ShinyHunters Identity Extortion, Oracle PeopleSoft Mass Exploitation, and Supply Chain Breaches Converge on the Healthcare Sector
Published September 30, 2026 | RedSheep Reports
Three distinct but overlapping attack patterns are hitting healthcare organizations simultaneously. ShinyHunters is running a sustained vishing and identity-access campaign that bypasses MFA and exfiltrates data from cloud SaaS platforms without encrypting anything[1]. The same actor cluster, tracked by Mandiant as UNC6240, renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft on September 25, using a WAF-evading URL-encoding bypass to reach systems that blocked only the literal exploit path [9][10]. Separately, traditional ransomware operators including Chaos and GENESIS are claiming healthcare victims [15][16], and supply chain compromises continue to cascade through vendor relationships, with Verizon's 2026 DBIR placing third-party involvement at 32% of healthcare breaches [12].
The combined picture: healthcare organizations face an identity-and-SaaS-access extortion model their ransomware recovery investments were not designed to address, an actively exploited zero-day in a widely deployed ERP platform, and a structural vendor-risk problem that turns single intrusions into multi-million-record exposures.
ShinyHunters: From Data Theft to Identity Extortion
ShinyHunters is not operating like a traditional ransomware group. Health-ISAC describes the operation as an identity- and SaaS-access extortion model [1]. Nothing gets encrypted. The group gains access to SSO platforms, pivots into connected cloud applications, exfiltrates data at scale, and then demands payment to prevent publication [3].
Health-ISAC issued a TLP:WHITE threat bulletin on August 28, 2026 (Alert ID 24113aee), warning that ShinyHunters was running persistent, highly targeted vishing campaigns against the global health sector using medical-themed impersonation domains. The bulletin reported several recent cases where the group successfully bypassed MFA to pivot from SSO platforms into connected cloud applications for large-scale data exfiltration. Health-ISAC had issued targeted alerts to multiple health sector organizations during the two weeks preceding that bulletin, after intelligence partners identified look-alike infrastructure.
The group's confirmed and claimed victims include McKesson, Medtronic, iRhythm, OneMedical, DentaQuest, AdaptHealth, and Him & Hers [3]. Germany's Fresenius Medical Care was listed on the ShinyHunters leak site on September 22, 2026 [8].
The Vishing Kill Chain: Reverse-Proxy MFA Bypass
The attack starts with reconnaissance. Actors research individual employees and the internal departments they plan to impersonate, most often the IT help desk or legal operations [1]. They then call employees directly on personal mobile devices using spoofed numbers, follow up with voicemails, and send mass emails from randomized accounts[2].
The lure directs targets to lookalike login pages. Health-ISAC identifies a signature pattern in the domain naming: domains use formats like company-claims[.]com or company[.]claims, incorporating the target company's name[2]. Mirage Security tracked 29 such .claims domains since late August, each hosting a cloned Okta login page behind Cloudflare [4]. By January 2026, security firms had counted over 100 organizations targeted by this operation [4].
The phishing pages run a real-time adversary-in-the-middle relay [4]. The kit forwards stolen credentials to the real corporate login portal, then prompts the victim over the phone to supply an active MFA token or approve a push notification, granting the attacker a live web session. Mirage Security's teardown of two captured kits confirmed the relay beats Okta Verify number matching: the page retrieves the live challenge digit from its server and displays it to the victim [4]. Every origin-bound factor (FastPass, security key, PIV/CAC) is rendered as a real option but deliberately fails. The operators disabled exactly the factors that cannot be relayed [4].
Once authenticated, attackers log into the organization's Okta, Microsoft Entra, or Google SSO dashboard and access all listed applications: Microsoft 365, Salesforce, Dropbox, Google Drive, SharePoint, and other third-party platforms [3]. Data is rapidly exfiltrated, and victims receive an extortion demand [3].
McKesson: The Largest Claimed Victim
McKesson detected an intrusion on August 25, 2026, per its SEC filing [6]. ShinyHunters claimed to have stolen 284 million patient records after vishing two employees and pulling data from the company's Salesforce and Snowflake environments [5][7]. The hackers demanded $55 million to prevent publication [5]. McKesson confirmed unauthorized access to third-party applications and exfiltration of data related to its oncology, multispecialty, and medical-surgical business units, but stated the investigation "is in its early stages" and had not determined materiality [6]. TechCrunch verified a small subset of the shared data samples against public records [5]. The 284 million figure and the $55 million demand remain unverified actor claims [7].
Astrana Health
Astrana Health reported in a Form 8-K dated September 22, 2026 that attackers impersonated staff and spoofed its main corporate phone number to trick employees into granting system access [14]. The company reset credentials, restricted remote access tools, and restored certain systems from clean backups [14]. No group had claimed the attack as of reporting [14].
CVE-2026-35273: Oracle PeopleSoft Mass Exploitation and WAF Bypass
CVE-2026-35273 is an unauthenticated SSRF-to-RCE vulnerability (CVSS 9.8) in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62, specifically the Environment Management Hub (PSEMHUB) component [11]. Oracle issued an out-of-band security alert and patch on June 10, 2026 [11]. The vulnerability was added to CISA KEV on June 12, 2026 [11]. Mandiant confirmed zero-day exploitation by UNC6240 (ShinyHunters) between May 27 and June 9, 2026, predominantly against higher education; 68 percent of the more than 100 notified organizations were universities and colleges [11].
On September 25, 2026, Mandiant and Google Threat Intelligence Group reported renewed mass exploitation [10]. UNC6240 adapted to organizations that had deployed literal path-based WAF blocking (blocking /PSEMHUB/) by URL-encoding characters in the request path: replacing /PSEMHUB/ with /%50SEMHUB/, where %50 is the URL-encoded representation of the letter "P" [10][21]. WebLogic decodes the path and routes the request to the vulnerable servlet, while WAFs comparing the pre-decoded literal string fail to match [10][21]. The renewed campaign deployed web shells on dozens of systems globally across healthcare, higher education, government, technology, and other sectors [9][10].
The attack chain includes deployment of custom MeshCentral remote management agents disguised as Microsoft Azure binaries, data exfiltration using the zstd compression tool, the SIDEEYE backdoor for credential theft, and ransom notes left in PeopleSoft directories [9][22].
Traditional Ransomware: Chaos and GENESIS
On September 29, 2026, the Chaos ransomware group announced a cyberattack on Carolina Asthma & Allergy Center, threatening to release 290 GB of data and demanding negotiations within 24 hours [15].
Two separate ransomware groups listed Interim HealthCare, a home health and hospice provider operating across roughly 40 U.S. states: GENESIS posted on August 10, 2026, followed by a second group (identified as Anubis) on August 21, 2026 [16]. Interim HealthCare had not confirmed either claim as of September 2026 [16]. GENESIS's total claimed victims are estimated at 90 to 115 as of early September 2026 [16].
