate Oracle update traffic from PeopleSoft web tier (baseline and exclude known Oracle endpoints)
level: critical
tags:
  - attack.command_and_control
  - attack.t1071.001
---
title: MeshAgent RMM Execution on PeopleSoft Web Tier
id: 5c3a7e2d-4f1b-6a8c-d3e9-4f7a0b1d5e23
status: experimental
description: Detects execution or installation of MeshCentral MeshAgent, repurposed by UNC6240 as an RMM persistence mechanism on compromised servers
date: 2026/09/28
author: Security Arsenal Threat Intelligence
logsource:
  category: process_creation
  product: windows
detection:
  selection_image:
    Image|endswith:
      - '\meshagent.exe'
      - '\meshagent64.exe'
  selection_cmdline:
    CommandLine|contains:
      - 'meshagent'
      - 'meshcentral'
  selection_service:
    CommandLine|contains:
      - '-fullinstall'
      - 'Mesh Agent'
  condition: selection_image or selection_cmdline or selection_service
falsepositives:
  - Authorized MeshCentral deployment (verify against approved RMM inventory)
level: high
tags:
  - attack.command_and_control
  - attack.t1219
KQL — Microsoft Sentinel / Defender
// UNC6240 / ShinyHunters PeopleSoft Compromise Hunt - Microsoft Sentinel
// Hunts network IOCs, web-tier egress anomalies, and MeshAgent/SIDEEYE artifacts
let Lookback = 30d;
let C2IP = "104.219.234.138";
let C2Domain = "azurenetfiles.net";
let SIDEEYEHashes = dynamic([
    "2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7",
    "3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3",
    "419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86",
    "48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494",
    "ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07"]);
union isfuzzy=true
(
    DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where RemoteIP == C2IP or RemoteUrl has C2Domain
    | project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort
    | extend HuntHit = "Known C2 Network IOC"
),
(
    DeviceFileEvents
    | where TimeGenerated > ago(Lookback)
    | where SHA256 in~ (SIDEEYEHashes)
    | project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, InitiatingProcessFileName
    | extend HuntHit = "SIDEEYE File Hash Match"
),
(
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where (ProcessCommandLine has_any ("meshagent", "meshcentral", "Neo-reGeorg", "reGeorg"))
        or (FileName in~ ("java.exe", "javaw.exe", "w3wp.exe") and ProcessCommandLine has_any ("cmd.exe", "powershell", "certutil", "curl", "bitsadmin"))
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName
    | extend HuntHit = "MeshAgent/RMM or Web-Tier Shell Spawning"
),
(
    DeviceNetworkEvents
    | where TimeGenerated > ago(Lookback)
    | where InitiatingProcessFileName in~ ("java.exe", "javaw.exe", "w3wp.exe")
    | where RemotePort in (443, 80) and not(RemoteUrl has_any ("oracle.com", "microsoft.com", "windowsupdate.com"))
    | summarize ConnectionCount = count(), RemoteHosts = make_set(RemoteUrl, 20) by DeviceName, InitiatingProcessFileName
    | extend HuntHit = "PeopleSoft Web Tier Unexpected Egress"
)
| sort by TimeGenerated desc
PowerShell
# UNC6240 / ShinyHunters - PeopleSoft Compromise IOC Sweep
# Run elevated on PeopleSoft web/application tier servers

$ErrorActionPreference = 'SilentlyContinue'
$Report = @()

# --- 1. Hash sweep for SIDEEYE payloads ---
$SIDEEYEHashes = @(
    '2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7',
    '3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3',
    '419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86',
    '48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494',
    'ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07'
)

$SearchPaths = @('C:\PSFT', 'D:\PSFT', 'C:\oracle', 'C:\Inetpub', 'C:\Temp', 'C:\Windows\Temp')
foreach ($Path in $SearchPaths) {
    if (Test-Path $Path) {
        Get-ChildItem -Path $Path -Recurse -File -Include *.jsp,*.jspx,*.asp,*.aspx,*.exe,*.dll -ErrorAction SilentlyContinue | ForEach-Object {
            $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
            if ($SIDEEYEHashes -contains $h) {
                $Report += [PSCustomObject]@{ Check='SIDEEYE Hash Match'; Finding=$_.FullName; Severity='CRITICAL' }
            }
        }
    }
}

# --- 2. Web shell / Neo-reGeorg artifact hunt (recent JSP/JSPX in web roots) ---
$WebRoots = @('C:\PSFT\webserv', 'D:\PSFT\webserv')
foreach ($Root in $WebRoots) {
    if (Test-Path $Root) {
        Get-ChildItem -Path $Root -Recurse -Include *.jsp,*.jspx,*.war -File |
            Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-60) } |
            ForEach-Object {
                $content = Get-Content $_.FullName -Raw
                if ($content -match 'reGeorg|socket|ProcessBuilder|Runtime\.getRuntime|proxy') {
                    $Report += [PSCustomObject]@{ Check='Suspicious Web Shell Content'; Finding=$_.FullName; Severity='HIGH' }
                }
            }
    }
}

