ShinyHunters Oracle PeopleSoft Exploitation
CVE-2026-35273 Zero-Day Exploitation, Enterprise-App Trust, and Evidence-Led Response
- Field
- User Topic
- Value
- The UNC6240/ShinyHunters-linked exploitation and extortion campaign targeting Oracle PeopleSoft Environment Management Hub through CVE-2026-35273, with emphasis on U.S. SMB and enterprise-application risk.
- Field
- Interpreted Questions
- Value
- What exploitation is confirmed, when did it occur, which PeopleTools deployments are affected, which technical and behavioral indicators are public, what impacts were observed, and how should owners contain, hunt, restore trust, and describe uncertainty?
- Field
- Initial Observations
- Value
- Mandiant and GTIG observed exploitation from May 27 through June 9, before Oracle's June 10 alert, and attribute the active compromise and extortion campaign to UNC6240 (ShinyHunters). The attackers targeted PSEMHUB endpoints, staged customized MeshCentral agents, sprayed SSH credentials laterally, compressed stolen data, placed an extortion marker, and connected infrastructure to the group's public leak-site mirror. Oracle confirms unauthenticated HTTP takeover risk in supported PeopleTools 8.61 and 8.62; CISA added the CVE to KEV on June 12 with a June 15 due date.1, 2, 3, 4
- Field
- Source Coverage
- Value
- Tier
- Tier 0 - Most Trusted
- Checked
- 5
- Candidate Hits
- 5
- Planner Selected
- 5
- Not Used
- 0
- Tier
- Tier 1 - Authoritative
- Checked
- 5
- Candidate Hits
- 5
- Planner Selected
- 4
- Not Used
- 1
- Tier
- Tier 2 - High-Value Research
- Checked
- 5
- Candidate Hits
- 3
- Planner Selected
- 2
- Not Used
- 3
- Tier
- Tier 3 - Corroborating News
- Checked
- 6
- Candidate Hits
- 4
- Planner Selected
- 1
- Not Used
- 5
- Tier
- Tier 4 - Community Signal
- Checked
- 5
- Candidate Hits
- 2
- Planner Selected
- 0
- Not Used
- 5
- Tier
- Tier 5 - Custom Source
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tier 6 - Custom Integrations with API/Keys
- Checked
- 0
- Candidate Hits
- 0
- Planner Selected
- 0
- Not Used
- 0
- Tier
- Tier 7 - Inner Discovery
- Checked
- 4
- Candidate Hits
- 3
- Planner Selected
- 2
- Not Used
- 2
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Checked
- 7
- Candidate Hits
- 5
- Planner Selected
- 3
- Not Used
- 4
- Tier
- Total
- Checked
- 37
- Candidate Hits
- 27
- Planner Selected
- 17
- Not Used
- 20
Tier Checked Candidate Hits Planner Selected Not Used Tier 0 - Most Trusted 5 5 5 0 Tier 1 - Authoritative 5 5 4 1 Tier 2 - High-Value Research 5 3 2 3 Tier 3 - Corroborating News 6 4 1 5 Tier 4 - Community Signal 5 2 0 5 Tier 5 - Custom Source 0 0 0 0 Tier 6 - Custom Integrations with API/Keys 0 0 0 0 Tier 7 - Inner Discovery 4 3 2 2 Tier 8 - Expansion Research / AI Agent Delta 7 5 3 4 Total 37 27 17 20
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | The UNC6240/ShinyHunters-linked exploitation and extortion campaign targeting Oracle PeopleSoft Environment Management Hub through CVE-2026-35273, with emphasis on U.S. SMB and enterprise-application risk. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What exploitation is confirmed, when did it occur, which PeopleTools deployments are affected, which technical and behavioral indicators are public, what impacts were observed, and how should owners contain, hunt, restore trust, and describe uncertainty? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | Mandiant and GTIG observed exploitation from May 27 through June 9, before Oracle's June 10 alert, and attribute the active compromise and extortion campaign to UNC6240 (ShinyHunters). The attackers targeted PSEMHUB endpoints, staged customized MeshCentral agents, sprayed SSH credentials laterally, compressed stolen data, placed an extortion marker, and connected infrastructure to the group's public leak-site mirror. Oracle confirms unauthenticated HTTP takeover risk in supported PeopleTools 8.61 and 8.62; CISA added the CVE to KEV on June 12 with a June 15 due date.1, 2, 3, 4 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Use this decision table per deployment and per dependent business service. It separates authoritative vulnerability scope, observed campaign evidence, local exposure, and confirmed impact; the four figures above provide context but are not a substitute for the developed decision record.1, 2, 3, 4
Observed window
May 27–Jun 9
GTIG campaign observation; not a claim that risk ended June 9.
KEV due date
Jun 15
CISA added the CVE June 12 under BOD 26-04 guidance.
Notified
>100
Potentially vulnerable organizations; not confirmed victims.
Education share
68%
Share of GTIG's notification population, not global victimology.
- Decision Dimension
- Campaign status
- Confirmed Record
- Observed May 27–June 9 as active compromise and extortion; KEV added June 12.
- Required Decision
- Treat historically reachable affected systems as incident-triage candidates now.
- Decision Dimension
- Affected product
- Confirmed Record
- PeopleTools 8.61 and 8.62 supported versions; earlier releases likely affected but untested.
- Required Decision
- Verify release and Oracle patch evidence for every production, test, DR, and hosted instance.
- Evidence Boundary
- Oracle's public page does not expose fixed patch-level numbers.2
- Decision Dimension
- Entry path
- Confirmed Record
- Unauthenticated network access via HTTP/HTTPS to Updates Environment Management; observed PSEMHUB targeting.
- Required Decision
- Disable/remove EMHub where appropriate or block external PSEMHUB and Integration Broker access.
- Decision Dimension
- Detection pivots
- Confirmed Record
- External POSTs to two endpoints, unexpected JSP/XML/staging artifacts, outbound SMB, MeshCentral, zstd, SSH fanout, and exact IOCs.
- Required Decision
- Correlate web, host, network, identity, storage, and application evidence by timestamp.
- Evidence Boundary
- Single indicators can be benign or reused; context and prevalence matter.1
- Decision Dimension
- Observed impact
- Confirmed Record
- Data theft, extortion markers, DLS publication for some organizations; NAIC confirms unauthorized access and temporary storage access.
- Required Decision
- Scope data and connected trust before notification, restoration, and insurer decisions.
- Decision Dimension
- SMB / supply-chain reach
- Confirmed Record
- PeopleSoft may serve shared HR, payroll, finance, student, and regulatory workflows.
- Required Decision
- Ask providers and parent organizations for instance-specific exposure, patch, and investigation attestations.
| Decision Dimension | Confirmed Record | Required Decision | Evidence Boundary |
|---|---|---|---|
| Campaign status | Observed May 27–June 9 as active compromise and extortion; KEV added June 12. | Treat historically reachable affected systems as incident-triage candidates now. | Public activity window does not prove local compromise or campaign cessation.1, 3 |
| Affected product | PeopleTools 8.61 and 8.62 supported versions; earlier releases likely affected but untested. | Verify release and Oracle patch evidence for every production, test, DR, and hosted instance. | Oracle's public page does not expose fixed patch-level numbers.2 |
| Entry path | Unauthenticated network access via HTTP/HTTPS to Updates Environment Management; observed PSEMHUB targeting. | Disable/remove EMHub where appropriate or block external PSEMHUB and Integration Broker access. | A WAF-only rule can be bypassed and is not durable remediation.1, 2 |
| Detection pivots | External POSTs to two endpoints, unexpected JSP/XML/staging artifacts, outbound SMB, MeshCentral, zstd, SSH fanout, and exact IOCs. | Correlate web, host, network, identity, storage, and application evidence by timestamp. | Single indicators can be benign or reused; context and prevalence matter.1 |
| Observed impact | Data theft, extortion markers, DLS publication for some organizations; NAIC confirms unauthorized access and temporary storage access. | Scope data and connected trust before notification, restoration, and insurer decisions. | Actor claims and notified populations are not verified impact counts.1, 7 |
| SMB / supply-chain reach | PeopleSoft may serve shared HR, payroll, finance, student, and regulatory workflows. | Ask providers and parent organizations for instance-specific exposure, patch, and investigation attestations. | A downstream relationship establishes dependency, not data exposure.2, 7, 8 |
The confirmed observed activity window is May 27 through June 9, 2026. Oracle disclosed the issue on June 10, making the observed campaign zero-day exploitation. The window bounds public campaign evidence; owners should not assume activity stopped on June 9.1, 2
Oracle lists supported PeopleTools 8.61 and 8.62 as affected and warns that earlier unsupported releases are likely affected but were not tested. The public advisory provides a patch-availability document rather than public fixed patch-level numbers; owners must verify the applicable Oracle patch in My Oracle Support.2, 4
GTIG triaged five staging IPs, customized Windows and Linux MeshCentral agents, the azurenetfiles.net C2 endpoint, reconnaissance of PeopleSoft configuration, a victim-specific fanout script, SSH credential spraying, zstd compression, and a connection to the ShinyHunters leak-site mirror.1
GTIG says some notified organizations blocked or remediated activity while others were compromised and had stolen data published. NAIC separately confirmed unauthorized PeopleSoft access and temporary access to certain storage areas, while disputing the actor's claimed data volume and reporting no confirmed public release at its June 23 update.1, 7
For U.S. SMBs, the principal risk is inherited dependence: a small organization may rely on a parent, payroll provider, university, insurer, MSP, or hosted administrator whose PeopleSoft environment concentrates its data. Product absence inside the SMB does not rule out third-party exposure.1, 7, 8
The report publishes hashes for the staged agents and command history but not for the fanout script or extortion marker. It does not publish victim-specific agent IDs, usernames, passwords, exploit payload, or a complete victim list. Local evidence must control organization-specific conclusions.1
Each audience owns a distinct decision and evidence standard; none can close the event alone.