Supply Chain Breaches: A Structural Problem
Verizon's 2026 DBIR healthcare snapshot found third-party involvement in 32% of healthcare breaches, drawing on 1,438 confirmed data disclosures [12]. Academic analysis of 831 provider-reported ransomware incidents (2016 to 2024) reached a similar figure: 33.8% involved a business associate [12]. Seven of the ten largest healthcare breaches reported in H1 2026 involved a business associate or vendor system [12].
Recent supply chain incidents:
- Aesto Health: An Alabama-based EHR/data-migration vendor disclosed September 1, 2026 that an AWS infrastructure breach exposed data of 9,540,683 patients. Unauthorized access ran December 2 to 18, 2025. The breach rippled to more than two dozen hospital clients [18].
- NYC Health + Hospitals: An unnamed third-party vendor breach gave attackers access from late November 2025 through February 2026, exposing data of at least 1.8 million people including medical records, government IDs, and fingerprint/palm-print biometrics [19].
- Poland (Medyc): An injection flaw in Medyc practice-management software gave attackers access from mid-2024 until August 23, 2026. Attackers claim up to five million patient records and eight million photographs. This came weeks after the MyDr breach exposed almost 19 million Poles [13].
- France: Three supplier-side leaks in a single week: 15,000 patients of Hôpital Paris Saint-Joseph compromised through an appointment-booking vendor, ophthalmology chain Point Vision hit through the same class of provider, and 50,000 home-care patients of VitalAire's VitalWeb extranet claimed exfiltrated through a single account without two-factor authentication [13].
- DC DHCF: DC's Medicaid agency disclosed that personal data of 399,086 individuals may have been exposed on a public website for up to three years due to hidden personal fields in published reports [17].
IOC Table
| Type | Value | Context | Source |
|---|---|---|---|
| Domain Pattern | company.claims |
ShinyHunters Okta-clone impersonation domains | [4] |
| Domain Pattern | company-claims[.]com |
ShinyHunters impersonation domain format | |
| URL Path | /%50SEMHUB/ |
WAF-evading encoded path for CVE-2026-35273 exploitation | [10][21] |
| IP | 162.219.30.165 |
C2 server, ShinyHunters PeopleSoft campaign | [9] |
| IP | 142.11.200.186 |
Staging/C2, PeopleSoft exploitation | [11] |
| IP | 142.11.200.187 |
Staging/C2, PeopleSoft exploitation | [11] |
| IP | 142.11.200.188 |
Staging/C2, PeopleSoft exploitation | [11] |
| IP | 142.11.200.189 |
Staging/C2, PeopleSoft exploitation | [11] |
| IP | 142.11.200.190 |
Staging/C2, PeopleSoft exploitation | [11] |
| IP | 176.120.22.24 |
ShinyHunters DLS mirror | [11] |
| IP | 5.199.162.157 |
Attack controller, PeopleSoft campaign | [21] |
| IP | 104.219.234.138 |
September infrastructure, PeopleSoft campaign | [21] |
| IP | 108.174.202.99 |
PeopleSoft attack infrastructure | [22] |
| Malware | SIDEEYE | Backdoor for credential theft and exfiltration in PeopleSoft campaign | [9] |
MITRE ATT&CK Mapping
The following techniques are directly supported by the source material describing ShinyHunters/UNC6240 operations and associated healthcare-sector attacks:
| ID | Name | Context |
|---|---|---|
| T1598.004 | Phishing for Information: Spearphishing Voice | Vishing calls to employees on personal devices impersonating IT helpdesk[2][20] |
| T1656 | Impersonation | Actors impersonate IT helpdesk, legal operations, and spoof corporate phone numbers[1][14] |
| T1583.001 | Acquire Infrastructure: Domains | Registration of .claims and -claims.com domains impersonating targets[4] |
| T1557 | Adversary-in-the-Middle | Real-time reverse-proxy relay of credentials and MFA tokens to legitimate SSO portals[4] |
| T1621 | Multi-Factor Authentication Request Generation | Prompting victims to approve push notifications or supply MFA tokens during vishing calls[4] |
| T1078 | Valid Accounts | Use of stolen credentials to access Okta, Microsoft Entra, Google SSO dashboards [3] |
| T1213.002 | Data from Information Repositories: SharePoint | Exfiltration from Microsoft 365 and SharePoint after SSO compromise [3] |
| T1567.002 | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Data exfiltration from Salesforce, Snowflake, and other SaaS platforms [5][7] |
| T1190 | Exploit Public-Facing Application | CVE-2026-35273 exploitation against internet-facing PSEMHUB endpoints [9][10][11] |
| T1505.003 | Server Software Component: Web Shell | Web shell deployment on PeopleSoft servers post-exploitation [9][10] |
| T1219 | Remote Access Software | MeshCentral/MeshAgent deployed as persistence mechanism disguised as Azure binaries [9][22] |
| T1486 | Data Encrypted for Impact | Ransomware deployment by Chaos, GENESIS against healthcare targets [15][16] |
| T1199 | Trusted Relationship | Supply chain compromise via third-party vendors (Aesto Health, Medyc, VitalAire) [12][13][18] |
Vishing Infrastructure Detection
Monitor DNS logs and proxy logs for newly registered domains matching the patterns -claims.com and .claims incorporating your organization's name or brand terms[4]. These domains are hosted behind Cloudflare, so SSL certificate transparency logs (e.g., crt.sh queries) are a useful supplementary source for identifying new registrations.
Sigma Rule (DNS query for .claims TLD with org name)
title: Potential ShinyHunters Vishing Domain Resolution
id: a7c3e1f0-9b2d-4e8a-b1c5-3f6d7e8a9b0c
status: experimental
author: RedSheepSec
logsource:
category: dns
detection:
selection:
query|endswith: '.claims'
condition: selection
falsepositives:
- Legitimate .claims TLD usage (review matches for organizational brand keywords)
level: medium
SSO and Identity Monitoring
Alert on SSO login events (Okta, Microsoft Entra, Google Workspace) originating from IP addresses or ASNs associated with known phishing infrastructure, particularly sessions that are immediately followed by access to multiple SaaS applications within minutes [3]. Monitor for password resets or MFA re-enrollment requests that originate from helpdesk calls without callback verification to a pre-registered number [3].
CVE-2026-35273 / PeopleSoft PSEMHUB
WAF rules blocking the literal /PSEMHUB/ path are insufficient. Search web server access logs for URL-encoded variants targeting the PSEMHUB endpoint [10][21]:
# Regex for web/proxy access logs
.*\/%[0-9a-fA-F]{2}SEMHUB.*
.*\/PS%[0-9a-fA-F]{2}MHUB.*
.*\/PSE%[0-9a-fA-F]{2}HUB.*
Block all external access to PSEMHUB endpoints at the network layer, not just via WAF path matching. Patch to Oracle's June 10, 2026 remediation if not already applied [10][11]. Hunt for MeshAgent or MeshCentral binaries on PeopleSoft servers, particularly those masquerading as Azure-related executables [9][22]. Check for the SIDEEYE backdoor and zstd-compressed exfiltration archives [9].
Correlate network traffic against the IOC IPs listed above, particularly the 142.11.200.186-190 range and 162.219.30.165 [9][11].
Supply Chain Visibility
Audit third-party vendor access to SaaS environments. Identify which vendors have SSO-integrated access and whether those integrations enforce phishing-resistant MFA independently [3][12].
Analysis
The ShinyHunters operation represents a fundamental mismatch between where healthcare has invested defensively and where the threat has moved. Health systems spent three years hardening backups, segmenting networks, and rehearsing downtime procedures [1]. None of those controls address an attacker who steals data from cloud SaaS applications through a compromised identity without ever touching on-premises infrastructure [1]. A July Health-ISAC survey found recovery to be the weakest function across healthcare cyber maturity [1], but recovery is irrelevant when the threat model is data theft and extortion without encryption.
The CVE-2026-35273 WAF bypass reinforces a known operational lesson: path-based blocking is a detection-evasion speed bump, not a compensating control for an unauthenticated RCE [21]. Organizations that treated WAF rules as an alternative to patching are now re-exposed.
The supply chain data is consistent across multiple methodologies. Verizon (32%), academic researchers (33.8%), and federal breach portal analysis (seven of ten largest H1 2026 breaches) all converge on roughly a third of healthcare breaches involving third parties [12]. The Aesto Health incident, where a single vendor compromise exposed 9.54 million patients across more than two dozen hospitals, illustrates the amplification effect [18].
Red Sheep Assessment
Confidence: High (based on convergent reporting from Health-ISAC, Mandiant/GTIG, multiple independent security vendors, and victim disclosures)
ShinyHunters has built a repeatable, scalable intrusion model specifically suited to healthcare's architecture. The sector's heavy reliance on SSO-federated SaaS platforms means a single compromised identity can provide access to clinical, financial, and operational data across multiple applications without lateral movement through traditional network infrastructure. This is not a temporary campaign. The group has been refining this approach since late 2025, scaling from roughly 100 targets by January 2026 to confirmed intrusions at major healthcare distributors and manufacturers by August [4][5].
The convergence of the vishing/identity campaign with renewed CVE-2026-35273 exploitation suggests UNC6240 is operating multiple parallel access methods against healthcare. Organizations that deploy phishing-resistant FIDO2/WebAuthn credentials will substantially reduce exposure to the vishing chain, but remain vulnerable to the PeopleSoft exploitation path.
A contrarian reading is that the 284 million record claim from the McKesson breach is substantially inflated (the company has not confirmed the figure [6][7]) and that ShinyHunters' actual data haul across healthcare may be smaller than its public posture suggests. The deadline for McKesson passed September 1, 2026 with no data published [7], which could indicate ongoing negotiations, a smaller dataset than claimed, or a bluff. Regardless, the access method is proven and the sector's exposure to it is structural.
Defender's Checklist
- ▢[ ] Deploy phishing-resistant MFA (FIDO2/WebAuthn passkeys) for all SSO-integrated accounts. Disable SMS, TOTP, and push-based MFA for accounts with access to clinical or sensitive data. Passkeys stop the reverse-proxy relay [4].
- ▢[ ] Implement out-of-band identity proofing for all password/MFA resets and device re-enrollment: callback verification to a previously verified phone number and manager approval for privileged user changes [3].
- ▢[ ] Patch Oracle PeopleSoft to the June 10, 2026 remediation for CVE-2026-35273. Block all external access to PSEMHUB endpoints at the network layer, not via WAF path rules alone. Hunt for
/%50SEMHUB/and similar URL-encoded variants in access logs [10][11][21]. - ▢[ ] Audit all third-party vendor SSO integrations. Identify which business associates have federated access to SaaS platforms and verify that each integration enforces phishing-resistant MFA. Review contracts for cybersecurity requirements [3][12].
- ▢[ ] Hunt for ShinyHunters PeopleSoft C2 infrastructure in network traffic logs:
142.11.200.186-190,162.219.30.165,5.199.162.157,104.219.234.138,108.174.202.99. Search for MeshAgent binaries and SIDEEYE backdoor artifacts on PeopleSoft-connected servers [9][11][21][22].
References
[1] https://healthsystemcio.com/2026/09/10/shinyhunters-healthcare-identity-extortion/
[2] https://industrialcyber.co/medical/health-isac-warns-shinyhunters-targets-health-sector-with-vishing-credential-theft-and-mfa-bypass-tactics/
[3] https://www.hipaajournal.com/health-isac-warning-shinyhunters-healthcare/
[4] https://www.miragesecurity.ai/blog/shinyhunters-vishing-playbook
[5] https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson/
[6] https://www.helpnetsecurity.com/2026/08/31/healthcare-company-mckesson-data-breach/
[7] https://breachhistory.com/blog/mckesson-shinyhunters-data-breach-august-2026
[8] https://ctiwatch.com/victims/a99cc2bc-6f15-452c-b53a-a838846ce49b-fresenius-medical-care
[9] https://aviatrix.ai/threat-research-center/shinyhunters-oracle-peoplesoft-cve-2026-35273-waf-bypass/
[10] https://aicybr.com/blog/oracle-peoplesoft-cve-2026-35273-waf-bypass
[11] https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/
[12] https://www.paubox.com/blog/third-parties-behind-a-third-of-healthcare-breach-exposure
[13] https://cyberverso.net/ehealth/ehealth-cyber-brief-28-sep-2026
[14] https://swktech.com/swk-cybersecurity-news-recap-september-2026
[15] https://dexpose.io/chaos-ransomware-strikes-carolina-asthma-allergy-center
[16] https://tech-insider.org/interim-healthcare-ransomware-genesis-attack-2026/
[17] https://shattered.io/dc-medicaid-dhcf-data-exposure-399086-2026
[18] https://tech-insider.org/aesto-health-data-breach-9-5-million-patients-2026/
[19] https://www.malwarebytes.com/blog/news/2026/05/biometrics-diagnoses-and-bank-details-exposed-in-major-healthcare-breach
[20] https://www.startupdefense.io/mitre-attack-techniques/t1598-004-spearphishing-voice
[21] https://gbhackers.com/oracle-peoplesoft-servers
[22] https://www.decryptiondigest.com/blog/oracle-peoplesoft-cve-2026-35273-psemhub-zero-day
Event Timeline
Timeline
Entity Relationships
Entity Graph (16 entities, 9 relationships)
Diamond Model
Diamond Model
Hunt Guide: ShinyHunters/UNC6240 Identity Extortion, CVE-2026-35273 PeopleSoft Exploitation, and Healthcare Supply Chain Compromise
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If ShinyHunters/UNC6240 is active in our environment, we expect to observe DNS queries to .claims domains matching organizational branding, URL-encoded requests to PSEMHUB endpoints bypassing WAF rules, network connections to known C2 infrastructure (142.11.200.186-190, 162.219.30.165, 5.199.162.157, 104.219.234.138, 108.174.202.99), MeshAgent/MeshCentral binaries masquerading as Azure executables on PeopleSoft servers, anomalous SSO authentication patterns followed by rapid multi-application SaaS access, and SIDEEYE backdoor artifacts in endpoint telemetry.
