ShinyHunters brought a CrowdStrike off-switch to PeopleSoft

Published

A small Windows batch file named cs_disable.cmd turned up inside one victim of ShinyHunters' Oracle PeopleSoft campaign. Its job, according to the incident responders who found it, was to switch off CrowdStrike's endpoint protection.

The detail comes from a report published on October 1 by Sekoia's Threat Detection and Research (TDR) team, written by Enzo Saez, Robert (Bobby) Venal and the TDR team and co-authored with Beazley Security. Most of the original report traces six years of the extortion brand's history, but its newest material is first-hand: Beazley Security's DFIR team worked a breach in May 2026 that was eventually confirmed as part of the PeopleSoft wave exploiting CVE-2026-35273, the critical remote code execution flaw Google tied to ShinyHunters in June.

What responders found after the break-in

Google's earlier reporting showed how the crew got in and how it staged its tooling. The Beazley case shows what it did once inside a victim network:

Sekoia's indicator table lists several recovered files, including the MeshAgent configuration and an egress test script, as redacted.

A brand, not a gang

The wider report argues that ShinyHunters is best understood as a financially motivated data theft and extortion brand rather than a fixed group, surviving arrests, indictments and forum seizures since 2020. Sekoia assesses with high confidence that it is linked to "The Com", the cybercrime community that also produced Scattered Spider and Lapsus$. In 2026 Google tracks the intrusion clusters behind the activity as UNC6661 and UNC6671, with UNC6240 acting as the extortion arm that claims the data.

Two warnings stand out. The group's publicised breach figures have repeatedly outstripped what victim companies later confirm, so every claim needs independent verification. And Sekoia reports that the long promised shinysp1d3r ransomware has moved toward a functional, tested payload, though with no known victims as of mid-2026.

Patch PeopleSoft, then hunt for these traces

Organizations running PeopleSoft should apply Oracle's June 10 Security Alert for CVE-2026-35273 rather than relying on firewall path rules, which the crew has already learned to sidestep. Sekoia's published hunting queries look for:

Any host where PowerShell logging or endpoint protection has quietly gone dark deserves a closer look too. The lesson of six years of ShinyHunters is that the people change and the platforms change, but the business keeps finding whichever trust gap is cheapest to exploit at scale.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions