SIDEEYE is a C++ backdoor deployed on compromised Windows servers by UNC6240, a threat activity cluster associated with ShinyHunters. It steals credentials from browsers and desktop applications, supports file and process management, and provides interactive reverse-shell and reverse-proxy functionality. It communicates with command-and-control infrastructure over raw TCP, using separate connections for control and data.
SIDEEYE is delivered through a trojanized Light Alloy media-player installer bearing a valid digital signature. The installer uses a multistage execution chain that decrypts embedded data and loads the backdoor into memory; observed delivery samples are protected with VMProtect. Operators have transferred the installer through JSP web shells after exploiting Oracle PeopleSoft vulnerability CVE-2026-35273. SIDEEYE has been deployed as a post-exploitation tool in campaigns targeting PeopleSoft environments worldwide across higher education, technology, IT services, healthcare, agriculture, transportation, and government. Its credential-access and remote-control functions support the operators' broader data-theft and extortion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ShinyHunters (UNC6240) resumed mass exploitation of CVE-2026-35273, a critical unauthenticated remote-code-execution vulnerability in Oracle PeopleSoft. Attackers bypassed path-based WAF rules with /%50SEMHUB/hub, which WebLogic normalizes to the vulnerable /PSEMHUB/hub servlet. | On Windows servers, attackers upload and run Ple64.exe, which loads the SIDEEYE backdoor in memory. SIDEEYE communicates with its command-and-control server over raw TCP on ports 3333 and 3334.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On Windows servers, attackers upload and run Ple64.exe, which loads the SIDEEYE backdoor in memory. SIDEEYE communicates with its command-and-control server over raw TCP on ports 3333 and 3334.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
“x.jsp accepts hex-encoded commands via HTTP POST” and reconstructs “/bin/sh from an ASCII character array to avoid static string signatures.”
SIDEEYE, a C++ backdoor delivered as Ple64.exe , a trojanized Light Alloy installer signed with a valid EV certificate and packed with VMProtect.
This installer loads a second-stage launcher, which decrypts data embedded within Ple64.exe to load and execute the SIDEEYE C++ backdoor.
Some were disguised as Microsoft Azure-related services to avoid detection. On Windows servers, attackers upload and run Ple64.exe. The file poses as a signed installer for the Light Alloy media player.
[They deployed] a trojanized installer called Ple64.exe, which is disguised as an installer for the Light Alloy media player.
SIDEEYE capabilities are described as "all communicating out to attacker infrastructure."
SIDEEYE... gives the actor a reverse shell and proxy. Neo-reGeorg tunnels ( tunnel.jsp, tunnel.jspx ) for moving into the internal network.
SIDEEYE provides reverse-proxy functionality, and the actor uploaded the Neo-reGeorg tunneling toolkit.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
In-memory backdoor delivered through a trojanized signed installer. It steals credentials from browsers and desktop applications, supports file and process management, provides an interactive reverse shell, and can operate as a reverse proxy to attacker-controlled infrastructure.
C++ backdoor that steals browser and application credentials, manages files and processes, and provides reverse-shell and reverse-proxy access.
An in-memory backdoor deployed following PeopleSoft exploitation. It provides credential theft, process and file management, interactive reverse-shell access, and reverse-proxy capabilities.
An in-memory backdoor delivered through a trojanized installer to compromised Windows PeopleSoft servers. It supports credential theft, file and process management, interactive reverse-shell access, and proxying.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.