- Audience
- Executive / owner
- Decision
- Keep service online, isolate, or invoke continuity plans.
- Audience
- PeopleSoft / infrastructure
- Decision
- Apply correct Oracle mitigation and reduce administrative reachability.
- Audience
- SOC / DFIR
- Decision
- Classify attempt, likely compromise, or confirmed compromise and define blast radius.
- Audience
- SMB / customer
- Decision
- Determine indirect exposure through providers, employers, schools, or shared services.
- Audience
- MSP / hosting provider
- Decision
- Contain centrally while preserving tenant-separated evidence and communications.
- Audience
- Legal / privacy / insurance
- Decision
- Assess notification, claims, and representations from confirmed facts.
| Audience | Decision | Minimum Evidence |
|---|---|---|
| Executive / owner | Keep service online, isolate, or invoke continuity plans. | Instance inventory, exposure history, business dependency, confirmed findings, and recovery option.1, 2, 3 |
| PeopleSoft / infrastructure | Apply correct Oracle mitigation and reduce administrative reachability. | Running release, patch proof, EMHub/PSEMHUB configuration, access paths, service validation.1, 2 |
| SOC / DFIR | Classify attempt, likely compromise, or confirmed compromise and define blast radius. | Preserved HTTP, filesystem, process, network, identity, storage, database, and integration telemetry.1, 3 |
| SMB / customer | Determine indirect exposure through providers, employers, schools, or shared services. | Written provider attestation tied to the instance, data relationship, window, and investigation.1, 7, 8 |
| MSP / hosting provider | Contain centrally while preserving tenant-separated evidence and communications. | Per-tenant assets, access, credentials, IOCs, data, costs, notices, and closure.1, 3 |
| Legal / privacy / insurance | Assess notification, claims, and representations from confirmed facts. | Chronology, access and acquisition proof, data scope, affected persons, contracts, costs, and uncertainty.3, 7 |
- Treat this as a compromise-assessment event: The campaign exploited CVE-2026-35273 as a zero-day from May 27 through June 9, and CISA later added it to KEV. Any affected system reachable during that period requires patch verification plus historical hunting; a current patch alone cannot resolve prior access.1, 2, 3
- Reduce the exposed administrative surface immediately: Oracle requires its mitigation, while GTIG recommends disabling EMHub or removing PSEMHUB where appropriate and otherwise blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector. WAF body inspection alone is insufficient.1, 2
- Hunt with exact campaign evidence: Correlate five staging IPs, azurenetfiles.net and its WebSocket endpoint, four staged agent names and hashes, the fanout script and marker filename, suspicious endpoint POSTs, unexpected JSP/XML files, outbound SMB, MeshCentral commands, SSH spraying, and zstd archives.1
- Assume enterprise-app trust may extend beyond one host: PeopleSoft can expose HR, payroll, finance, student, identity, storage, integration, and administrative workflows. If compromise is plausible, scope connected credentials, shares, databases, exports, service accounts, and dependent parties before restoring trust.1, 7, 8
- Keep impact statements evidence-specific: GTIG's >100 notifications and 68% education concentration describe potentially vulnerable endpoints, not confirmed victims. NAIC confirms access but disputes the actor's claimed volume. Separate exposure, compromise, acquisition, publication, and extortion claims.1, 7
- Make SMB, MSP, legal, and insurance decisions per tenant: Record which data and services each relationship exposes, preserve evidence, notify providers, evaluate contractual and regulatory duties, and obtain written closure. Do not translate a shared provider's fleet status into a customer-specific impact claim.1, 3, 7
Research and scoping note
Current uncertainty remains material: public sources do not enumerate every victim, every exploit request, victim-specific agent identifiers, the contents of stolen archives, or exact Oracle patch-level numbers. Those gaps increase the importance of local telemetry and Oracle support records; they do not reduce urgency.1, 2, 3, 4
Mandiant and GTIG identified an active compromise and extortion campaign attributed to UNC6240, which they associate with ShinyHunters, targeting Oracle PeopleSoft application infrastructure. Observed activity ran from May 27 through June 9 and aligned directly with exploitation of PSEMHUB endpoints. Because Oracle disclosed CVE-2026-35273 on June 10, this was zero-day exploitation.1, 2
Oracle describes a remotely exploitable, unauthenticated HTTP vulnerability in Updates Environment Management that can result in PeopleTools takeover and remote code execution. Supported affected releases are 8.61 and 8.62; Oracle warns earlier unsupported releases are likely affected but were not tested. CVSS 3.1 is 9.8 with high confidentiality, integrity, and availability impacts.2, 4
CISA added the issue to KEV on June 12 with a June 15 due date and requires vendor mitigation plus applicable BOD 26-04 forensic triage. The catalog's known-ransomware field is Known; this supports extortion/ransomware risk prioritization but does not prove encryption, identify every actor, or establish a local incident.3, 4
GTIG notified more than 100 organizations whose IPs correlated with potentially vulnerable endpoints; most were U.S.-based and 68% were higher-education institutions. These are exposure notifications, not a confirmed victim count. GTIG says some recipients blocked or remediated activity, while others experienced compromise and publication of stolen data.1
The public campaign record is technically concrete. Five sequential staging IPs served attacker directories on TCP 8888. Customized MeshCentral agents masqueraded as Azure services and connected to wss://azurenetfiles.net:443/agent.ashx. Operators inspected PeopleSoft and WebLogic configuration, deployed a victim-specific fanout script, sprayed SSH credentials, placed an extortion marker, compressed exfiltrated data with zstd, and connected to 176.120.22.24, the public leak-site mirror.1
Detection should combine exact IOCs with behavior: external POSTs to /PSEMHUB/hub and /PSIGW/HttpListeningConnector; loopback or internal SSRF values; unexpected JSPs below PSEMHUB.war; content in envmetadata/transactions; suspicious logs, persistantstorage, or scratchpad directories; recently changed XML below envmetadata/data/environment; outbound TCP 445; MeshCentral execution; sshpass; zstd; and the published filenames and hashes.1
Observed impact crosses enterprise boundaries. NAIC confirmed unauthorized PeopleSoft access and temporary access to certain data storage areas, but said it did not believe the actor held the claimed volume and had no confirmed public release as of June 23. That direct disclosure illustrates why leak-site claims, campaign attribution, and organization-confirmed impact must remain separate.7
For U.S. SMBs, PeopleSoft may be a hidden supply-chain exposure through payroll, benefits, universities, insurers, public-sector partners, MSPs, or shared administrative services. Leaders should request per-instance patch and investigation evidence, map data and credentials shared with providers, preserve contractual notices, and avoid assuming either safety or breach from provider-level statements alone.1, 7, 8
Immediate response is to apply Oracle's alert, reduce PSEMHUB/Integration Broker exposure, preserve evidence, search the full historical window, contain suspicious web tiers, rotate or revoke plausibly exposed trust, validate databases and exports, and rebuild or restore from trusted state when integrity cannot be established. No public fixed patch-level numbers replace Oracle's customer-specific patch documentation.1, 2, 3
Research and scoping note
The brief does not infer compromise from internet exposure, attribution from an IOC match, or data loss from a marker file. Conversely, absence of the published IOCs does not rule out exploitation because infrastructure and tooling can change. Use multiple corroborating signals and preserve negative as well as positive findings.1, 2, 3, 7
PeopleSoft sits at the intersection of sensitive records, privileged workflows, shared infrastructure, and outside dependencies. These concentrations determine why a web-tier exploit becomes a business-risk decision.
- Risk Concentration
- Unauthenticated enterprise-app entry
- Why It Matters
- Affected HTTP/HTTPS access requires no account and can lead to PeopleTools takeover.
- Risk Concentration
- Regulated business records
- Why It Matters
- PeopleSoft commonly supports HR, payroll, finance, student, identity, and administrative records.
- Risk Concentration
- Connected trust
- Why It Matters
- Operators mapped configuration, sprayed SSH credentials, accessed remote agents, and reached storage beyond the application.
- Risk Concentration
- Data-theft extortion
- Why It Matters
- The campaign used marker files and leak-site publication; business harm can occur without encryption.
- Risk Concentration
- SMB and provider dependency
- Why It Matters
- Smaller organizations may inherit exposure through employers, payroll firms, schools, insurers, MSPs, or shared administrators.
| Risk Concentration | Why It Matters | Decision Consequence |
|---|---|---|
| Unauthenticated enterprise-app entry | Affected HTTP/HTTPS access requires no account and can lead to PeopleTools takeover. | Prioritize every historically reachable instance for containment, patch proof, and forensic triage.1, 2, 3 |
| Regulated business records | PeopleSoft commonly supports HR, payroll, finance, student, identity, and administrative records. | Scope actual schemas, exports, attachments, reports, and affected people before impact statements.1, 7, 8 |
| Connected trust | Operators mapped configuration, sprayed SSH credentials, accessed remote agents, and reached storage beyond the application. | Review service accounts, keys, shares, databases, schedulers, integrations, and downstream sessions.1, 7 |
| Data-theft extortion | The campaign used marker files and leak-site publication; business harm can occur without encryption. | Prepare privacy, legal, communications, insurance, and law-enforcement workstreams around verified data evidence.1, 7 |
| SMB and provider dependency | Smaller organizations may inherit exposure through employers, payroll firms, schools, insurers, MSPs, or shared administrators. | Obtain instance-specific provider attestations and map the SMB's own data and service dependency.1, 7, 8 |
- Date / Period
- May 27, 2026
- Event / Meaning
- Earliest observed campaign activity; MeshCentral 1.1.59 and acme-client were installed on staging infrastructure and the masquerading domain was prepared.1
- Sources
- 1
- Date / Period
- May 29
- Event / Meaning
- Command history records a check for an authenticode-related npm tool, a lead for code-signing intent but not proof a staged binary was signed.1
- Sources
- 1
- Date / Period
- June 9
- Event / Meaning
- Open attacker directories enabled detailed triage; the campaign correlated with publication of stolen organization data on the ShinyHunters leak site.1
- Sources
- 1
- Date / Period
- June 10
- Event / Meaning
- Oracle released its out-of-band Security Alert and high-priority mitigation for supported PeopleTools 8.61 and 8.62.2
- Sources
- 2
- Date / Period
- June 11
- Event / Meaning
- Mandiant/GTIG publicly documented the campaign, attribution, exposure-notification population, IOCs, behaviors, detection, and hardening guidance.1
- Sources
- 1
- Date / Period
- June 12
- Date / Period
- June 15
- Event / Meaning
- CISA required-action due date. Unresolved systems after this point remain overdue and still require forensic triage where applicable.3
- Sources
- 3
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| May 27, 2026 | Earliest observed campaign activity; MeshCentral 1.1.59 and acme-client were installed on staging infrastructure and the masquerading domain was prepared.1 | 1 |
| May 29 | Command history records a check for an authenticode-related npm tool, a lead for code-signing intent but not proof a staged binary was signed.1 | 1 |
| June 9 | Open attacker directories enabled detailed triage; the campaign correlated with publication of stolen organization data on the ShinyHunters leak site.1 | 1 |
| June 10 | Oracle released its out-of-band Security Alert and high-priority mitigation for supported PeopleTools 8.61 and 8.62.2 | 2 |
| June 11 | Mandiant/GTIG publicly documented the campaign, attribution, exposure-notification population, IOCs, behaviors, detection, and hardening guidance.1 | 1 |
| June 12 | CISA added CVE-2026-35273 to KEV under BOD 26-04, with a compressed three-day federal deadline.3, 4 | 3, 4 |
| June 15 | CISA required-action due date. Unresolved systems after this point remain overdue and still require forensic triage where applicable.3 | 3 |
| June 23 | NAIC updated its direct disclosure: access had been contained, temporary storage access blocked, investigation and FBI coordination continued, and actor volume claims remained unconfirmed.7 | 7 |
| June 24 | TrendAI Zero Day Initiative published additional vulnerability analysis after coordinated disclosure, useful for technical context but later than the observed zero-day window.5 | 5 |
- Phase
- 1 — Inventory and expose
- Phase
- 2 — Contain
- Phase
- 3 — Preserve
- Phase
- 4 — Hunt
- Action
- Search exact network and file indicators plus endpoint POSTs, SSRF values, unexpected JSP/XML content, MeshCentral, sshpass, zstd, fanout, marker placement, outbound SMB, and leak-site connection evidence.1
- Sources
- 1
- Phase
- 5 — Scope trust
- Phase
- 6 — Eradicate and recover
| Phase | Action | Sources |
|---|---|---|
| 1 — Inventory and expose | Identify production, test, DR, cloned, hosted, and MSP-managed PeopleSoft; capture PeopleTools release, EMHub/PSEMHUB state, network paths, owner, and reachability since May 27.1, 2, 3 | 1, 2, 3 |
| 2 — Contain | Apply Oracle mitigation; disable EMHub or remove PSEMHUB where operationally appropriate; otherwise block external PSEMHUB and Integration Broker access and restrict management paths.1, 2 | 1, 2 |
| 3 — Preserve | Retain PIA/WebLogic logs, proxy/WAF records, filesystem metadata, EDR, NetFlow, DNS, authentication, database, storage, integration, and cloud evidence before cleanup.1, 3 | 1, 3 |
| 4 — Hunt | Search exact network and file indicators plus endpoint POSTs, SSRF values, unexpected JSP/XML content, MeshCentral, sshpass, zstd, fanout, marker placement, outbound SMB, and leak-site connection evidence.1 | 1 |
| 5 — Scope trust | Map service accounts, keys, passwords, shares, databases, exports, schedulers, payroll/HR/finance interfaces, storage, and third parties reachable from the web and application tiers.1, 7, 8 | 1, 7, 8 |
| 6 — Eradicate and recover | Remove unauthorized artifacts, rotate plausibly exposed trust, validate application and data integrity, and rebuild from known-good state when persistence or integrity cannot be resolved.1, 3 | 1, 3 |
| 7 — Decide and document | Separate vulnerability, attempt, access, acquisition, publication, and extortion findings; coordinate counsel, insurer, regulators, customers, employees, providers, and law enforcement from confirmed facts.1, 7 | 1, 7 |
- Term
- EMHub / PSEMHUB
- Term
- UNC6240 / ShinyHunters
- Term
- MeshCentral
- Meaning Here
- Legitimate open-source remote-management software customized here as attacker C2 agents. Presence must be assessed against authorization and configuration.1
- Sources
- 1
- Term
- Zero-day
| Term | Meaning Here | Sources |
|---|---|---|
| EMHub / PSEMHUB | PeopleSoft Environment Management Hub and its web application. The campaign targeted PSEMHUB endpoints; it is administrative infrastructure, not a normal user page.1, 2 | 1, 2 |
| UNC6240 / ShinyHunters | GTIG activity-cluster and extortion-brand relationship used for this campaign. It is a source-specific attribution, not proof every ShinyHunters claim shares one operator.1, 9 | 1, 9 |
| MeshCentral | Legitimate open-source remote-management software customized here as attacker C2 agents. Presence must be assessed against authorization and configuration.1 | 1 |
| Zero-day | Exploitation occurred before the vendor's public June 10 advisory and mitigation, based on GTIG's May 27–June 9 observation.1, 2 | 1, 2 |
| KEV | CISA catalog of vulnerabilities known to have been exploited. It confirms in-the-wild exploitation, not compromise of a particular organization.3 | 3 |
| SSRF | Server-side request forgery can induce server-side requests toward loopback, internal, or external destinations; GTIG recommends detecting such values at the Integration Broker connector.1 | 1 |
- Behavior / ATT&CK
- T1190 — Exploit Public-Facing Application
- Behavior / ATT&CK
- T1219 — Remote Access Software
- Behavior / ATT&CK
- T1110 — Brute Force
- Behavior / ATT&CK
- T1016 / configuration discovery
- Behavior / ATT&CK
- T1560 — Archive Collected Data
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| T1190 — Exploit Public-Facing Application | Observed PSEMHUB exploitation is consistent with exploiting an internet-reachable application for initial access.1, 10 | 1, 10 |
| T1219 — Remote Access Software | Customized MeshCentral agents provided command execution and remote administration. Mapping is behavior-based and does not make MeshCentral inherently malicious.1, 11 | 1, 11 |
| T1110 — Brute Force | The fanout script sprayed hardcoded common administrative and application credentials over SSH against internal hosts.1, 12 | 1, 12 |
| T1016 / configuration discovery | Operators inspected mounts, /etc/hosts, psappsrv.cfg, and WebLogic config.xml to map application and network topology.1, 13 | 1, 13 |
| T1560 — Archive Collected Data | The command record used tar-like collection and zstd compression to create exfil.tar.zst from an exfil directory.1, 14 | 1, 14 |
| T1041 — Exfiltration Over C2 Channel | Data theft is confirmed, but the precise transfer channel for every archive is not public; use this as a hunt hypothesis, not a universal observed technique.1, 15 | 1, 15 |
Answers distinguish authoritative campaign facts from organization-specific conclusions.
- Question
- Does affected PeopleTools mean compromise?
- Answer
- No. It establishes susceptibility; exposure and telemetry establish local status.
- Question
- Did activity end June 9?
- Answer
- June 9 ends GTIG's observed window, not necessarily all exploitation.
- Question
- Which fixed version should we run?
- Answer
- Oracle names affected branches and supplies customer patch documents, not public fixed patch-level numbers.
- Evidence Boundary
- Verify the applicable patch in My Oracle Support and prove installation.2
- Question
- Is a WAF rule enough?
- Answer
- No. GTIG warns body-inspection rules can be bypassed.
- Question
- Does no IOC match mean clean?
- Answer
- No. Infrastructure and tooling can change.
- Evidence Boundary
- Behavioral, historical, and integrity evidence remain necessary.1
- Question
- Were more than 100 organizations breached?
- Answer
- Not established. More than 100 potentially vulnerable organizations were notified.
- Evidence Boundary
- Only some were stated to experience compromise.1
- Question
- Is attribution confirmed?
- Answer
- GTIG attributes this campaign to UNC6240/ShinyHunters.
- Question
- We do not run PeopleSoft; are we out of scope?
- Answer
- Not necessarily if a provider, employer, school, insurer, or partner processed your data in PeopleSoft.
| Question | Answer | Evidence Boundary |
|---|---|---|
| Does affected PeopleTools mean compromise? | No. It establishes susceptibility; exposure and telemetry establish local status. | Record reachability, patch timing, and hunt results.1, 2, 3 |
| Did activity end June 9? | June 9 ends GTIG's observed window, not necessarily all exploitation. | Continue monitoring and include later suspicious activity.1, 3 |
| Which fixed version should we run? | Oracle names affected branches and supplies customer patch documents, not public fixed patch-level numbers. | Verify the applicable patch in My Oracle Support and prove installation.2 |
| Is a WAF rule enough? | No. GTIG warns body-inspection rules can be bypassed. | Use Oracle mitigation and endpoint/network restriction.1, 2 |
| Does no IOC match mean clean? | No. Infrastructure and tooling can change. | Behavioral, historical, and integrity evidence remain necessary.1 |
| Were more than 100 organizations breached? | Not established. More than 100 potentially vulnerable organizations were notified. | Only some were stated to experience compromise.1 |
| Is attribution confirmed? | GTIG attributes this campaign to UNC6240/ShinyHunters. | Direct victim notices may not independently confirm that actor.1, 7, 9 |
| We do not run PeopleSoft; are we out of scope? | Not necessarily if a provider, employer, school, insurer, or partner processed your data in PeopleSoft. | Dependency is not exposure; obtain provider-specific evidence.1, 7, 8 |
Each reference answers a different vulnerability-management question. The campaign report controls observed exploitation; vendor and registries control product facts; taxonomy explains weakness; direct disclosures control organizational impact.
