Mandiant, Google Threat Intelligence Group. (2026, June 11). ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Retrieved June 11, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupShinyHunters | ShinyHunters has collected machine names and IP addresses by parsing the process scheduler configuration file psappsrv.cfg. |
| T1018 Remote System Discovery |
GroupShinyHunters | ShinyHunters has enumerated the internal subnet using ` cat /etc/hosts | grep -E "[redacted_victim_string]"`. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupShinyHunters | ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
| T1059.007 JavaScript |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line interface utility meshctrl.js and npm to interact with compromised systems. Specifically for npm, ShinyHunters has checked for the authenticode tool using the command `npm list global authenticode`. Additionally, ShinyHunters has used the MeshCentral command to execute the propagation script: ` node meshctrl.js RunCommand --loginuser admin --loginpass '[password]' --id '[agent_id]' --run 'bash /tmp/[victim_abbreviation]_fanout.sh' `. |
| T1082 System Information Discovery |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems. |
| T1083 File and Directory Discovery |
GroupShinyHunters | ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml). |
| T1105 Ingress Tool Transfer |
GroupShinyHunters | ShinyHunters has deployed custom scripts to targeted systems from customized MeshAgents in their staging environment. |
| T1190 Exploit Public-Facing Application |
GroupShinyHunters | ShinyHunters has exploited CVE-2026-35273 against Oracle PeopleSoft application infrastructure. ShinyHunters has exploited known vulnerabilities in internet-facing servers. |
| T1219 Remote Access Tools |
GroupShinyHunters | ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh. |
| T1491.001 Internal Defacement |
GroupShinyHunters | ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. |
| T1560.002 Archive via Library |
GroupShinyHunters | ShinyHunters has used the following command to compress collected data: ` pv -s "$(du -sb exfil | awk '{print $1}')" | zstd -3 -T0 -o exfil.tar.zst `. |
| T1573.002 Asymmetric Cryptography |
GroupShinyHunters | ShinyHunters has established a connection between the staging host and the C2 using SSH. |
| T1583.001 Domains |
GroupShinyHunters | ShinyHunters has established clearnet and Tor data leak sites (DLS) including one named “SHINYHUNTERS” for the exfiltration and posting of stolen data. Additionally, ShinyHunters has registered domains that mimic legitimate Microsoft Azure NetApp Files endpoints, such as azurenetfiles[.]net, and legitimate Okta SSO login pages, such as trial-6857053.okta[.]com. |
| T1583.004 Server |
GroupShinyHunters | ShinyHunters has used five IP addresses to host Python SimpleHTTP servers on port 8888, which exposed staging materials, customized agents, and .bash_history files. |
| T1587.004 Exploits |
GroupShinyHunters | ShinyHunters has exploited zero-day vulnerability CVE-2026-35273 against Oracle PeopleSoft application infrastructure. |
| T1588.002 Tool |
GroupShinyHunters | ShinyHunters has obtained MeshCentral to deploy agents masquerading as legitimate cloud endpoints. ShinyHunters has obtained WinSCP to gather information on S3 bucket configurations. ShinyHunters has obtained ConnectWise and other RMM tools to gain initial access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.