Inside an Oracle Database SQL Injection Attack | Huntress
Cybersecurity Classified by Officially
Huntress recently observed an incident that started with a "simple" SQL injection bug in an organization's vulnerable public-facing web app, and ended with OS-level remote code execution
Notably, after gaining initial access the threat actor dropped a post-exploitation toolkit (khunt) via a Java Source within an Oracle database, which is a novel aspect of this attack. A Java Source (a code-object that's stored directly in Oracle's database engine) allows developers to store and run Java code in the database as schema objects, but the threat actor abused this as a way to upload the toolkit directly into the database.
The toolkit included several objects, including khuntCmd and khuntHash, which essentially acted as purpose-built tools that were compiled and stored in the database, and enabled malicious functionalities like running OS commands and writing usernames/password data to a file
Threat actors used khunt to perform several malicious measures, including attempting to exfiltrate SAM, SECURITY, and SYSTEM registry hives
Acknowledgments: Special thanks to Lindsey O'Donnell-Welch for contributions to this investigation and write-up.
On July 27, 2026 Huntress was alerted to credential theft activity on an endpoint hosting an Oracle database server. The attacker had managed to make copies of several registry hives (SAM, SECURITY, SYSTEM) likely for exfiltration and to dump credentials contained within.
Upon further investigation, Huntress researchers determined that this attack was the result of a SQL injection (SQLi) attack. SQLi attacks have existed for decades, and are often the result of mishandling inputs going to the SQL server, as opposed to exploitable vulnerabilities.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/khunt-malware-sql-injection-oracle
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/khunt-malware-sql-injection-oracle