- Reference
- Oracle June 10 Security Alert
- What It Establishes
- Affected supported branches, Updates Environment Management component, HTTP precondition, unauthenticated exploitation, CVSS, and mitigation path.
- Interpretation Limit
- Public page does not give fixed patch-level numbers, campaign IOCs, actor, or victim facts.2
- Reference
- Mandiant / GTIG June 11 report
- What It Establishes
- Observed zero-day window, PSEMHUB targeting, UNC6240 attribution, IOCs, attacker workflow, outcomes, detection, and hardening.
- Interpretation Limit
- Visibility is campaign-specific; notification counts are not a complete victim census.1
- Reference
- CISA KEV record
- What It Establishes
- Known exploitation, June 12 addition, June 15 due date, vendor-action requirement, forensic-triage reference, and ransomware field.
- Interpretation Limit
- Does not prove local compromise, name a local victim, or establish encryption.3
- Reference
- NIST NVD record
- What It Establishes
- CNA CVSS provenance, CPEs, CWE-306, SSVC, references, and change chronology.
- Interpretation Limit
- NVD has no independent score or incident telemetry for this issue.4
- Reference
- TrendAI ZDI-26-388
- What It Establishes
- Post-disclosure technical context and researcher provenance credited by Oracle.
- Reference
- MITRE CWE-306
- What It Establishes
- Meaning and consequences of missing authentication for a critical function.
- Interpretation Limit
- Does not reveal the issue's HTTP payload, vulnerable method, or campaign behavior.6
| Reference | What It Establishes | Interpretation Limit |
|---|---|---|
| Oracle June 10 Security Alert | Affected supported branches, Updates Environment Management component, HTTP precondition, unauthenticated exploitation, CVSS, and mitigation path. | Public page does not give fixed patch-level numbers, campaign IOCs, actor, or victim facts.2 |
| Mandiant / GTIG June 11 report | Observed zero-day window, PSEMHUB targeting, UNC6240 attribution, IOCs, attacker workflow, outcomes, detection, and hardening. | Visibility is campaign-specific; notification counts are not a complete victim census.1 |
| CISA KEV record | Known exploitation, June 12 addition, June 15 due date, vendor-action requirement, forensic-triage reference, and ransomware field. | Does not prove local compromise, name a local victim, or establish encryption.3 |
| NIST NVD record | CNA CVSS provenance, CPEs, CWE-306, SSVC, references, and change chronology. | NVD has no independent score or incident telemetry for this issue.4 |
| TrendAI ZDI-26-388 | Post-disclosure technical context and researcher provenance credited by Oracle. | Later technical publication does not control campaign attribution, exploitation dates, or victim impact.2, 5 |
| MITRE CWE-306 | Meaning and consequences of missing authentication for a critical function. | Does not reveal the issue's HTTP payload, vulnerable method, or campaign behavior.6 |
This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.
- Observable
- Attacker IP addresses
- Defender Use
- 142.11.200.186, 142.11.200.187, 142.11.200.188, 142.11.200.189, and 142.11.200.190 hosted staging directories on TCP 8888. 176.120.22.24 hosted the public DLS mirror reached by SSH. Coverage: campaign-specific, point-in-time; do not block without ownership and business-impact review.1
- Sources
- 1
- Observable
- Attacker domain / FQDN
- Defender Use
- azurenetfiles.net. It masquerades as an Azure-related endpoint and was configured for campaign MeshCentral C2. Coverage: reliable campaign value; legitimate Azure/NetApp domains are distinct.1
- Sources
- 1
- Observable
- Attacker-controlled / malicious URL
- Defender Use
- wss://azurenetfiles.net:443/agent.ashx is the hardcoded WebSocket C2 endpoint in configured agents. No other complete attacker-controlled URL is public in the retained primary report.1
- Sources
- 1
- Observable
- Malware filename / attacker file name
- Defender Use
- meshagent32-azure-ops.exe; meshagent64-azure-ops.exe; meshagent64-v2.exe; meshagent; [victim_abbreviation]_fanout.sh; README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT; .bash_history; meshctrl.js; exfil.tar.zst. Some are legitimate tool names or patterns, so require path, hash, parent process, and authorization context.1
- Sources
- 1
- Observable
- Malware file hash — meshagent64-azure-ops.exe
- Defender Use
- SHA-256 f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc. Campaign-configured Windows agent.1
- Sources
- 1
- Observable
- Malware file hash — meshagent64-v2.exe
- Defender Use
- SHA-256 d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f. Campaign-configured Windows agent.1
- Sources
- 1
- Observable
- Malware file hash — meshagent32-azure-ops.exe
- Defender Use
- SHA-256 c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f. Campaign-configured Windows agent.1
- Sources
- 1
- Observable
- File hash — Linux meshagent
- Defender Use
- SHA-256 68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309. The sample was unconfigured and may require runtime parameters.1
- Sources
- 1
- Observable
- File hash — .bash_history
- Defender Use
- SHA-256 2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35. Attacker command history found identically across five staging hosts.1
- Sources
- 1
- Observable
- File hashes unavailable
- Defender Use
- No reliable public campaign-specific hash is published for [victim_abbreviation]_fanout.sh, README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, meshctrl.js, or exfil.tar.zst. Do not invent values; hash locally preserved copies.1
- Sources
- 1
- Observable
- HTTP observables
- Defender Use
- External or untrusted POST requests to /PSEMHUB/hub and /PSIGW/HttpListeningConnector; inspect connector content for 127.0.0.1, localhost, ::1, or internal ranges. Review status, bytes, timing, user agent, upstream, and follow-on application behavior.1
- Sources
- 1
- Observable
- Product observables
- Defender Use
- Unexpected JSP files below <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/; content in envmetadata/transactions; unexpected logs, persistantstorage, or scratchpad directories; recent XML changes in <docroot>/envmetadata/data/environment/.1
- Sources
- 1
- Observable
- Identity observables
| Observable | Defender Use | Sources |
|---|---|---|
| Attacker IP addresses | 142.11.200.186, 142.11.200.187, 142.11.200.188, 142.11.200.189, and 142.11.200.190 hosted staging directories on TCP 8888. 176.120.22.24 hosted the public DLS mirror reached by SSH. Coverage: campaign-specific, point-in-time; do not block without ownership and business-impact review.1 | 1 |
| Attacker domain / FQDN | azurenetfiles.net. It masquerades as an Azure-related endpoint and was configured for campaign MeshCentral C2. Coverage: reliable campaign value; legitimate Azure/NetApp domains are distinct.1 | 1 |
| Attacker-controlled / malicious URL | wss://azurenetfiles.net:443/agent.ashx is the hardcoded WebSocket C2 endpoint in configured agents. No other complete attacker-controlled URL is public in the retained primary report.1 | 1 |
| Malware filename / attacker file name | meshagent32-azure-ops.exe; meshagent64-azure-ops.exe; meshagent64-v2.exe; meshagent; [victim_abbreviation]_fanout.sh; README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT; .bash_history; meshctrl.js; exfil.tar.zst. Some are legitimate tool names or patterns, so require path, hash, parent process, and authorization context.1 | 1 |
| Malware file hash — meshagent64-azure-ops.exe | SHA-256 f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc. Campaign-configured Windows agent.1 | 1 |
| Malware file hash — meshagent64-v2.exe | SHA-256 d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f. Campaign-configured Windows agent.1 | 1 |
| Malware file hash — meshagent32-azure-ops.exe | SHA-256 c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f. Campaign-configured Windows agent.1 | 1 |
| File hash — Linux meshagent | SHA-256 68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309. The sample was unconfigured and may require runtime parameters.1 | 1 |
| File hash — .bash_history | SHA-256 2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35. Attacker command history found identically across five staging hosts.1 | 1 |
| File hashes unavailable | No reliable public campaign-specific hash is published for [victim_abbreviation]_fanout.sh, README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT, meshctrl.js, or exfil.tar.zst. Do not invent values; hash locally preserved copies.1 | 1 |
| HTTP observables | External or untrusted POST requests to /PSEMHUB/hub and /PSIGW/HttpListeningConnector; inspect connector content for 127.0.0.1, localhost, ::1, or internal ranges. Review status, bytes, timing, user agent, upstream, and follow-on application behavior.1 | 1 |
| Product observables | Unexpected JSP files below <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/; content in envmetadata/transactions; unexpected logs, persistantstorage, or scratchpad directories; recent XML changes in <docroot>/envmetadata/data/environment/.1 | 1 |
| Identity observables | SSH password spraying with common administrative/application accounts, key-based SSH fallback, new or unexplained service-account use, access to shares or stores, and credential use outside normal PeopleSoft job patterns. Victim-specific agent IDs and credentials are not public.1, 7 | 1, 7 |
| Host observables | meshctrl.js RunCommand execution, sshpass loops, reads of psappsrv.cfg and config.xml, /etc/hosts enumeration, mount queries, zstd compression, marker-file propagation, unexpected JSP/XML creation, and remote-management agent processes or persistence.1 | 1 |
| Network observables | Outbound WebSocket TLS to the C2 endpoint; Python SimpleHTTP on TCP 8888 at staging IPs; outbound SMB TCP 445 from PeopleSoft hosts to untrusted internet destinations; internal SSH fanout; and outbound SSH to 176.120.22.24.1 | 1 |
- Actor / Label
- UNC6240
- Actor / Label
- ShinyHunters
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| UNC6240 | Mandiant/GTIG uncategorized cluster used to track extortion activity attributed in this campaign. The label reflects Google's analytical tracking and may evolve.1, 9 | 1, 9 |
| ShinyHunters | Extortion brand associated by GTIG with UNC6240 here; stolen organization data was published on the brand's DLS. Brand use does not prove one stable membership or operator for every claim.1, 9 | 1, 9 |
| Campaign operator | The exposed staging history supports campaign behavior and infrastructure ownership assessments, but it does not publish a natural-person identity, location, or complete organization chart.1 | 1 |
| Victim-side unknown third party | NAIC describes an unknown third party and separates public campaign reporting from its own verified impact. Preserve that direct-disclosure wording when discussing NAIC.7 | 7 |
- Audience
- Executive team
- Audience
- SOC / DFIR
- Decision-ready Point
- Start with exact published IOCs and behaviors, then correlate web, network, host, identity, storage, database, and integration telemetry. Absence of listed IOCs does not exclude changed infrastructure.1
- Sources
- 1
- Audience
- U.S. SMB owner
- Audience
- MSP / service provider
- Audience
- Counsel / privacy
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executive team | This is known zero-day exploitation of a business-data control plane; closure requires patch evidence, historical hunting, and a decision on connected trust—not a vulnerability ticket alone.1, 2, 3 | 1, 2, 3 |
| SOC / DFIR | Start with exact published IOCs and behaviors, then correlate web, network, host, identity, storage, database, and integration telemetry. Absence of listed IOCs does not exclude changed infrastructure.1 | 1 |
| U.S. SMB owner | Ask payroll, HR, education, insurer, MSP, and administrative providers whether your data touched an affected instance and request per-instance patch and investigation evidence.1, 7, 8 | 1, 7, 8 |
| MSP / service provider | Maintain tenant-specific exposure, credentials, indicators, data, notification, and closure records; one customer's evidence cannot establish another's status.1, 3 | 1, 3 |
| Counsel / privacy | Differentiate attempted exploit, unauthorized access, acquired data, published data, and actor claims. Direct organization findings control notices and representations.1, 7 | 1, 7 |
| Insurance | Preserve dates, logs, version and mitigation proof, affected services, restoration decisions, vendor communications, expenses, and notification analysis; avoid overstating unverified actor volumes.3, 7 | 3, 7 |
Leadership closure should be expressed as decisions with accountable owners and proof, not as a list of technical tasks completed in isolation.
