One URL-Encoded Character Bypasses WAF Rules: ShinyHunters-Linked UNC6240 Expands Oracle PeopleSoft Attacks and Deploys Web Shells

One URL-Encoded Character Bypasses WAF Rules: ShinyHunters-Linked UNC6240 Expands Oracle PeopleSoft Attacks and Deploys Web Shells

One URL-Encoded Character Bypasses WAF Rules: ShinyHunters-Linked UNC6240 Expands Oracle PeopleSoft Attacks and Deploys Web Shells

Google is warning of renewed mass exploitation of a known Oracle PeopleSoft vulnerability after attackers modified their exploit to slip past the web application firewalls that were blocking it. The campaign, attributed by Mandiant to the ShinyHunters-linked cluster UNC6240, weaponizes CVE-2026-35273 (CVSS 9.8), a critical flaw enabling unauthenticated remote code execution in the PeopleSoft Environment Management Hub (PSEMHUB). The vulnerability was first exploited as a zero-day against academic institutions to run reconnaissance, install the MeshCentral agent for persistence, move laterally over SSH and steal data. In this new wave, targets span higher education, technology, IT services, healthcare, agriculture, transportation and government, with web shells deployed on dozens of systems.

The WAF bypass is the story's center. Mandiant: "This new wave of activity stems from UNC6240 modifying its exploit to bypass web application firewall (WAF) rules blocking the vulnerable Environment Management Hub (PSEMHUB) endpoint. The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/." The encoded %50 decodes to the letter P after the proxy. "Many WAF and reverse proxy rules match the literal path before URL decoding, while the PeopleSoft application server decodes the request and routes it to the vulnerable servlet."

From there the chain is fast: a POST to /%50SEMHUB/hub carrying a serialized Java object abuses deserialization in the hub servlet for fileless command execution, then drops two JSP web shells into the PSEMHUB.war directory — x.jsp for cross-platform command execution and u.jsp for chunked file uploads and command execution via cmd.exe. The web shells upload a trojanized but validly signed installer, Ple64.exe, which loads the SIDEEYE C++ backdoor in memory and communicates with 162.219.30[.]165 over TCP for credential theft, process and file management, and reverse shell and reverse proxy capabilities. On Linux hosts, UNC6240 deployed MeshAgent for persistence, alongside the Neo-reGeorg tunneling toolkit. Roughly a quarter of the actor's commands ran as root or NT Authority\SYSTEM; the rest under PeopleSoft or WebLogic service accounts. Google notes UNC6240 follows a data-theft extortion pattern: steal data, threaten to publish unless paid — affected organizations should prepare for extortion communications.

What Should You Do?

  1. Apply the CVE-2026-35273 patch — this is a known, patched flaw being re-exploited; unpatched PSEMHUB endpoints are the entire attack surface.
  2. Remove the servlet: disable the Environment Management Hub service in multi-server configurations, or remove the PSEMHUB application entirely in single-server ones.
  3. Hunt now: search WebLogic access logs for requests to "/PSEMHUB/" and any percent-encoded variant; inspect the PSEMHUB.war directory for JSP web shells; rotate credentials readable by the PeopleSoft service account.
  4. Follow the data: check PeopleSoft and database hosts for large archive files in temporary or web-accessible directories, review database audit logs for bulk queries against HR, payroll and student records, and monitor outbound traffic from PeopleSoft hosts.

The WAF Angle

This incident is the cleanest possible demonstration of why literal string matching is a WAF's soft spot: one encoded byte — %50 for P — defeated rules that were otherwise doing their job. The rule saw /%50SEMHUB/, found no match for /PSEMHUB/, and let the request through; the application server then decoded the path and routed it exactly where attackers wanted. The fix is to normalize and decode before matching: run rules on the decoded path, block percent-encoded variants of sensitive endpoints outright, and treat any request path containing percent-encoding that resolves to a protected URI as a high-severity event on its own. It is also a reminder that WAFs buy time, not safety — the real fix was the patch, available since Oracle's July update. The same group's FBI intrusion used a different PeopleSoft zero-day, which we covered when ShinyHunters claimed the FBIJobs.gov breach; the lesson from both is that ERP servlets exposed to the internet are a standing target, and a bypassable WAF is not a mitigating control worth betting an HR database on.

Sources