Intelligence Summary: ShinyHunters (tracked by Mandiant as UNC6240) is conducting sustained vishing and identity-access campaigns against healthcare organizations, bypassing MFA through adversary-in-the-middle reverse-proxy phishing kits to exfiltrate data from cloud SaaS platforms without encryption. The same actor cluster renewed mass exploitation of CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft on September 25, 2026, using URL-encoded WAF bypass techniques, deploying web shells, MeshCentral agents, and the SIDEEYE backdoor. Traditional ransomware operators (Chaos, GENESIS) continue claiming healthcare victims, and supply chain breaches account for approximately one-third of healthcare data exposures according to multiple independent analyses.
Confidence: High | Priority: Critical
Scope
- Networks: All healthcare network segments, PeopleSoft/WebLogic server subnets, DMZ and internet-facing application tiers, SSO/identity infrastructure, SaaS platform egress points, and third-party vendor VPN/access segments
- Timeframe: May 27, 2026 through present (90-day retrospective hunt recommended; CVE-2026-35273 zero-day exploitation confirmed from May 27 and renewed exploitation from September 25)
- Priority Systems: Oracle PeopleSoft servers (PeopleTools 8.61/8.62), Okta/Microsoft Entra/Google Workspace SSO infrastructure, WebLogic application servers, systems with MeshCentral/MeshAgent presence, Salesforce and Snowflake data stores, SharePoint and Microsoft 365 environments, any internet-facing PSEMHUB endpoints
MITRE ATT&CK Techniques
T1598.004: Phishing for Information: Spearphishing Voice (Reconnaissance) [P2]
ShinyHunters conducts targeted vishing campaigns against healthcare employees using spoofed phone numbers and impersonation of IT help desk or legal operations staff. Calls are placed to personal mobile devices to direct victims to adversary-in-the-middle phishing pages.
Splunk SPL:
index=telephony sourcetype=cisco:ucm OR sourcetype=vnc_cdr
| eval call_duration_sec=duration
| where call_duration_sec > 60 AND call_duration_sec < 600
| stats count by calling_party called_party call_duration_sec
| where count > 3
| sort -count
| table calling_party called_party count call_duration_sec
**Elastic KQL:**
event.category:"voice" AND event.action:"call" AND event.duration:[60000 TO 600000]
**Sigma Rule:**
title: Potential Vishing Follow-up - Helpdesk Password Reset Without Callback Verification
id: b8d2e3f1-7a4c-4b9e-a2d6-5e8f9c0a1b2d
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects password or MFA reset events originating from helpdesk interactions that may indicate successful vishing compromise by ShinyHunters
logsource:
product: windows
service: security
detection:
selection:
EventID: 4724
condition: selection
falsepositives:
- Legitimate helpdesk password resets
level: low
tags:
- attack.reconnaissance
- attack.t1598.004
*Vishing detection is primarily procedural. Correlate password/MFA reset events with helpdesk ticket metadata to identify resets that lacked callback verification. Monitor for MFA re-enrollment events occurring within minutes of helpdesk contact.*
#### T1583.001: Acquire Infrastructure: Domains (Resource Development) [P1]
ShinyHunters registers domains using patterns like company.claims and company-claims.com incorporating target organization branding. These domains host cloned Okta login pages behind Cloudflare. Mirage Security tracked 29 such .claims domains since late August 2026.
**Splunk SPL:**
index=corelight sourcetype=corelight_dns
| where (match(query, "(?i)\.claims$") OR match(query, "(?i)-claims\.com$")) |
|---|
| stats count values(id.orig_h) as src_ips dc(id.orig_h) as unique_sources by query |
| sort -count |
| table query count unique_sources src_ips |
**Elastic KQL:**
dns.question.name:.claims OR dns.question.name:-claims.com
**Sigma Rule:**
title: Potential ShinyHunters Vishing Domain Resolution - Claims TLD
id: a7c3e1f0-9b2d-4e8a-b1c5-3f6d7e8a9b0c
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects DNS queries for .claims TLD domains that may be ShinyHunters phishing infrastructure impersonating healthcare organizations
logsource:
category: dns
detection:
selection_claims_tld:
query|endswith: '.claims'
selection_claims_com:
query|endswith: '-claims.com'
condition: selection_claims_tld or selection_claims_com
falsepositives:
- Legitimate .claims TLD usage by insurance or legal organizations
level: medium
tags:
- attack.resource_development
- attack.t1583.001
*Review matches for organizational brand keywords in the domain name. The .claims TLD has limited legitimate use; most hits warrant investigation. Cross-reference with Certificate Transparency logs for newly issued certificates on matching domains.*
#### T1557: Adversary-in-the-Middle (Credential Access) [P2]
ShinyHunters phishing kits run a real-time adversary-in-the-middle relay that forwards stolen credentials to the legitimate corporate SSO portal. The kit retrieves the live Okta Verify challenge digit from the relay server and displays it to the victim, defeating number-matching MFA. Origin-bound factors (FastPass, security keys, PIV/CAC) are deliberately disabled in the kit.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad"
| spath output=auth_result path=properties.status.errorCode |
|---|
| spath output=app_name path=properties.appDisplayName |
| spath output=src_ip path=properties.ipAddress |
| spath output=user path=properties.userPrincipalName |
| spath output=auth_method path=properties.authenticationDetails{}.authenticationMethod |
| where auth_result="0" |
| stats dc(app_name) as apps_accessed values(app_name) as app_list min(_time) as first_access max(_time) as last_access by user src_ip |
| eval time_span_minutes=round((last_access-first_access)/60,1) |
| where apps_accessed >= 5 AND time_span_minutes <= 15 |
| sort -apps_accessed |
| table user src_ip apps_accessed time_span_minutes app_list |
**Elastic KQL:**
event.dataset:"azure.signinlogs" AND event.outcome:"success" AND azure.signinlogs.properties.status.errorCode:0
**Sigma Rule:**
title: Rapid Multi-Application SSO Access Post-Authentication
id: c9d4f2e1-8b5a-4c0f-b3e7-6f9a0d1c2e3f
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects a user accessing five or more SSO-integrated applications within 15 minutes of authentication, which may indicate ShinyHunters post-compromise SaaS data harvesting
logsource:
