ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
ID: de886cd3-0f2d-52d1-8c35-6cf5986e3e0e
STIX ID: report--de886cd3-0f2d-52d1-8c35-6cf5986e3e0e
Feed Name: Google Cloud Threat Intelligence
On 9 June 2026, investigators discovered five public IPs hosting open Python SimpleHTTP directories containing MeshCentral staging materials and pre-configured agent binaries (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe) hardcoded to contact wss://azurenetfiles.net:443/agent.ashx. The actors automated TLS provisioning using acme-client, used MeshCentral CLI for internal reconnaissance (including Oracle PeopleSoft and WebLogic artifacts), and staged an unconfigured Linux agent; over 100 exposed organizations—68% in higher education—were notified, and some were confirmed compromised with stolen data later published to the ShinyHunters DLS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
