ShinyHunters Relaunches Oracle PeopleSoft Exploitation Campaign
ShinyHunters, a notorious hacking group, is targeting organizations that have not fully patched their Oracle PeopleSoft systems. The group has been exploiting a zero-day vulnerability in the platform's Environment Management Hub (PSEMHUB) endpoint.
Google researchers reported that more than 100 organizations worldwide have been notified about the renewed exploitation of this critical flaw, identified as CVE-2026-35273. ShinyHunters is bypassing web application firewall rules on systems that were not fully patched.
The group has been deploying a new multi-stage backdoor in its attacks, dubbed SIDEEYE. This backdoor can steal credentials, manage files and processes, open a reverse shell, and proxy traffic. The hackers are disguising the trojanized malware as a 'Light Alloy' media player installer, digitally signed with a valid certificate to make it appear legitimate.
Google is urging defenders to review the Indicators of Compromise, detection guidance, and remediation steps provided in its report, including patching CVE-2026-35273, inspecting PeopleSoft servers for web shells/backdoor, rotating exposed credentials, and hunting for the campaign's network indicators.