product: azure
service: signinlogs
detection:
selection:
Status.errorCode: 0
condition: selection
# Aggregation logic must be implemented in SIEM
falsepositives:
- Administrators performing legitimate multi-app operations
- Automated service accounts
level: medium
tags:
- attack.credential_access
- attack.t1557
*Tune threshold based on baseline user behavior. Focus on non-admin accounts accessing unusual combinations of applications (Salesforce + SharePoint + Dropbox + Google Drive in rapid succession). Correlate source IP with known VPN/proxy infrastructure.*
#### T1078: Valid Accounts (Initial Access) [P1]
After obtaining live SSO sessions through the AitM relay, ShinyHunters uses stolen credentials to log into Okta, Microsoft Entra, or Google SSO dashboards and access all listed applications including Microsoft 365, Salesforce, Dropbox, Google Drive, and SharePoint.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad"
| spath output=risk_level path=properties.riskLevelDuringSignIn |
|---|
| spath output=src_ip path=properties.ipAddress |
| spath output=user path=properties.userPrincipalName |
| spath output=location path=properties.location.city |
| spath output=device_detail path=properties.deviceDetail.operatingSystem |
| spath output=auth_result path=properties.status.errorCode |
| where auth_result="0" AND (risk_level="high" OR risk_level="medium") |
| stats count values(location) as locations dc(location) as location_count by user src_ip device_detail |
| table user src_ip device_detail locations location_count count |
**Elastic KQL:**
event.dataset:"azure.signinlogs" AND event.outcome:"success" AND azure.signinlogs.properties.riskLevelDuringSignIn:("high" OR "medium")
**Sigma Rule:**
title: SSO Login from Risky IP Followed by SaaS Application Access
id: d0e5a3b2-9c6d-4d1a-c4f8-7a0b1e2d3f4a
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects SSO authentication events flagged as risky that succeed, potentially indicating use of AitM-relayed credentials
logsource:
product: azure
service: signinlogs
detection:
selection:
Status.errorCode: 0
riskLevelDuringSignIn|contains:
- 'high'
- 'medium'
condition: selection
falsepositives:
- Legitimate logins from new locations or devices
level: high
tags:
- attack.initial_access
- attack.t1078
*Correlate with impossible travel detections. Pay particular attention to sessions where the authentication method is push notification or TOTP rather than FIDO2/WebAuthn, as these are the MFA methods vulnerable to the AitM relay.*
#### T1190: Exploit Public-Facing Application (Initial Access) [P1]
UNC6240 exploits CVE-2026-35273, an unauthenticated SSRF-to-RCE (CVSS 9.8) in Oracle PeopleSoft PeopleTools 8.61/8.62 PSEMHUB component. The renewed September 2026 campaign uses URL-encoded WAF bypass replacing /PSEMHUB/ with /%50SEMHUB/ (where %50 is URL-encoded P) to evade literal path-based WAF rules.
**Splunk SPL:**
index=corelight sourcetype=corelight_http
| where match(uri, "(?i)(%[0-9a-fA-F]{2}SEMHUB | PS%[0-9a-fA-F]{2}MHUB | PSE%[0-9a-fA-F]{2}HUB | PSEM%[0-9a-fA-F]{2}UB | PSEMH%[0-9a-fA-F]{2}B | PSEMHU%[0-9a-fA-F]{2} | PSEMHUB)") |
|---|---|---|---|---|---|---|
| stats count by id.orig_h id.resp_h uri status_code method | ||||||
| sort -count | ||||||
| table id.orig_h id.resp_h method uri status_code count |
**Elastic KQL:**
url.path:SEMHUB OR url.path:%50SEMHUB OR url.path:PS%45MHUB OR url.path:PSE%4DHUB
**Sigma Rule:**
title: CVE-2026-35273 Oracle PeopleSoft PSEMHUB Exploitation Attempt With URL Encoding WAF Bypass
id: e1f6b4c3-0d7e-4e2b-d5a9-8b1c2f3e4a5b
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects HTTP requests targeting the Oracle PeopleSoft PSEMHUB endpoint using URL-encoded characters to bypass WAF rules, indicative of CVE-2026-35273 exploitation by UNC6240
logsource:
category: webserver
detection:
selection_encoded:
cs-uri-query|re: '.%[0-9a-fA-F]{2}SEMHUB.'
selection_literal:
cs-uri-query|contains: '/PSEMHUB/'
condition: selection_encoded or selection_literal
falsepositives:
- Legitimate PeopleSoft admin access to PSEMHUB (should be internal only)
level: critical
tags:
- attack.initial_access
- attack.t1190
- cve.2026.35273
*Any external request to PSEMHUB, whether URL-encoded or literal, is suspicious. PSEMHUB should not be exposed to the internet. Also hunt in IIS/WebLogic access logs on PeopleSoft servers directly. Check for HTTP 200 responses which indicate successful exploitation.*
#### T1505.003: Server Software Component: Web Shell (Persistence) [P1]
Post-exploitation of CVE-2026-35273, UNC6240 deploys web shells on compromised PeopleSoft servers. The renewed September 2026 campaign deployed web shells on dozens of systems globally.
**Splunk SPL:**
index=sysmon sourcetype=XmlWinEventLog EventCode=11
| where match(TargetFilename, "(?i)(PeopleSoft | PSEMHUB | weblogic | wlserver).*\.(jsp | jspx | war | class | php | aspx | ashx | asmx)$") |
|---|---|---|---|---|---|---|---|---|---|---|
| stats count by Computer User TargetFilename | ||||||||||
| sort -count | ||||||||||
| table _time Computer User TargetFilename count |
**Elastic KQL:**
event.code:"11" AND file.path:(PeopleSoft OR PSEMHUB OR weblogic) AND file.extension:("jsp" OR "jspx" OR "war" OR "class" OR "php" OR "aspx")
**Sigma Rule:**
title: Web Shell Creation in PeopleSoft or WebLogic Directory
id: f2a7c5d4-1e8f-4f3c-e6b0-9c2d3a4b5c6d
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects creation of web-executable files in PeopleSoft or WebLogic directories, indicating potential web shell deployment following CVE-2026-35273 exploitation
logsource:
product: windows
category: file_event
detection:
selection_path:
TargetFilename|contains:
- 'PeopleSoft'
- 'PSEMHUB'
- 'weblogic'
- 'wlserver'
selection_ext:
TargetFilename|endswith:
- '.jsp'
- '.jspx'
- '.war'
- '.class'
- '.php'
condition: selection_path and selection_ext
falsepositives:
- Legitimate PeopleSoft deployments and updates
level: high
tags:
- attack.persistence
- attack.t1505.003
*Baseline legitimate deployment activity on PeopleSoft servers to reduce false positives. Any file creation in PSEMHUB directories outside of scheduled maintenance windows warrants immediate investigation.*
#### T1219: Remote Access Software (Command and Control) [P1]
UNC6240 deploys custom MeshCentral/MeshAgent remote management agents disguised as Microsoft Azure binaries on compromised PeopleSoft servers for persistence.
