Executive Summary
Healthcare organizations are currently facing a converged threat landscape involving ShinyHunters (tracked as UNC6240), traditional ransomware groups like Chaos and GENESIS, and systemic supply chain vulnerabilities. ShinyHunters has shifted toward an identity-and-SaaS-access extortion model that bypasses multi-factor authentication (MFA) to exfiltrate data directly from cloud platforms like Salesforce and Snowflake without utilizing encryption.
Technically, the actor cluster uses a two-pronged approach: sophisticated vishing campaigns that leverage adversary-in-the-middle (AitM) reverse-proxies to steal SSO sessions, and mass exploitation of CVE-2026-35273 in Oracle PeopleSoft. In recent campaigns, they have successfully bypassed WAF protections by utilizing URL-encoded path variants (e.g., /%50SEMHUB/) to deliver web shells, the SIDEEYE backdoor, and custom MeshCentral agents disguised as legitimate Azure binaries.
This activity represents a critical risk to the healthcare sector as it bypasses traditional ransomware recovery strategies. With third-party vendors involved in 32% of healthcare breaches, the amplification effect of a single compromise—such as the Aesto Health breach affecting 9.5 million patients—highlights a structural vulnerability in vendor-managed SaaS and EHR environments.
Key Details
Threat Name
ShinyHunters
Affects
Oracle PeopleSoft Enterprise PeopleTools 8.61, Oracle PeopleSoft Enterprise PeopleTools 8.62, PSEMHUB component
Adversary
ShinyHunters Other Adversaries and Aliases: Chaos; GENESIS; Anubis
MITRE Techniques
Malware/Tools
Chaos, GENESIS, SIDEEYE, MeshCentral, Anubis
