Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Targets Education Sector with Oracle PeopleSoft Exploit

f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc

TLP:CLEAR
Active

SHA-256 Hash

Description

Between May 27 and June 9, 2026, UNC6240 (ShinyHunters) conducted an active compromise and extortion campaign targeting Oracle PeopleSoft application infrastructure. The threat actor exploited CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component, as a zero-day before Oracle's June 10, 2026 advisory. Over 100 organizations were potentially affected, with 68 percent operating in higher education and most based in the United States. Attackers deployed customized MeshCentral agents masquerading as Microsoft Azure services, established C2 infrastructure at azurenetfiles.net, and used lateral movement scripts to propagate across internal networks. The campaign culminated in data exfiltration and publication of stolen data on the ShinyHunters Data Leak Site on June 9, 2026. Compromised systems received defacement markers and extortion notices.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Targets Education Sector with Oracle PeopleSoft Exploit
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:06
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.