**Splunk SPL:**
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where (match(Image, "(?i)mesh(agent | central)") OR match(OriginalFileName, "(?i)mesh(agent | central)")) |
|---|
OR (match(Image, "(?i)azure") AND match(ParentImage, "(?i)(java|weblogic|python|cmd|powershell)"))
| stats count by Computer Image ParentImage CommandLine User OriginalFileName |
|---|
| table _time Computer Image OriginalFileName ParentImage CommandLine User count |
**Elastic KQL:**
(process.name:mesh OR process.original_file_name:mesh) OR (process.name:azure AND process.parent.name:("java.exe" OR "weblogic.exe" OR "python.exe" OR "cmd.exe" OR "powershell.exe"))
**Sigma Rule:**
title: MeshAgent or MeshCentral Execution - Potential UNC6240 Persistence
id: a3b8d6e5-2f9a-4a4d-f7c1-0d3e4b5c6d7e
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects execution of MeshAgent or MeshCentral binaries, or Azure-named binaries spawned by web server processes, which may indicate UNC6240 persistence via disguised remote management tools
logsource:
product: windows
category: process_creation
detection:
selection_mesh:
Image|contains:
- 'meshagent'
- 'meshcentral'
OriginalFileName|contains:
- 'meshagent'
- 'meshcentral'
selection_disguised:
Image|contains: 'azure'
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
- '\weblogic.exe'
- '\python.exe'
condition: selection_mesh or selection_disguised
falsepositives:
- Legitimate MeshCentral usage by IT (should be inventoried)
- Legitimate Azure CLI tools
level: high
tags:
- attack.command_and_control
- attack.t1219
*MeshCentral is a legitimate open-source RMM tool. If your organization does not use MeshCentral, any detection is high confidence. Verify against approved RMM tool inventory. The disguised-as-Azure variant is higher confidence; legitimate Azure tools should not be spawned by Java/WebLogic processes.*
#### T1567.002: Exfiltration Over Web Service: Exfiltration to Cloud Storage (Exfiltration) [P2]
ShinyHunters exfiltrates data from Salesforce, Snowflake, Microsoft 365, SharePoint, Dropbox, and Google Drive after SSO compromise. Data exfiltration also uses zstd compression in the PeopleSoft campaign.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:activity"
| spath output=operation path=operationName | |||
|---|---|---|---|
| spath output=user path=identity.claims.name | |||
| where match(operation, "(?i)(download | export | copy | share)") |
| stats count sum(eval(if(isnotnull(properties.responseSize),properties.responseSize,0))) as total_bytes by user operation | |||
| where count > 50 OR total_bytes > 1073741824 | |||
| eval total_GB=round(total_bytes/1073741824,2) | |||
| sort -total_bytes | |||
| table user operation count total_GB |
**Elastic KQL:**
event.action:("FileDownloaded" OR "FileAccessed" OR "FileCopied") AND event.outcome:"success"
**Sigma Rule:**
title: High Volume SaaS Data Download Post-SSO Authentication
id: b4c9e7f6-3a0b-4b5e-a8d2-1e4f5a6b7c8d
status: experimental
author: RedSheepSec
date: 2026/10/01
description: Detects high-volume file download or export operations from SaaS platforms that may indicate ShinyHunters data exfiltration following SSO compromise
logsource:
product: m365
service: audit
detection:
selection:
Operation|contains:
- 'FileDownloaded'
- 'FileAccessed'
- 'FileSyncDownloadedFull'
condition: selection
# Volume thresholds should be applied at SIEM level
falsepositives:
- Bulk file operations during legitimate business processes
- Data migration activities
level: medium
tags:
- attack.exfiltration
- attack.t1567.002
*Baseline normal download volumes per user. Focus on accounts that show no prior history of bulk downloads. Correlate with SSO login anomalies from the T1557 and T1078 detections above.*
#### T1213.002: Data from Information Repositories: SharePoint (Collection) [P2]
After SSO compromise, ShinyHunters accesses Microsoft 365 and SharePoint to collect sensitive data across connected SaaS applications.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:activity"
| spath output=operation path=operationName | |||
|---|---|---|---|
| spath output=user path=identity.claims.name | |||
| spath output=site_url path=properties.SiteUrl | |||
| where match(operation, "(?i)(FileAccessed | FileDownloaded | PageViewed | SearchQueryPerformed)") |
| bucket _time span=1h | |||
| stats dc(site_url) as unique_sites count by _time user | |||
| where unique_sites > 10 OR count > 100 | |||
| sort -unique_sites | |||
| table _time user unique_sites count |
**Elastic KQL:**
event.dataset:"o365.audit" AND event.action:("FileAccessed" OR "FileDownloaded" OR "PageViewed" OR "SearchQueryPerformed") AND event.outcome:"success"
*Users accessing more than 10 unique SharePoint sites in one hour is unusual. Correlate with the user's normal access pattern and the SSO login source IP.*
#### T1621: Multi-Factor Authentication Request Generation (Credential Access) [P2]
During vishing calls, ShinyHunters operators prompt victims to approve push notifications or supply active MFA tokens. The AitM kit retrieves the Okta Verify number-matching challenge digit from the relay server and displays it to the victim.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad"
| spath output=auth_method path=properties.authenticationDetails{}.authenticationMethod | |||
|---|---|---|---|
| spath output=user path=properties.userPrincipalName | |||
| spath output=result path=properties.status.errorCode | |||
| where match(auth_method, "(?i)(push | phone | sms | totp)") |
| bucket _time span=5m | |||
| stats count dc(eval(if(result!="0",result,null()))) as failed_attempts by _time user auth_method | |||
| where failed_attempts >= 2 | |||
| sort -failed_attempts | |||
| table _time user auth_method count failed_attempts |
**Elastic KQL:**
event.dataset:"azure.signinlogs" AND azure.signinlogs.properties.authenticationDetails.authenticationMethod:("PhoneAppNotification" OR "OneWaySMS" OR "TwoWaySMS")
*Multiple MFA attempts in a short window, especially using push notifications, may indicate an operator prompting the victim during a live vishing call. Correlate with helpdesk activity.*
#### T1486: Data Encrypted for Impact (Impact) [P1]
Chaos and GENESIS ransomware groups are actively claiming healthcare victims. Chaos attacked Carolina Asthma and Allergy Center on September 29, 2026. GENESIS and Anubis both listed Interim HealthCare.
