A small Windows batch file named cs_disable.cmd turned up inside one victim of ShinyHunters' Oracle PeopleSoft campaign. Its job, according to the incident responders who found it, was to switch off CrowdStrike's endpoint protection.
The detail comes from a report published on October 1 by Sekoia's Threat Detection and Research (TDR) team, written by Enzo Saez, Robert (Bobby) Venal and the TDR team and co-authored with Beazley Security. Most of the original report traces six years of the extortion brand's history, but its newest material is first-hand: Beazley Security's DFIR team worked a breach in May 2026 that was eventually confirmed as part of the PeopleSoft wave exploiting CVE-2026-35273, the critical remote code execution flaw Google tied to ShinyHunters in June.
What responders found after the break-in
Google's earlier reporting showed how the crew got in and how it staged its tooling. The Beazley case shows what it did once inside a victim network:
- Persistence: small JSP backdoors (web shells, meaning scripts that let an attacker run commands through the web server) planted on compromised PeopleSoft servers, including one named orau.jsp.
- Lateral movement: mostly Remote Desktop (RDP) sessions using compromised credentials, with Pass-the-Hash also observed. The open source tunnelling tool Chisel was used to carry those RDP sessions.
- Staying hidden: many hosts ran malicious scheduled tasks executing obfuscated PowerShell, and many of those hosts had PowerShell monitoring disabled. Responders also recovered the small Windows script that disables CrowdStrike's EDR.
- Control and theft: MeshAgent, the agent of the open source MeshCentral remote management platform, served as command and control, matching Google's findings, and the file transfer utility Rclone was used when exfiltration was attempted.
Sekoia's indicator table lists several recovered files, including the MeshAgent configuration and an egress test script, as redacted.
A brand, not a gang
The wider report argues that ShinyHunters is best understood as a financially motivated data theft and extortion brand rather than a fixed group, surviving arrests, indictments and forum seizures since 2020. Sekoia assesses with high confidence that it is linked to "The Com", the cybercrime community that also produced Scattered Spider and Lapsus$. In 2026 Google tracks the intrusion clusters behind the activity as UNC6661 and UNC6671, with UNC6240 acting as the extortion arm that claims the data.
Two warnings stand out. The group's publicised breach figures have repeatedly outstripped what victim companies later confirm, so every claim needs independent verification. And Sekoia reports that the long promised shinysp1d3r ransomware has moved toward a functional, tested payload, though with no known victims as of mid-2026.
Patch PeopleSoft, then hunt for these traces
Organizations running PeopleSoft should apply Oracle's June 10 Security Alert for CVE-2026-35273 rather than relying on firewall path rules, which the crew has already learned to sidestep. Sekoia's published hunting queries look for:
- cs_disable.cmd under C:\Windows\Temp\.bea-cache\ (SHA256 fa210f015399de16bf7cb1e05856d179dfaabb1ecc9bb5fd277f94972a3bdc43)
- orau.jsp (SHA256 d5efdf6f35e9c6edcad5fbec707e6c88570c9d8796bf089c29303d591b94e384) and a second web shell named webpack
- a scheduled task named MeshFwFix, and a modified MeshAgent binary at C:\Windows\Temp\ma.exe
- traffic to azurenetfiles[.]net or 142[.]11[.]200[.]186
Any host where PowerShell logging or endpoint protection has quietly gone dark deserves a closer look too. The lesson of six years of ShinyHunters is that the people change and the platforms change, but the business keeps finding whichever trust gap is cheapest to exploit at scale.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.