- Decision
- Can each PeopleSoft service remain reachable?
- Accountable Owner
- Business executive with application and security leads
- Decision
- Which instances enter formal incident response?
- Accountable Owner
- Incident commander
- Decision
- Which credentials and connected systems must be revoked, rotated, or rebuilt?
- Accountable Owner
- Identity, infrastructure, database, and application owners
- Decision
- What data was accessible, acquired, or published?
- Accountable Owner
- Privacy, legal, records, and data owners
- Decision
- Which customers, employees, students, providers, or regulators require communication?
- Accountable Owner
- Legal, communications, HR, vendor management, and leadership
- Decision
- What insurer or law-enforcement coordination is required?
- Accountable Owner
- Risk, counsel, finance, and incident leadership
- Decision
- When is the event closed?
- Accountable Owner
- Executive risk owner
| Decision | Accountable Owner | Closure Evidence |
|---|---|---|
| Can each PeopleSoft service remain reachable? | Business executive with application and security leads | Instance-level exposure, mitigation, hunt, integrity, continuity, and exception record.1, 2, 3 |
| Which instances enter formal incident response? | Incident commander | Historical reachability plus suspicious request, file, process, network, identity, or storage evidence and documented classification.1, 3 |
| Which credentials and connected systems must be revoked, rotated, or rebuilt? | Identity, infrastructure, database, and application owners | Trust map tied to plausible attacker access, rotation results, session revocation, integrity validation, and known-good recovery state.1, 7 |
| What data was accessible, acquired, or published? | Privacy, legal, records, and data owners | Schema, query, export, file, storage, and egress evidence with affected-person analysis and explicit unknowns.1, 7 |
| Which customers, employees, students, providers, or regulators require communication? | Legal, communications, HR, vendor management, and leadership | Audience-specific fact record, contractual and statutory analysis, approved language, timing, and delivery evidence.1, 7 |
| What insurer or law-enforcement coordination is required? | Risk, counsel, finance, and incident leadership | Policy notice, preserved chronology, expenses, vendor records, law-enforcement contacts, and statements limited to verified facts.3, 7 |
| When is the event closed? | Executive risk owner | Mitigation verified, historical hunt adjudicated, trust recovered, impact assessed, notifications completed, monitoring active, and residual risk accepted.1, 2, 3 |
- Technology / Trust Path
- PSEMHUB web tier
- Technology / Trust Path
- PeopleSoft configuration
- Risk / Defensive Priority
- psappsrv.cfg, config.xml, mounts, and /etc/hosts exposed application topology and internal targets, enabling more precise lateral movement.1
- Sources
- 1
- Technology / Trust Path
- SSH and service trust
- Risk / Defensive Priority
- Credential spraying and key fallback can turn shared or weak administrative credentials into application-tier fanout across nodes.1
- Sources
- 1
- Technology / Trust Path
- HR, payroll, finance, and student data
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| PSEMHUB web tier | Unauthenticated HTTP/HTTPS takeover places an administrative component at the initial-access boundary; historical reachability and unexpected web-tier artifacts are decisive.1, 2 | 1, 2 |
| PeopleSoft configuration | psappsrv.cfg, config.xml, mounts, and /etc/hosts exposed application topology and internal targets, enabling more precise lateral movement.1 | 1 |
| SSH and service trust | Credential spraying and key fallback can turn shared or weak administrative credentials into application-tier fanout across nodes.1 | 1 |
| HR, payroll, finance, and student data | PeopleSoft deployments may concentrate regulated and business-critical records; actual schemas, exports, and downstream stores determine impact.1, 7, 8 | 1, 7, 8 |
| Storage and integrations | NAIC's confirmed temporary storage access shows compromise can extend beyond the PeopleSoft database into connected data areas.7 | 7 |
| SMB and provider dependency | Hosted or shared PeopleSoft can create indirect exposure across employers, customers, students, regulators, and vendors even when an SMB runs no local instance.1, 7 | 1, 7 |
Every tier is shown separately. A tier records the research lane and evidence boundary; a retained row does not make all sources equally authoritative.
- Tier
- Tier 0
- Retained Evidence
- Mandiant/GTIG, Oracle, CISA, NVD
- Tier
- Tier 1
- Retained Evidence
- ZDI, MITRE CWE, NAIC
- Tier
- Tier 2
- Retained Evidence
- Oracle documentation and Google naming guidance
- Tier
- Tier 3
- Retained Evidence
- MITRE ATT&CK T1190 taxonomy
- Use / Boundary
- Corroborating behavior vocabulary only; news rewrites add no controlling facts.10
- Tier
- Tier 4
- Retained Evidence
- ATT&CK T1219 and checked community leads
- Use / Boundary
- Remote-tool taxonomy and discovery; unverified social claims not promoted.11
- Tier
- Tier 5
- Retained Evidence
- No custom source supplied
- Use / Boundary
- Explicitly unused; no private evidence or requester assertion added.12
- Tier
- Tier 6
- Retained Evidence
- No keyed integration used
- Use / Boundary
- Explicitly unused; no credentialed telemetry or secrets accessed.13
- Tier
- Tier 7
- Retained Evidence
- ATT&CK archive taxonomy through linked discovery
- Use / Boundary
- Supports an observed zstd behavior mapping, not independent campaign confirmation.14
- Tier
- Tier 8
- Retained Evidence
- Expansion ATT&CK hypothesis and direct Nottingham notice
| Tier | Retained Evidence | Use / Boundary |
|---|---|---|
| Tier 0 | Mandiant/GTIG, Oracle, CISA, NVD | Campaign mechanics, product scope, KEV, scoring, and IOCs; controlling evidence.1, 2, 3, 4 |
| Tier 1 | ZDI, MITRE CWE, NAIC | Technical disclosure, weakness definition, and direct victim impact; each stays within source visibility.5, 6, 7 |
| Tier 2 | Oracle documentation and Google naming guidance | Product and attribution context; not new campaign telemetry.8, 9 |
| Tier 3 | MITRE ATT&CK T1190 taxonomy | Corroborating behavior vocabulary only; news rewrites add no controlling facts.10 |
| Tier 4 | ATT&CK T1219 and checked community leads | Remote-tool taxonomy and discovery; unverified social claims not promoted.11 |
| Tier 5 | No custom source supplied | Explicitly unused; no private evidence or requester assertion added.12 |
| Tier 6 | No keyed integration used | Explicitly unused; no credentialed telemetry or secrets accessed.13 |
| Tier 7 | ATT&CK archive taxonomy through linked discovery | Supports an observed zstd behavior mapping, not independent campaign confirmation.14 |
| Tier 8 | Expansion ATT&CK hypothesis and direct Nottingham notice | Adds bounded exfiltration hunting and victim impact while preserving attribution separation.15, 16 |
- Issue
- Observed window versus current risk
- Issue
- Notifications versus victims
- How IntelliOS Handles It
- >100 and 68% higher education describe potentially vulnerable endpoints notified by GTIG. Only some were stated to be compromised; no complete confirmed-victim count is public.1
- Sources
- 1
- Issue
- Affected versus fixed versions
- How IntelliOS Handles It
- Oracle publicly names affected supported branches 8.61 and 8.62 and links patch documentation behind customer support. This brief does not manufacture fixed patch-level numbers.2
- Sources
- 2
- Issue
- UNC6240 and ShinyHunters
- Issue
- Stolen data versus actor claims
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| Observed window versus current risk | May 27–June 9 is GTIG's observed campaign window. It is not a global stop date; KEV and continuing patch obligations remain current.1, 3 | 1, 3 |
| Notifications versus victims | >100 and 68% higher education describe potentially vulnerable endpoints notified by GTIG. Only some were stated to be compromised; no complete confirmed-victim count is public.1 | 1 |
| Affected versus fixed versions | Oracle publicly names affected supported branches 8.61 and 8.62 and links patch documentation behind customer support. This brief does not manufacture fixed patch-level numbers.2 | 2 |
| UNC6240 and ShinyHunters | GTIG makes the campaign attribution. Direct victim disclosures may use different or no actor wording and control their own evidence boundaries.1, 7, 9 | 1, 7, 9 |
| Stolen data versus actor claims | GTIG confirms stolen-data publication for some organizations. NAIC confirms access but disputes claimed volume and had no confirmation of public release at its cutoff.1, 7 | 1, 7 |
| Ransomware field versus encryption | CISA marks known ransomware campaign use, while GTIG documents data theft and extortion. The field does not establish file encryption or a ransomware binary in this campaign.1, 3 | 1, 3 |
- Contributor
- Oracle Security
- Role in This Brief
- What They Do: develop PeopleSoft and publish authoritative product security alerts. Why They Matter Here: control affected supported versions, unauthenticated HTTP precondition, CVSS, impact, and customer mitigation. Evidence Boundary: Oracle does not publish campaign actors, IOCs, victims, or public patch-level numbers.2
- Sources
- 2
- Contributor
- Mandiant / Google Threat Intelligence Group
- Role in This Brief
- What They Do: investigate intrusions and publish threat intelligence. Why They Matter Here: control the observed campaign window, UNC6240 attribution, staging evidence, IOCs, behaviors, impacts, detections, and hardening guidance. Evidence Boundary: notification population is not a complete victim list, and visibility may not cover all activity.1
- Sources
- 1
- Contributor
- CISA
- Role in This Brief
- What They Do: maintain KEV and federal risk directives. Why They Matter Here: control the June 12 addition, June 15 due date, required action, BOD 26-04 reference, and ransomware field. Evidence Boundary: KEV does not prove local compromise or identify a specific victim.3
- Sources
- 3
- Contributor
- NIST National Vulnerability Database
- Role in This Brief
- What They Do: enrich public vulnerability records. Why They Matter Here: corroborate CNA scoring, CWE-306, CPE scope, change history, and KEV metadata. Evidence Boundary: NVD has no independent score or incident telemetry here.4
- Sources
- 4
- Contributor
- TrendAI Zero Day Initiative
- Role in This Brief
- What They Do: coordinate vulnerability research and publish technical advisories. Why They Matter Here: researchers received Oracle credit and ZDI later documented technical vulnerability context. Evidence Boundary: post-disclosure analysis does not establish campaign attribution or victim impact.2, 5
- Contributor
- National Association of Insurance Commissioners
- Role in This Brief
- What They Do: support U.S. state insurance regulators and standards. Why They Matter Here: provide a direct, named organization disclosure of PeopleSoft and temporary storage access. Evidence Boundary: NAIC controls only its incident and explicitly disputes unverified actor volume claims.7
- Sources
- 7
- Contributor
- MITRE CWE and ATT&CK
| Contributor | Role in This Brief | Sources |
|---|---|---|
| Oracle Security | What They Do: develop PeopleSoft and publish authoritative product security alerts. Why They Matter Here: control affected supported versions, unauthenticated HTTP precondition, CVSS, impact, and customer mitigation. Evidence Boundary: Oracle does not publish campaign actors, IOCs, victims, or public patch-level numbers.2 | 2 |
| Mandiant / Google Threat Intelligence Group | What They Do: investigate intrusions and publish threat intelligence. Why They Matter Here: control the observed campaign window, UNC6240 attribution, staging evidence, IOCs, behaviors, impacts, detections, and hardening guidance. Evidence Boundary: notification population is not a complete victim list, and visibility may not cover all activity.1 | 1 |
| CISA | What They Do: maintain KEV and federal risk directives. Why They Matter Here: control the June 12 addition, June 15 due date, required action, BOD 26-04 reference, and ransomware field. Evidence Boundary: KEV does not prove local compromise or identify a specific victim.3 | 3 |
| NIST National Vulnerability Database | What They Do: enrich public vulnerability records. Why They Matter Here: corroborate CNA scoring, CWE-306, CPE scope, change history, and KEV metadata. Evidence Boundary: NVD has no independent score or incident telemetry here.4 | 4 |
| TrendAI Zero Day Initiative | What They Do: coordinate vulnerability research and publish technical advisories. Why They Matter Here: researchers received Oracle credit and ZDI later documented technical vulnerability context. Evidence Boundary: post-disclosure analysis does not establish campaign attribution or victim impact.2, 5 | 2, 5 |
| National Association of Insurance Commissioners | What They Do: support U.S. state insurance regulators and standards. Why They Matter Here: provide a direct, named organization disclosure of PeopleSoft and temporary storage access. Evidence Boundary: NAIC controls only its incident and explicitly disputes unverified actor volume claims.7 | 7 |
| MITRE CWE and ATT&CK | What They Do: maintain weakness and behavior taxonomies. Why They Matter Here: define CWE-306 and provide bounded technique mappings. Evidence Boundary: taxonomy is not campaign evidence and should not be treated as proof of an unobserved technique.6, 10, 11, 12, 13, 14, 15 | 6, 10, 11, 12, 13, 14, 15 |
These examples translate the campaign record into concrete defensive lessons without treating exposure leads or adversary claims as verified organization impact.
- Observed Example
- Five sequential staging hosts exposed directories and identical command history on TCP 8888.
- Decision Lesson
- Open adversary infrastructure can produce unusually rich point-in-time IOCs, command evidence, and detection ideas.
- Evidence Boundary
- Infrastructure may be abandoned or reassigned; match timestamps and ownership before blocking or attributing.1
- Observed Example
- Customized MeshCentral agents masqueraded as Azure services and used a hardcoded WebSocket C2 endpoint.
- Decision Lesson
- Legitimate remote-management tooling becomes malicious through unauthorized deployment, configuration, and operator use.
- Evidence Boundary
- MeshCentral presence alone is not an IOC; use hashes, endpoint, path, service, process, and authorization context.1
- Observed Example
- A victim-specific shell script parsed internal hosts, sprayed SSH credentials, and copied an extortion marker into multiple PeopleSoft directories.
- Decision Lesson
- One compromised application node can fan out through shared accounts and predictable administrative topology.
- Evidence Boundary
- The public script is redacted and victim-specific credentials and agent IDs are unavailable.1
- Observed Example
- NAIC confirmed that PeopleSoft access enabled temporary access to certain storage areas, which was then blocked.
- Decision Lesson
- Enterprise-app triage must extend into attached storage, credentials, automation, and data flows rather than stop at the web tier.
- Evidence Boundary
- NAIC disputed the actor's claimed volume and had no confirmed public data release at its June 23 cutoff.7
- Observed Example
- GTIG warned more than 100 potentially exposed organizations; some blocked activity, while others experienced compromise and publication.
- Decision Lesson
- Rapid notification and endpoint restriction can materially change outcomes during an exploitation window.
- Evidence Boundary
- Notification counts and education concentration do not equal confirmed victim or compromise counts.1
| Observed Example | Decision Lesson | Evidence Boundary |
|---|---|---|
| Five sequential staging hosts exposed directories and identical command history on TCP 8888. | Open adversary infrastructure can produce unusually rich point-in-time IOCs, command evidence, and detection ideas. | Infrastructure may be abandoned or reassigned; match timestamps and ownership before blocking or attributing.1 |
| Customized MeshCentral agents masqueraded as Azure services and used a hardcoded WebSocket C2 endpoint. | Legitimate remote-management tooling becomes malicious through unauthorized deployment, configuration, and operator use. | MeshCentral presence alone is not an IOC; use hashes, endpoint, path, service, process, and authorization context.1 |
| A victim-specific shell script parsed internal hosts, sprayed SSH credentials, and copied an extortion marker into multiple PeopleSoft directories. | One compromised application node can fan out through shared accounts and predictable administrative topology. | The public script is redacted and victim-specific credentials and agent IDs are unavailable.1 |
| NAIC confirmed that PeopleSoft access enabled temporary access to certain storage areas, which was then blocked. | Enterprise-app triage must extend into attached storage, credentials, automation, and data flows rather than stop at the web tier. | NAIC disputed the actor's claimed volume and had no confirmed public data release at its June 23 cutoff.7 |
| GTIG warned more than 100 potentially exposed organizations; some blocked activity, while others experienced compromise and publication. | Rapid notification and endpoint restriction can materially change outcomes during an exploitation window. | Notification counts and education concentration do not equal confirmed victim or compromise counts.1 |
Only explicitly public vendor or organization disclosures belong here. The rows below describe the public record and do not represent an affected-party list.