**Splunk SPL:**
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(CommandLine, "(?i)(vssadmin.delete.shadows | wmic.shadowcopy.delete | bcdedit.recoveryenabled.no | wbadmin.delete.catalog)") |
|---|---|---|---|
| stats count by Computer Image CommandLine User ParentImage | |||
| table _time Computer User Image ParentImage CommandLine count |
**Elastic KQL:**
process.command_line:(vssadmin AND delete AND shadows) OR process.command_line:(wmic AND shadowcopy AND delete) OR process.command_line:(bcdedit AND recoveryenabled AND no)
**Sigma Rule:**
title: Volume Shadow Copy Deletion - Ransomware Pre-Encryption Indicator
id: c5d0f8a7-4b1c-4c6f-b9e3-2f5a6b7c8d9e
status: experimental
author: Florian Roth
date: 2019/06/01
modified: 2026/10/01
description: Detects deletion of volume shadow copies, commonly performed by ransomware including Chaos and GENESIS prior to encryption
logsource:
product: windows
category: process_creation
detection:
selection_vss:
CommandLine|contains|all:
- 'vssadmin'
- 'delete'
- 'shadows'
selection_wmic:
CommandLine|contains|all:
- 'wmic'
- 'shadowcopy'
- 'delete'
condition: selection_vss or selection_wmic
falsepositives:
- Legitimate backup administration
level: high
tags:
- attack.impact
- attack.t1486
- attack.t1490
*Attribution: Florian Roth, SigmaHQ (adapted for context)*
*Shadow copy deletion is a high-fidelity pre-encryption indicator. Any detection outside of planned backup maintenance windows should trigger immediate incident response.*
#### T1199: Trusted Relationship (Initial Access) [P2]
Approximately one-third of healthcare breaches involve third-party vendors. Recent examples include Aesto Health (9.54M patients via AWS breach), NYC Health + Hospitals (1.8M via unnamed vendor), and multiple French healthcare supply chain compromises.
**Splunk SPL:**
index=cloud-azure sourcetype="azure:monitor:aad"
| spath output=app_name path=properties.appDisplayName |
|---|
| spath output=user path=properties.userPrincipalName |
| spath output=src_ip path=properties.ipAddress |
| spath output=auth_result path=properties.status.errorCode |
| where auth_result="0" AND NOT match(user, "@yourdomain\.com$") |
| stats count dc(app_name) as apps_accessed values(app_name) as app_list by user src_ip |
| where apps_accessed >= 3 |
| sort -apps_accessed |
| table user src_ip apps_accessed app_list count |
**Elastic KQL:**
event.dataset:"azure.signinlogs" AND event.outcome:"success" AND NOT user.name:*@yourdomain.com
*Replace 'yourdomain.com' with your organization's domain. This query identifies external/vendor accounts accessing multiple applications. Cross-reference with vendor access agreements.*
#### T1656: Impersonation (Defense Evasion) [P2]
ShinyHunters operators impersonate IT help desk and legal operations staff, and spoof corporate phone numbers. Astrana Health confirmed attackers spoofed its main corporate phone number.
**Splunk SPL:**
index=winevent sourcetype=XmlWinEventLog:Security EventCode=4724 OR EventCode=4723
| stats count by TargetUserName SubjectUserName Computer |
|---|
| where count >= 3 |
| sort -count |
| table _time TargetUserName SubjectUserName Computer count |
| rename TargetUserName as "Reset Target" SubjectUserName as "Reset By" |
**Elastic KQL:**
event.code:("4724" OR "4723") AND event.outcome:"success"
*Multiple password resets by the same operator in a short window may indicate attacker-controlled helpdesk access. Correlate with vishing reports.*
### Indicators of Compromise
| Type | Value | Context |
|------|-------|---------|
| ip | `162.219.30.165` | C2 server for ShinyHunters Oracle PeopleSoft campaign \| AbuseIPDB confidence 0% (0 reports, GB) |
| ip | `142.11.200.186` | Staging/C2 infrastructure, ShinyHunters PeopleSoft exploitation \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `142.11.200.187` | Staging/C2 infrastructure, ShinyHunters PeopleSoft exploitation \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `142.11.200.188` | Staging/C2 infrastructure, ShinyHunters PeopleSoft exploitation \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `142.11.200.189` | Staging/C2 infrastructure, ShinyHunters PeopleSoft exploitation \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `142.11.200.190` | Staging/C2 infrastructure, ShinyHunters PeopleSoft exploitation \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `176.120.22.24` | ShinyHunters data leak site mirror IP (RU) \| AbuseIPDB confidence 0% (0 reports, RU) |
| ip | `5.199.162.157` | Attack controller, Oracle PeopleSoft campaign (LT) \| AbuseIPDB confidence 1% (1 reports, LT) |
| ip | `104.219.234.138` | Mandiant-identified September infrastructure, PeopleSoft campaign \| AbuseIPDB confidence 0% (0 reports, US) |
| ip | `108.174.202.99` | ShinyHunters Oracle PeopleSoft attack infrastructure \| AbuseIPDB confidence 0% (0 reports, US) |
| domain | `company.claims` | ShinyHunters domain naming pattern for Okta-clone impersonation domains (pattern, not literal domain) \| VirusTotal 1/91 malicious |
| domain | `company-claims.com` | ShinyHunters domain naming pattern for impersonation domains (pattern, not literal domain) \| VirusTotal 0/91 malicious |
| url | `/%50SEMHUB/` | WAF-evading URL-encoded path variant used in September 2026 CVE-2026-35273 exploitation |
**IOC Sweep Queries (Splunk):**
index=corelight sourcetype=corelight_conn (id.resp_h="162.219.30.165" OR id.orig_h="162.219.30.165")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="142.11.200.186" OR id.orig_h="142.11.200.186")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="142.11.200.187" OR id.orig_h="142.11.200.187")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="142.11.200.188" OR id.orig_h="142.11.200.188")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="142.11.200.189" OR id.orig_h="142.11.200.189")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="142.11.200.190" OR id.orig_h="142.11.200.190")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="176.120.22.24" OR id.orig_h="176.120.22.24")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="5.199.162.157" OR id.orig_h="5.199.162.157")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="104.219.234.138" OR id.orig_h="104.219.234.138")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_conn (id.resp_h="108.174.202.99" OR id.orig_h="108.174.202.99")
| stats count min(_time) as first_seen max(_time) as last_seen values(id.orig_h) as src_ips values(id.resp_p) as dest_ports by id.resp_h |
|---|
| table id.resp_h src_ips dest_ports count first_seen last_seen |
index=corelight sourcetype=corelight_dns
