INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 6/11/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9.8) in the E…
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
sha256:a3807de02d8ea0e4986ea934df53c1a7c25dd1e73f09a45ae79467df067af100
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| meshagent32-azure-ops.exe |
| Open → |
| domain | meshagent64-azure-ops.exe | Open → |
| domain | meshagent64-v2.exe | Open → |
| domain | azurenetfiles.net | Open → |
| domain | agent.ashx | Open → |
| domain | psappsrv.cfg | Open → |
| domain | readme-if-you-see-this-youve-been-hacked.txt | Open → |
| domain | exfil.tar.zst | Open → |
| domain | psemhub.war | Open → |
| sha256 | 2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35 | Open → |
| sha256 | f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc | Open → |
| sha256 | d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f | Open → |
| sha256 | c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f | Open → |
| sha256 | 68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309 | Open → |
| cve | CVE-2026-35273 | Open → |