ShinyHunters Bypasses WAFs with URL Trick to Exploit Oracle
The ShinyHunters extortion gang is exploiting the Oracle PeopleSoft CVE-2026-35273 zero-day using a percent-encoded URL to bypass web application

ShinyHunters is using a percent-encoded URL trick to bypass web application firewall (WAF) protections for the Oracle PeopleSoft CVE-2026-35273 vulnerability. The group, tracked by Google as UNC6240, is exploiting a critical flaw in PeopleSoft’s Environment Management Hub (PSEMHUB) that allows unauthenticated remote code execution.
Attackers evade WAF rules by changing the request path from /PSEMHUB/ to /%50SEMHUB/. Here, %50 is the URL-encoded equivalent of the letter 'P'. Many WAF and reverse-proxy rules compare literal request paths before URL decoding occurs. They fail to recognize the altered request. Oracle WebLogic server, however, decodes the %50 back to a 'P' and routes the request to the vulnerable endpoint. Mandiant states this simple obfuscation creates a dangerous timing gap. "This allows the threat actor to reach the endpoint on systems whose operators may have believed their WAF rules had mitigated the exposure," the firm said.
Google warns that ShinyHunters may use other percent-encoded characters, mixed-case variations, or different spellings of the /PSEMHUB/ path to achieve the same bypass. Before exploitation, attackers typically send between 5 and 15 POST requests to the encoded endpoint. These probes return host operating system information without writing files or disrupting service.
Exploitation leads to web shell deployment and backdoor installation
After gaining access via the zero-day, attackers deploy JSP web shells and use trojanized installers to drop the SIDEEYE backdoor on Windows and Linux systems. The primary web shell, x.jsp, is used for command execution. For uploading larger files, attackers deploy u.jsp and u2.jsp. The u.jsp shell uploads files in 150 KB chunks to avoid standard HTTP request-size limits.
On compromised Windows servers, ShinyHunters uploaded a 5.2 MB file named Ple64.exe. This is a trojanized Light Alloy media player installer signed with a valid certificate. It delivers the SIDEEYE backdoor. SIDEEYE is a powerful malware family. It can steal browser and desktop application credentials. It manages processes and files. The backdoor also creates interactive reverse shells and provides reverse proxy functionality.
Attackers further entrenched access using tunneling tools and legitimate remote management software. They deployed the open-source Neo-reGeorg toolkit via tunnel.jsp and tunnel.jspx files. This tool allows SOCKS5 proxy traffic to be tunneled over HTTP and HTTPS. On compromised Linux systems, Mandiant observed ShinyHunters using the legitimate MeshAgent remote management software to maintain persistent access.
Campaign linked to ShinyHunters and tied to FBI breach claims
The ongoing activity is attributed to UNC6240, also known as the ShinyHunters extortion gang. The group claimed on September 22 that it breached FBI systems using a new Oracle PeopleSoft zero-day. ShinyHunters told one outlet the alleged FBI breach allowed remote code execution and lateral movement into the FBI's AWS GovCloud environment. The group confirmed it used the WAF bypass technique against the FBI Jobs website.
The FBI stated it was investigating claims of unauthorized activity affecting FBIjobs.gov. It did not confirm systems were breached or that any data was stolen. The outlet could not independently verify the group's claims of lateral movement or data theft. ShinyHunters continues to assert it exploited a 'NEW unknown vulnerability' in the PSEMHUB component.
Mandiant and the Google Threat Intelligence Group identified renewed exploitation of CVE-2026-35273. The same group exploited it as a zero-day between May 27 and June 9 of this year. Oracle released an emergency security update on June 10. The latest activity is a continuation of that earlier campaign. In the initial wave, researchers identified more than 100 organizations with potentially exposed PeopleSoft systems.
| Sector | Percentage/Count from Earlier Campaign |
|---|---|
| Organizations with exposed systems | Over 100 |
| Higher education organizations | 68% |
| US-based higher education organizations | Majority |
In the current campaign, Mandiant has found web shells on dozens of compromised systems across a broad range of sectors. These include higher education, technology, IT services, healthcare, agriculture, transportation, and government.
Organizations should apply the Oracle patch for CVE-2026-35273 immediately. They must also monitor WebLogic access logs for requests to /PSEMHUB/ and encoded variants like /%50SEMHUB/. Mandiant recommends that organizations running Oracle PeopleSoft take the following immediate actions.





