Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Targets Education Sector with Oracle PeopleSoft Exploit

2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35

TLP:CLEAR
Active

SHA-256 Hash

Description

Between May 27 and June 9, 2026, UNC6240 (ShinyHunters) conducted an active compromise and extortion campaign targeting Oracle PeopleSoft application infrastructure. The threat actor exploited CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component, as a zero-day before Oracle's June 10, 2026 advisory. Over 100 organizations were potentially affected, with 68 percent operating in higher education and most based in the United States. Attackers deployed customized MeshCentral agents masquerading as Microsoft Azure services, established C2 infrastructure at azurenetfiles.net, and used lateral movement scripts to propagate across internal networks. The campaign culminated in data exfiltration and publication of stolen data on the ShinyHunters Data Leak Site on June 9, 2026. Compromised systems received defacement markers and extortion notices.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Targets Education Sector with Oracle PeopleSoft Exploit
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:06
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.