ShinyHunters Healthcare Identity Extortion and PeopleSoft Exploitation
Score: 9/10

ShinyHunters Healthcare Identity Extortion and PeopleSoft Exploitation

ShinyHunters (UNC6240) is targeting healthcare through identity-access extortion using vishing/AitM kits and mass exploitation of CVE-2026-35273 in Oracle PeopleSoft.

Executive Summary

Healthcare organizations are currently facing a converged threat landscape involving ShinyHunters (tracked as UNC6240), traditional ransomware groups like Chaos and GENESIS, and systemic supply chain vulnerabilities. ShinyHunters has shifted toward an identity-and-SaaS-access extortion model that bypasses multi-factor authentication (MFA) to exfiltrate data directly from cloud platforms like Salesforce and Snowflake without utilizing encryption.

Technically, the actor cluster uses a two-pronged approach: sophisticated vishing campaigns that leverage adversary-in-the-middle (AitM) reverse-proxies to steal SSO sessions, and mass exploitation of CVE-2026-35273 in Oracle PeopleSoft. In recent campaigns, they have successfully bypassed WAF protections by utilizing URL-encoded path variants (e.g., /%50SEMHUB/) to deliver web shells, the SIDEEYE backdoor, and custom MeshCentral agents disguised as legitimate Azure binaries.

This activity represents a critical risk to the healthcare sector as it bypasses traditional ransomware recovery strategies. With third-party vendors involved in 32% of healthcare breaches, the amplification effect of a single compromise—such as the Aesto Health breach affecting 9.5 million patients—highlights a structural vulnerability in vendor-managed SaaS and EHR environments.

Key Details

Threat Name

ShinyHunters

Affects

Oracle PeopleSoft Enterprise PeopleTools 8.61, Oracle PeopleSoft Enterprise PeopleTools 8.62, PSEMHUB component

Adversary

ShinyHunters Other Adversaries and Aliases: Chaos; GENESIS; Anubis

Malware/Tools

Chaos, GENESIS, SIDEEYE, MeshCentral, Anubis

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance10
Enterprise Relevance10
Clarity & Structure10
Technical Depth8

Sources