- Disclosure / Affected Set
- GTIG notification population
- Disclosure Boundary
- More than 100 potentially vulnerable organizations were notified; most were in the United States and 68% were higher education. This is exposure-notification telemetry, not a confirmed-victim census.1
- Sources
- 1
- Disclosure / Affected Set
- GTIG confirmed campaign outcomes
- Disclosure Boundary
- Some organizations blocked or remediated activity; others experienced compromise and stolen-data publication. The public report does not enumerate every organization or quantify all stolen data.1
- Sources
- 1
- Disclosure / Affected Set
- NAIC
- Disclosure Boundary
- Directly confirmed unauthorized PeopleSoft access identified June 11 and temporary access to certain storage areas. Access was blocked and remediated; investigation and FBI coordination continued. NAIC disputed the claimed data volume and had no confirmed public release as of June 23.7
- Sources
- 7
- Disclosure / Affected Set
- University of Nottingham
- Disclosure Boundary
- The university publicly confirmed significant unauthorized access to student-record data, but its direct notice did not itself establish PeopleSoft or actor attribution. Retain the institutional data-impact statement separately from GTIG's broader campaign assessment.16
- Sources
- 16
- Disclosure / Affected Set
- Other named or alleged victims
| Disclosure / Affected Set | Disclosure Boundary | Sources |
|---|---|---|
| GTIG notification population | More than 100 potentially vulnerable organizations were notified; most were in the United States and 68% were higher education. This is exposure-notification telemetry, not a confirmed-victim census.1 | 1 |
| GTIG confirmed campaign outcomes | Some organizations blocked or remediated activity; others experienced compromise and stolen-data publication. The public report does not enumerate every organization or quantify all stolen data.1 | 1 |
| NAIC | Directly confirmed unauthorized PeopleSoft access identified June 11 and temporary access to certain storage areas. Access was blocked and remediated; investigation and FBI coordination continued. NAIC disputed the claimed data volume and had no confirmed public release as of June 23.7 | 7 |
| University of Nottingham | The university publicly confirmed significant unauthorized access to student-record data, but its direct notice did not itself establish PeopleSoft or actor attribution. Retain the institutional data-impact statement separately from GTIG's broader campaign assessment.16 | 16 |
| Other named or alleged victims | Not included without a stable direct disclosure or authoritative campaign-level confirmation. Leak-site listings and social claims are leads, not sufficient organization-specific evidence.1, 7 | 1, 7 |
| U.S. SMB downstream parties | No complete public list exists. SMBs should query providers and partners using PeopleSoft and record whether their own data, credentials, or services were in scope.1, 7, 8 | 1, 7, 8 |
- Item
- CVE-2026-35273
- Item
- Affected versions
- Item
- Fixed / mitigated versions
- Status / Meaning
- Oracle released the June 10 Security Alert and links customer patch documents for 8.61 and 8.62. Exact fixed patch-level numbers are not public on the advisory; verify the applicable patch and successful installation in My Oracle Support. Disable/remove or restrict EMHub/PSEMHUB as directed when patching is incomplete.1, 2
- Item
- CVSS v3.1 — 9.8 Critical
- Item
- CWE-306
- Item
- CISA KEV
- Item
- Public exploit status
| Item | Status / Meaning | Sources |
|---|---|---|
| CVE-2026-35273 | Missing Authentication for Critical Function in PeopleSoft Enterprise PeopleTools Updates Environment Management; unauthenticated HTTP access can lead to takeover and remote code execution.2, 4, 6 | 2, 4, 6 |
| Affected versions | Supported PeopleTools 8.61 and 8.62. Oracle says earlier unsupported releases are likely affected but were not tested; upgrade to a supported release before applying available mitigation.2, 4 | 2, 4 |
| Fixed / mitigated versions | Oracle released the June 10 Security Alert and links customer patch documents for 8.61 and 8.62. Exact fixed patch-level numbers are not public on the advisory; verify the applicable patch and successful installation in My Oracle Support. Disable/remove or restrict EMHub/PSEMHUB as directed when patching is incomplete.1, 2 | 1, 2 |
| CVSS v3.1 — 9.8 Critical | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It measures base technical severity, not local exposure, exploitation success, data scope, or business loss; NVD had no independent NIST score.2, 4 | 2, 4 |
| CWE-306 | CISA-ADP assigns Missing Authentication for Critical Function. This class does not disclose the exploit payload, HTTP body, vulnerable method, or persistence mechanism.4, 6 | 4, 6 |
| CISA KEV | Added June 12, 2026; due June 15; required action is vendor mitigation plus applicable BOD 26-04 forensic triage. Known ransomware campaign use is marked Known.3, 4 | 3, 4 |
| Public exploit status | No retained primary source establishes a complete public proof-of-concept release. The campaign's observed exploitation and public technical indicators make PoC status irrelevant to urgency; this is an evidence boundary, not proof code is unavailable anywhere.1, 2, 3, 4, 5 | 1, 2, 3, 4, 5 |
This lifecycle view orders confirmed behaviors and carefully labeled hunt hypotheses. Technique identifiers organize telemetry; they do not expand the observed record.
- Lifecycle Phase
- Initial access — T1190
- Campaign Evidence
- Observed exploitation of externally reachable PSEMHUB endpoints through the unauthenticated PeopleTools flaw.
- Lifecycle Phase
- Command and control — T1219
- Campaign Evidence
- Customized MeshCentral agents connected to a hardcoded WebSocket endpoint and supported remote command execution.
- Lifecycle Phase
- Discovery — T1016 and configuration discovery
- Campaign Evidence
- Commands inspected mounts, /etc/hosts, psappsrv.cfg, and WebLogic config.xml to identify application nodes and topology.
- Lifecycle Phase
- Credential access / lateral movement — T1110
- Campaign Evidence
- The fanout script sprayed common credentials over SSH, tried key fallback, and copied the extortion marker across PeopleSoft nodes.
- Lifecycle Phase
- Collection — T1560
- Campaign Evidence
- Operators compressed an exfil directory into exfil.tar.zst using zstd and monitored progress.
- Lifecycle Phase
- Exfiltration / impact
- Campaign Evidence
- GTIG confirms stolen data and DLS publication for some organizations; exact transfer paths for every archive are not public.
| Lifecycle Phase | Campaign Evidence | Defender Telemetry / Limit |
|---|---|---|
| Initial access — T1190 | Observed exploitation of externally reachable PSEMHUB endpoints through the unauthenticated PeopleTools flaw. | PIA/WebLogic, reverse proxy, WAF, load balancer, endpoint URL, source, timing, response, and follow-on host evidence.1, 2, 10 |
| Command and control — T1219 | Customized MeshCentral agents connected to a hardcoded WebSocket endpoint and supported remote command execution. | DNS, TLS, process ancestry, service installation, agent configuration, WebSocket sessions, and published hashes; legitimate MeshCentral use requires context.1, 11 |
| Discovery — T1016 and configuration discovery | Commands inspected mounts, /etc/hosts, psappsrv.cfg, and WebLogic config.xml to identify application nodes and topology. | Shell history, EDR command lines, file auditing, process access, unusual reads by the PeopleSoft service context, and remote-command logs.1, 13 |
| Credential access / lateral movement — T1110 | The fanout script sprayed common credentials over SSH, tried key fallback, and copied the extortion marker across PeopleSoft nodes. | SSH authentication failures and success, sshpass execution, new keys, internal fanout, remote file creation, and service-account anomalies.1, 12 |
| Collection — T1560 | Operators compressed an exfil directory into exfil.tar.zst using zstd and monitored progress. | Archive creation, file reads, zstd and pv execution, disk growth, staging directories, parent process, and subsequent network transfer.1, 14 |
| Exfiltration / impact | GTIG confirms stolen data and DLS publication for some organizations; exact transfer paths for every archive are not public. | Network egress, storage access, database exports, archive movement, DLS evidence, marker files, extortion communications, and direct victim findings.1, 7, 15 |
Weight follows claim type, not a universal publisher ranking. Product, campaign, government, victim, and taxonomy sources retain separate authority boundaries.
- Source Class
- Oracle vendor advisory
- Controlling Use
- Highest for affected supported versions, preconditions, severity, impact, and mitigation.
- Boundary
- Does not control actor attribution, campaign IOCs, or local compromise.2
- Source Class
- Mandiant / GTIG campaign research
- Controlling Use
- Highest for observed window, UNC6240 attribution, infrastructure, files, hashes, commands, detections, and outcomes.
- Boundary
- Visibility is not a universal victim census and indicators are point-in-time.1
- Source Class
- CISA and NVD
- Controlling Use
- Highest for KEV status, deadline, required action, registry history, SSVC, CVSS provenance, and CWE assignment.
- Source Class
- Direct organization disclosures
- Controlling Use
- Highest for that organization's access, containment, data, investigation, and uncertainty statements.
- Source Class
- MITRE CWE / ATT&CK
- Controlling Use
- High for common weakness and behavior vocabulary used in analysis and hunting.
- Source Class
- Community, social, and secondary reporting
- Controlling Use
- Useful for discovery and corroboration leads only.
| Source Class | Controlling Use | Boundary |
|---|---|---|
| Oracle vendor advisory | Highest for affected supported versions, preconditions, severity, impact, and mitigation. | Does not control actor attribution, campaign IOCs, or local compromise.2 |
| Mandiant / GTIG campaign research | Highest for observed window, UNC6240 attribution, infrastructure, files, hashes, commands, detections, and outcomes. | Visibility is not a universal victim census and indicators are point-in-time.1 |
| CISA and NVD | Highest for KEV status, deadline, required action, registry history, SSVC, CVSS provenance, and CWE assignment. | Catalog records do not establish an organization's incident or business loss.3, 4 |
| Direct organization disclosures | Highest for that organization's access, containment, data, investigation, and uncertainty statements. | Cannot be generalized to every PeopleSoft user or used alone for campaign attribution.7, 16 |
| MITRE CWE / ATT&CK | High for common weakness and behavior vocabulary used in analysis and hunting. | Taxonomy is not proof that an issue-specific action occurred unless campaign evidence shows it.6, 10, 11, 14, 15 |
| Community, social, and secondary reporting | Useful for discovery and corroboration leads only. | Not promoted when it duplicates primary material or lacks stable source-backed detail.1, 7 |
Published research notes
Public, read-only, source-backed context retained with this brief. No account or sign-in is required.
Confirmed facts
Zero-day exploitation window, campaign attribution, affected releases, CVSS, KEV, C2 infrastructure, hashes, behaviors, and direct NAIC impact are source facts within each publisher's visibility.1, 2, 3, 4, 7
Assessment
Supply-chain reach, SMB prioritization, trust-restoration scope, and ATT&CK mappings are defensive assessments based on source-described capability and architecture; they are not additional observed impacts.1, 7, 10
Unknowns
Complete victim count, victim-specific agent IDs, exploit payload, all exfiltration channels, all stolen datasets, exact public fixed patch levels, and full operator identity remain unavailable in retained public sources.1, 2, 7
IOC use
Published infrastructure and hashes are campaign-specific and point-in-time. Match quality depends on timestamps, prevalence, authorization, and surrounding behavior; absence does not rule out changed infrastructure.1
- #
- 1
- Tier
- Tier 0 - Most Trusted
- Publisher
- Mandiant / Google Threat Intelligence Group
- Published
- Jun 11, 2026
- Why Used
- Controlling campaign source for attribution, window, notification population, impact, infrastructure, agents, hashes, commands, detection, and hardening.
- #
- 2
- Tier
- Tier 0 - Most Trusted
- Publisher
- Oracle
- Published
- Jun 10, 2026
- Why Used
- Controls affected supported versions, component, unauthenticated HTTP precondition, CVSS, impact, and official mitigation path.
- #
- 3
- Tier
- Tier 0 - Most Trusted
- Publisher
- CISA
- Published
- Added Jun 12, 2026
- Why Used
- Controls KEV date, June 15 due date, required action, forensic-triage reference, and ransomware-use field.
- #
- 4
- Tier
- Tier 0 - Most Trusted
- Publisher
- NIST NVD
- Published
- Jun 11; modified Jul 23, 2026
- Why Used
- Corroborates CNA description, affected configurations, CVSS provenance, CWE-306, SSVC, and KEV history.
- Source
- CVE-2026-35273
- #
- 5
- Tier
- Tier 1 - Authoritative
- Publisher
- TrendAI Zero Day Initiative
- Published
- Jun 24, 2026
- Why Used
- Technical vulnerability and coordinated-disclosure context from researchers credited by Oracle; not campaign attribution evidence.
- #
- 6
- Tier
- Tier 1 - Authoritative
- Publisher
- MITRE CWE
- Published
- Checked Aug 9, 2026
- Why Used
- Defines the assigned weakness and its interpretation limits.
- #
- 7
- Tier
- Tier 1 - Authoritative
- Publisher
- National Association of Insurance Commissioners
- Published
- Updated Jun 23, 2026
- Why Used
- Direct named disclosure controlling NAIC access, containment, storage reach, investigation, and actor-claim boundaries.
- Source
- Security Update
- #
- 8
- Tier
- Tier 2 - High-Value Research
- Publisher
- Oracle Documentation
- Published
- Checked Aug 9, 2026
- Why Used
- Authoritative product context for PeopleSoft administrative and enterprise-application roles; not campaign telemetry.
- #
- 9
- Tier
- Tier 2 - High-Value Research
- Publisher
- Google Threat Intelligence
- Published
- Apr 2, 2025
- Why Used
- Explains UNC cluster naming and why source-specific actor labels require attribution discipline.
- #
- 10
- Tier
- Tier 3 - Corroborating News
- Publisher
- MITRE ATT&CK
- Published
- Checked Aug 9, 2026
- Why Used
- Taxonomy-only corroboration for the observed initial-access behavior.
- #
- 11
- Tier
- Tier 4 - Community Signal
- Publisher
- MITRE ATT&CK
- Published
- Checked Aug 9, 2026
- Why Used
- Taxonomy-only mapping for customized MeshCentral use; community claims were not promoted.
- #
- 12
- Tier
- Tier 5 - Custom Source
- Publisher
- No custom source supplied
- Published
- Aug 9, 2026 cutoff
- Why Used
- No private custom source was supplied; the row preserves explicit Tier 5 disposition without adding evidence.
- Source
- Public-source boundary
- #
- 13
- Tier
- Tier 6 - Custom Integrations with API/Keys
- Publisher
- No keyed integration used
- Published
- Aug 9, 2026 cutoff
- Why Used
- No private API, credentialed telemetry, or integration-only claim was used; the row records the Tier 6 boundary.
- Source
- Public-source boundary
- #
- 14
- Tier
- Tier 7 - Inner Discovery
- Publisher
- MITRE ATT&CK
- Published
- Checked Aug 9, 2026
- Why Used
- Linked taxonomy discovery for observed zstd compression; not independent campaign evidence.
- #
- 15
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Publisher
- MITRE ATT&CK
- Published
- Checked Aug 9, 2026
- Why Used
- Expansion-research hunt hypothesis; the report confirms theft but not this transfer path for every archive.
- #
- 16
- Tier
- Tier 8 - Expansion Research / AI Agent Delta
- Publisher
- University of Nottingham Students' Union
- Published
- Jun 12, 2026
- Why Used
- Public institutional disclosure confirming significant student-record access; does not independently establish PeopleSoft or actor attribution.
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 - Most Trusted | Mandiant / Google Threat Intelligence Group | Jun 11, 2026 | Controlling campaign source for attribution, window, notification population, impact, infrastructure, agents, hashes, commands, detection, and hardening. | ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit |
| 2 | Tier 0 - Most Trusted | Oracle | Jun 10, 2026 | Controls affected supported versions, component, unauthenticated HTTP precondition, CVSS, impact, and official mitigation path. | Oracle Security Alert Advisory — CVE-2026-35273 |
| 3 | Tier 0 - Most Trusted | CISA | Added Jun 12, 2026 | Controls KEV date, June 15 due date, required action, forensic-triage reference, and ransomware-use field. | Known Exploited Vulnerabilities Catalog — CVE-2026-35273 |
| 4 | Tier 0 - Most Trusted | NIST NVD | Jun 11; modified Jul 23, 2026 | Corroborates CNA description, affected configurations, CVSS provenance, CWE-306, SSVC, and KEV history. | CVE-2026-35273 |
| 5 | Tier 1 - Authoritative | TrendAI Zero Day Initiative | Jun 24, 2026 | Technical vulnerability and coordinated-disclosure context from researchers credited by Oracle; not campaign attribution evidence. | ZDI-26-388: Oracle PeopleSoft HubMBeanPersistance Deserialization RCE |
| 6 | Tier 1 - Authoritative | MITRE CWE | Checked Aug 9, 2026 | Defines the assigned weakness and its interpretation limits. | CWE-306: Missing Authentication for Critical Function |
| 7 | Tier 1 - Authoritative | National Association of Insurance Commissioners | Updated Jun 23, 2026 | Direct named disclosure controlling NAIC access, containment, storage reach, investigation, and actor-claim boundaries. | Security Update |
| 8 | Tier 2 - High-Value Research | Oracle Documentation | Checked Aug 9, 2026 | Authoritative product context for PeopleSoft administrative and enterprise-application roles; not campaign telemetry. | PeopleSoft Enterprise Applications and PeopleTools |
| 9 | Tier 2 - High-Value Research | Google Threat Intelligence | Apr 2, 2025 | Explains UNC cluster naming and why source-specific actor labels require attribution discipline. | Updated Cyber Threat Actor Naming System |
| 10 | Tier 3 - Corroborating News | MITRE ATT&CK | Checked Aug 9, 2026 | Taxonomy-only corroboration for the observed initial-access behavior. | T1190: Exploit Public-Facing Application |
| 11 | Tier 4 - Community Signal | MITRE ATT&CK | Checked Aug 9, 2026 | Taxonomy-only mapping for customized MeshCentral use; community claims were not promoted. | T1219: Remote Access Software |
| 12 | Tier 5 - Custom Source | No custom source supplied | Aug 9, 2026 cutoff | No private custom source was supplied; the row preserves explicit Tier 5 disposition without adding evidence. | Public-source boundary |
| 13 | Tier 6 - Custom Integrations with API/Keys | No keyed integration used | Aug 9, 2026 cutoff | No private API, credentialed telemetry, or integration-only claim was used; the row records the Tier 6 boundary. | Public-source boundary |
| 14 | Tier 7 - Inner Discovery | MITRE ATT&CK | Checked Aug 9, 2026 | Linked taxonomy discovery for observed zstd compression; not independent campaign evidence. | T1560: Archive Collected Data |
| 15 | Tier 8 - Expansion Research / AI Agent Delta | MITRE ATT&CK | Checked Aug 9, 2026 | Expansion-research hunt hypothesis; the report confirms theft but not this transfer path for every archive. | T1041: Exfiltration Over C2 Channel |
| 16 | Tier 8 - Expansion Research / AI Agent Delta | University of Nottingham Students' Union | Jun 12, 2026 | Public institutional disclosure confirming significant student-record access; does not independently establish PeopleSoft or actor attribution. | University of Nottingham Data Breach |
- Version
- v1.0
- Date
- Aug 9, 2026
- Changes
- Initial 32-card Flash publication. Establishes the confirmed May 27–June 9 exploitation window, Oracle and CISA status, UNC6240/ShinyHunters attribution, exact public campaign IOCs, observed data-theft and extortion impacts, direct disclosure boundaries, and evidence-led U.S. SMB/MSP response.
| Version | Date | Changes |
|---|---|---|
| v1.0 | Aug 9, 2026 | Initial 32-card Flash publication. Establishes the confirmed May 27–June 9 exploitation window, Oracle and CISA status, UNC6240/ShinyHunters attribution, exact public campaign IOCs, observed data-theft and extortion impacts, direct disclosure boundaries, and evidence-led U.S. SMB/MSP response. |
