Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors unc6240

Also known as: tracked as, ShinyHunters, Kryptonite Panda, GINGHAM TYPHOON, Leviathan, UNC6040, TEMP.Periscope, TEMP.Jumper, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, Gingham Typhoon, ISLAND CASTLE

Description

Between May 27 and June 9, 2026, UNC6240 (ShinyHunters) conducted an active compromise and extortion campaign targeting Oracle PeopleSoft application infrastructure. The threat actor exploited CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component, as a zero-day before Oracle's June 10, 2026 advisory. Over 100 organizations were potentially affected, with 68 percent operating in higher education and most based in the United States. Attackers deployed customized MeshCentral agents masquerading as Microsoft Azure services, established C2 infrastructure at azurenetfiles.net, and used lateral movement scripts to propagate across internal networks. The campaign culminated in data exfiltration and publication of stolen data on the ShinyHunters Data Leak Site on June 9, 2026. Compromised systems received defacement markers and extortion notices.

Goals & Targeting

Targeted Sectors

Education
Financial services
Government
Aviation
Energy
Healthcare
Maritime
Telecommunications
Defense
Critical infrastructure
Manufacturing
Retail

Targeted Countries / Regions

United States of America
IN
CN
GB
US

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 9 Filename 5 Email Address 2 IPv4 Address 4

References

  1. www.huntress.com — Cited by web research for: UNC6040
  2. attack.mitre.org — Cited by web research for: T1020
  3. cloud.google.com — Cited by web research for: MeshCentral
  4. cloud.google.com — Cited by web research for: Phishing infrastructure
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet

Intel Summary

19

Techniques

30

Tools

0

Campaigns

29

IOCs

0

Observed Data

10

Tactics

Tags

Ransomware
APT
Zero-Day Exploitation
Backdoor / C2
Data Exfiltration
Hacktivism

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.