# --- 3. MeshAgent persistence: services, scheduled tasks, run keys ---
$MeshSvc = Get-Service | Where-Object { $_.Name -match 'mesh' -or $_.DisplayName -match 'mesh' }
if ($MeshSvc) { $Report += [PSCustomObject]@{ Check='MeshAgent Service'; Finding=($MeshSvc | Out-String).Trim(); Severity='HIGH' } }

Get-ScheduledTask | Where-Object { $_.TaskName -match 'mesh' -or ($_.Actions.Execute -match 'meshagent') } | ForEach-Object {
    $Report += [PSCustomObject]@{ Check='MeshAgent Scheduled Task'; Finding=$_.TaskName; Severity='HIGH' }
}

$RunKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run',
             'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $RunKeys) {
    (Get-ItemProperty $key).PSObject.Properties | Where-Object { $_.Value -match 'meshagent' } | ForEach-Object {
        $Report += [PSCustomObject]@{ Check='MeshAgent Run Key'; Finding="$key -> $($_.Name)=$($_.Value)"; Severity='HIGH' }
    }
}

# --- 4. Live network connections to C2 / from web-tier processes ---
$SuspiciousConns = Get-NetTCPConnection -State Established | Where-Object {
    $_.RemoteAddress -eq '104.219.234.138' -or
    ($_.OwningProcess -in (Get-Process java,javaw,w3wp -ErrorAction SilentlyContinue).Id -and $_.RemotePort -in @(80,443))
}
foreach ($c in $SuspiciousConns) {
    $proc = (Get-Process -Id $c.OwningProcess).ProcessName
    $Report += [PSCustomObject]@{ Check='Suspicious Web-Tier Egress'; Finding="$proc -> $($c.RemoteAddress):$($c.RemotePort)"; Severity='CRITICAL' }
}

# --- 5. DNS cache check for C2 domain ---
$DnsHit = Get-DnsClientCache | Where-Object { $_.Entry -match 'azurenetfiles\.net' }
if ($DnsHit) { $Report += [PSCustomObject]@{ Check='C2 DNS Resolution'; Finding=($DnsHit | Out-String).Trim(); Severity='CRITICAL' } }

# --- Output ---
if ($Report.Count -eq 0) { Write-Host '[+] No UNC6240 indicators found on this host.' -ForegroundColor Green }
else { $Report | Sort-Object Severity | Format-Table -AutoSize | Out-String | Write-Host -ForegroundColor Red }

Response Priorities

Immediate (0-4 hours)

  • Block network IOCs at the perimeter: 104.219.234.138 and azurenetfiles.net at firewall, proxy, and DNS layers.
  • Inventory PeopleSoft exposure: identify every internet-reachable PeopleSoft instance and confirm CVE-2026-35273 patch status. If unpatched, take the Environment Management endpoints offline or restrict to allowlisted management IPs immediately — the WAF bypass means your WAF is not compensating control here.
  • Sweep web tiers with the PowerShell hunt script above; prioritize servers that were internet-facing during the campaign window.
  • Review WAF/reverse-proxy logs for single-character URL-encoded request paths hitting PeopleSoft Environment Management URIs over the past 90 days.

24 Hours

  • If compromise is confirmed, assume data exfiltration occurred and activate breach response: identify which PeopleSoft data stores (HR, payroll, student, financial) were accessible from the compromised tier.
  • Force credential rotation for all PeopleSoft service accounts, database accounts, and any credentials stored or cached on the compromised web tier. SIDEEYE provides full shell access — treat all credentials on the host as burned.
  • Retro-hunt EDR and proxy telemetry for the SIDEEYE hashes, MeshAgent execution, and web-tier egress anomalies across the full fleet, not just PeopleSoft servers (Neo-reGeorg tunneling means lateral movement is probable).
  • Monitor dark web leak channels for extortion posts referencing your organization — ShinyHunters typically moves to extortion within days of exfiltration.

1 Week

  • Architecture hardening: remove direct internet exposure of PeopleSoft web tiers where possible; place behind authenticated reverse proxy with strict path allowlisting that rejects encoded characters before the WAF inspection point.
  • Enforce egress restrictions on PeopleSoft servers — permit only Oracle update endpoints and approved internal services. This single control neutralizes both SIDEEYE C2 and MeshAgent callback channels.
  • Deploy RMM allowlisting policy: block execution of MeshAgent and other unapproved remote management tools via AppLocker/WDAC or EDR custom rules across all servers.
  • Add the Sigma rules and Sentinel KQL queries above to production detection pipelines with tuned baselines for legitimate Oracle traffic.
  • Conduct a lessons-learned review of patch latency for internet-facing enterprise applications — CVE-2026-35273 exploitation succeeded because patch deployment lagged public exploitability.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.