| where match(query, "(?i)\.claims$") |
|---|
| stats count values(id.orig_h) as src_ips dc(id.orig_h) as unique_hosts by query |
| sort -count |
| table query count unique_hosts src_ips |
index=corelight sourcetype=corelight_dns
| where match(query, "(?i)-claims\.com$") |
|---|
| stats count values(id.orig_h) as src_ips dc(id.orig_h) as unique_hosts by query |
| sort -count |
| table query count unique_hosts src_ips |
index=corelight sourcetype=corelight_http
| where match(uri, "(?i)%50SEMHUB") |
|---|
| stats count by id.orig_h id.resp_h uri status_code method |
| table _time id.orig_h id.resp_h method uri status_code count |
### YARA Rules
**HUNT_MeshAgent_Disguised_Azure**: Detects MeshAgent binaries that may be disguised as Microsoft Azure executables, as deployed by UNC6240 on compromised PeopleSoft servers
rule HUNT_MeshAgent_Disguised_Azure {
meta:
author = "RedSheepSec"
description = "Detects MeshAgent binaries potentially disguised as Azure executables, used by UNC6240/ShinyHunters for persistence on PeopleSoft servers"
date = "2026-10-01"
reference = "https://aviatrix.ai/threat-research-center/shinyhunters-oracle-peoplesoft-cve-2026-35273-waf-bypass/"
threat_actor = "UNC6240/ShinyHunters"
strings:
$mesh1 = "MeshAgent" ascii wide nocase
$mesh2 = "MeshCentral" ascii wide nocase
$mesh3 = "meshcore" ascii wide nocase
$mesh4 = "mesh.agent" ascii wide nocase
$azure1 = "azure" ascii wide nocase
$azure2 = "Microsoft.Azure" ascii wide nocase
$pe_header = { 4D 5A }
condition:
$pe_header at 0 and (any of ($mesh)) and (any of ($azure))
}
**HUNT_SIDEEYE_Backdoor_Strings**: Detects potential SIDEEYE backdoor binaries used by UNC6240 for credential theft and exfiltration in the PeopleSoft campaign
rule HUNT_SIDEEYE_Backdoor_Strings {
meta:
author = "RedSheepSec"
description = "Detects potential SIDEEYE backdoor used by UNC6240/ShinyHunters for credential theft in Oracle PeopleSoft exploitation campaigns"
date = "2026-10-01"
reference = "https://aviatrix.ai/threat-research-center/shinyhunters-oracle-peoplesoft-cve-2026-35273-waf-bypass/"
threat_actor = "UNC6240/ShinyHunters"
strings:
$s1 = "SIDEEYE" ascii wide nocase
$s2 = "sideeye" ascii
$zstd1 = "zstd" ascii wide
$zstd2 = "zstandard" ascii wide nocase
$ps1 = "PeopleSoft" ascii wide nocase
$ps2 = "PSEMHUB" ascii wide nocase
$pe_header = { 4D 5A }
condition:
$pe_header at 0 and (any of ($s)) and (any of ($zstd) or any of ($ps*))
}
**HUNT_WebShell_PeopleSoft_Directory**: Detects JSP web shells potentially deployed in PeopleSoft directories following CVE-2026-35273 exploitation
rule HUNT_WebShell_PeopleSoft_Directory {
meta:
author = "RedSheepSec"
description = "Generic JSP web shell indicators that may be found in PeopleSoft directories post CVE-2026-35273 exploitation"
date = "2026-10-01"
reference = "https://gbhackers.com/oracle-peoplesoft-servers"
strings:
$jsp_runtime = "Runtime.getRuntime().exec" ascii
$jsp_process = "ProcessBuilder" ascii
$jsp_cmd1 = "cmd.exe" ascii nocase
$jsp_cmd2 = "/bin/sh" ascii
$jsp_cmd3 = "/bin/bash" ascii
$jsp_request = "request.getParameter" ascii
$jsp_base64 = "Base64.getDecoder" ascii
condition:
any of ($jsp_runtime, $jsp_process) and any of ($jsp_cmd*) and any of ($jsp_request, $jsp_base64)
}
### Suricata Rules
**SID 2026001**: Detects HTTP request to PSEMHUB with URL-encoded characters indicating CVE-2026-35273 WAF bypass exploitation attempt
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2026-35273 Oracle PeopleSoft PSEMHUB URL-Encoded WAF Bypass"; flow:established,to_server; content:"%50SEMHUB"; http_uri; nocase; reference:cve,2026-35273; reference:url,gbhackers.com/oracle-peoplesoft-servers; classtype:web-application-attack; sid:2026001; rev:1;)
**SID 2026002**: Detects HTTP request to literal PSEMHUB path indicating CVE-2026-35273 exploitation attempt
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT CVE-2026-35273 Oracle PeopleSoft PSEMHUB Direct Access Attempt"; flow:established,to_server; content:"/PSEMHUB/"; http_uri; nocase; reference:cve,2026-35273; reference:url,www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/; classtype:web-application-attack; sid:2026002; rev:1;)
**SID 2026003**: Detects outbound connection to ShinyHunters C2 IP 162.219.30.165
alert ip $HOME_NET any -> 162.219.30.165 any (msg:"HUNT ShinyHunters C2 Communication - 162.219.30.165"; reference:url,aviatrix.ai/threat-research-center/shinyhunters-oracle-peoplesoft-cve-2026-35273-waf-bypass/; classtype:trojan-activity; sid:2026003; rev:1;)
**SID 2026004**: Detects outbound connection to ShinyHunters staging/C2 IP range 142.11.200.186-190
alert ip $HOME_NET any -> [142.11.200.186,142.11.200.187,142.11.200.188,142.11.200.189,142.11.200.190] any (msg:"HUNT ShinyHunters Staging/C2 Communication - 142.11.200.186-190"; reference:url,www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/; classtype:trojan-activity; sid:2026004; rev:1;)
**SID 2026005**: Detects outbound connection to ShinyHunters DLS mirror IP 176.120.22.24
alert ip $HOME_NET any -> 176.120.22.24 any (msg:"HUNT ShinyHunters DLS Mirror Communication - 176.120.22.24"; reference:url,www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273/; classtype:trojan-activity; sid:2026005; rev:1;)
**SID 2026006**: Detects outbound connection to PeopleSoft attack controller IP 5.199.162.157
alert ip $HOME_NET any -> 5.199.162.157 any (msg:"HUNT ShinyHunters PeopleSoft Attack Controller - 5.199.162.157"; reference:url,gbhackers.com/oracle-peoplesoft-servers; classtype:trojan-activity; sid:2026006; rev:1;)
**SID 2026007**: Detects outbound connection to PeopleSoft attack infrastructure IP 104.219.234.138
alert ip $HOME_NET any -> 104.219.234.138 any (msg:"HUNT ShinyHunters September Infrastructure - 104.219.234.138"; reference:url,gbhackers.com/oracle-peoplesoft-servers; classtype:trojan-activity; sid:2026007; rev:1;)
**SID 2026008**: Detects outbound connection to PeopleSoft attack infrastructure IP 108.174.202.99
alert ip $HOME_NET any -> 108.174.202.99 any (msg:"HUNT ShinyHunters PeopleSoft IOC - 108.174.202.99"; reference:url,www.decryptiondigest.com/blog/oracle-peoplesoft-cve-2026-35273-psemhub-zero-day; classtype:trojan-activity; sid:2026008; rev:1;)
**SID 2026009**: Detects DNS query for .claims TLD which may indicate ShinyHunters phishing domain resolution
alert dns $HOME_NET any -> any any (msg:"HUNT ShinyHunters Potential Vishing Domain - .claims TLD Query"; dns.query; content:".claims"; nocase; endswith; reference:url,www.miragesecurity.ai/blog/shinyhunters-vishing-playbook; classtype:social-engineering; sid:2026009; rev:1;)