ShinyHunters has launched a renewed mass-exploitation campaign targeting Oracle PeopleSoft systems, with Google notifying more than 100 organisations worldwide about attacks involving a previously exploited critical vulnerability.
The campaign is targeting systems that were not fully patched. Researchers said attackers are bypassing web application firewall protections, deploying web shells and using a newly identified backdoor called SIDEEYE on compromised Windows PeopleSoft servers.
What Is the PeopleSoft Vulnerability?
The attacks involve CVE-2026-35273, a critical Oracle PeopleSoft vulnerability that had previously been exploited in June.
Google said it had notified more than 100 organisations worldwide about renewed exploitation of the flaw. The latest activity is linked to ShinyHunters, tracked as UNC6240.
The campaign appears to focus particularly on organisations that relied on mitigation guidance but did not fully patch the vulnerable PeopleSoft platform.
How Are Hackers Bypassing Firewalls?
Some organisations had adjusted their web application firewall, or WAF, rules as a temporary measure instead of applying a permanent patch.
Google researchers said the attackers have adapted their methods to bypass those protections. The group is modifying its exploit to get around WAF rules designed to block access to the vulnerable PeopleSoft Environment Management Hub endpoint.
Researchers observed a consistent attack sequence beginning with discovery and verification before progressing to web shell deployment and direct activity by the attackers.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Who Has Been Targeted?
Google researchers said dozens of systems around the world have had web shells deployed.
The affected organisations span several sectors, including technology, IT services, healthcare, agriculture, transportation and government. Universities were also among the targets.
The scale and range of victims show that the campaign is not limited to a single industry.
Is the FBI Connected to the Attacks?
ShinyHunters has claimed that the FBI was among its latest victims and alleged that it exploited a newly discovered Oracle PeopleSoft zero-day.
However, it remained unclear whether the FBI had patched its systems or relied on the WAF workaround.
The FBI acknowledged the hackers’ claims and reported problems with several online portals. ShinyHunters also claimed it had stolen sensitive information concerning almost all FBI agents and employees.
The group said its actions were retaliation over an FBI advisory issued in May and demanded that the agency partially retract statements concerning the group’s behaviour. The hackers threatened retaliation if their demand was not met, but did not specify what that action would involve.
What Is the SIDEEYE Backdoor?
Google researchers also identified ShinyHunters deploying a new multi-stage backdoor named SIDEEYE during the attacks.
The malware is installed on compromised Windows PeopleSoft servers and communicates directly with command-and-control servers operated by the attackers.
Researchers said the attackers disguise the trojanised malware as a “Light Alloy” media player installer. It was digitally signed with a valid certificate to make it appear legitimate, although that certificate has since been revoked.
Once installed, SIDEEYE can steal credentials, manage files and processes, open a reverse shell and proxy network traffic. These capabilities can give attackers substantial control over an infected server.
What Should Organisations Do Now?
Google is urging defenders to patch CVE-2026-35273 and inspect PeopleSoft servers for web shells and the SIDEEYE backdoor.
Organisations are also being advised to rotate credentials that may have been exposed and examine their environments for network indicators associated with the campaign.
The renewed attacks highlight the danger of relying on temporary firewall rules instead of fixing the underlying vulnerability. In this campaign, attackers adapted their techniques specifically to bypass protections used by organisations that had not completed the patching process.
The420 Takeaway
The PeopleSoft campaign shows that a temporary security workaround cannot replace a permanent patch. Once attackers learn how organisations are blocking an exploit, they can change their methods and bypass those controls. Systems affected by CVE-2026-35273 require patching as well as checks for web shells, stolen credentials and the SIDEEYE backdoor.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics