logo

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

ID: de886cd3-0f2d-52d1-8c35-6cf5986e3e0e

STIX ID: report--de886cd3-0f2d-52d1-8c35-6cf5986e3e0e

Feed Name: Google Cloud Threat Intelligence

Threat Score
78/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

Author: Mandiant

...
...

On 9 June 2026, investigators discovered five public IPs hosting open Python SimpleHTTP directories containing MeshCentral staging materials and pre-configured agent binaries (meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, meshagent64-v2.exe) hardcoded to contact wss://azurenetfiles.net:443/agent.ashx. The actors automated TLS provisioning using acme-client, used MeshCentral CLI for internal reconnaissance (including Oracle PeopleSoft and WebLogic artifacts), and staged an unconfigured Linux agent; over 100 exposed organizations—68% in higher education—were notified, and some were confirmed compromised with stolen data later published to the ShinyHunters DLS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.