Threat reportVulnerabilityTL-2026-2067

khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation

highACTIVE

khunt Toolkit (TL-2026-2067), also tracked as khunt, is a high-severity software vulnerability, first published 2026-08-18. It has no confirmed attribution, affects Unspecified Public-facing Java/Apache Tomcat web application, maps to 10 MITRE ATT&CK techniques (T1003, T1003.002, T1005), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-2067

Threat ID
TL-2026-2067
Also known as
khunt, KHunt Toolkit
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
8

Malware and tooling in khunt Toolkit

Malware and tooling: khunt, Reg - S0075, cmd - S0106, esentutl - S0404

How khunt Toolkit works

Threat actors exploited an unauthenticated SQL injection flaw in a public-facing Java/Tomcat application's autocomplete search feature to reach an over-permissioned Oracle JDBC account, then used Oracle's CREATE JAVA SOURCE statement to compile the 'khunt' post-exploitation toolkit as database schema objects. Khunt gave the attackers SYSTEM-level OS command execution, Oracle credential-table dumping, file-system enumeration, and archive handling, which they used to confirm SYSTEM privileges, enumerate services, and stage copies of the SAM, SECURITY, and SYSTEM registry hives for exfiltration.

On 27 July 2026, Huntress investigated credential-theft detections on a customer's Windows server hosting Oracle Database and traced the activity back to an unauthenticated SQL injection vulnerability in the autocomplete search feature of a public-facing Java/Apache Tomcat web application. The application passed unvalidated user input directly into SQL statements executed over a JDBC connection using a database account that was permissioned to create Java objects — no novel or exotic vulnerability was required, since the autocomplete field alone was sufficient to reach PL/SQL and, from there, the underlying operating system.

Rather than dropping a conventional OS-level binary, the attackers abused Oracle's embedded Java Virtual Machine and its CREATE JAVA SOURCE statement to compile malicious Java code directly into the database as compiled schema objects, paired with khunt_-prefixed PL/SQL wrapper procedures that exposed the underlying Java methods to ordinary SQL calls. Because the payload lives as Java classes and PL/SQL wrappers inside the database rather than as files or processes on disk, it falls outside the visibility of most endpoint security tooling, which is built to inspect processes, binaries, and the filesystem rather than database schema objects.

The resulting toolkit, dubbed 'khunt', consists of six named Java objects: KhuntCmd (loads cmd.exe to run arbitrary OS commands issued as SQL), KhuntHash (extracts usernames and password data from Oracle's internal user tables to a file), KhuntFS and KhuntFS2 (file-system explorers for listing, reading, searching, and sizing files), KhuntT (a toolkit-reachability/connectivity check), and KhuntUnzip (archive decompression). Huntress noted the architecture closely mirrors Marco Ivaldi's 2006 raptor_oraexec.sql exploitation suite — a Java-source-object-plus-PL/SQL-wrapper technique for Oracle RCE that has long been publicly documented but, per Huntress, rarely observed exploited in the wild until this incident.

Using khunt, the attackers ran `cmd.exe /c whoami` via KhuntCmd to confirm that commands executed through the Oracle database inherited SYSTEM-level privileges on the underlying Windows host — a consequence of the Oracle service account itself running as SYSTEM. They then ran `tasklist /svc` to enumerate running services (saved as khunttasks.txt) and used `reg.exe` save operations together with `esentutl.exe` (the Extensible Storage Engine utility, used to copy files normally locked by the OS) to copy the SAM, SECURITY, and SYSTEM registry hives, staging the resulting .hiv files under an `F:\Oracle\` directory ahead of likely exfiltration. Huntress's investigation did not confirm that exfiltration of the staged hives actually completed. No CVE was assigned, since the root cause is an application-specific input-validation failure combined with database-account overprovisioning rather than a product vulnerability; no CVSS score was published by the source. Huntress publicly disclosed the technique, IOCs, and hunting guidance on 5 August 2026, and it was subsequently covered by BleepingComputer, The Hacker News, CSO Online, GBHackers, and Infosecurity Magazine, among others.

MITRE ATT&CK techniques used in TL-2026-2067

Credential Access

T1003 OS Credential Dumping; T1003.002 Security Account Manager

Collection

T1005 Data from Local System; T1074.001 Local Data Staging

Discovery

T1007 System Service Discovery; T1033 System Owner/User Discovery

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.001 SQL Stored Procedures

Affected products and versions in khunt Toolkit

  • Unspecified — Public-facing Java/Apache Tomcat web application (autocomplete search feature) with Oracle JDBC backend
    Vulnerable versions: Application-specific SQL injection flaw; no product version disclosed
  • Oracle — Oracle Database (embedded Java Virtual Machine / CREATE JAVA SOURCE capability)
    Vulnerable versions: Any Oracle Database instance with JVM enabled and a JDBC application account permissioned to CREATE JAVA SOURCE

Remediation for khunt Toolkit

Immediate actions

  • Search Oracle schema objects and stored-procedure catalogs for names matching 'Khunt%' or unexpected CREATE JAVA SOURCE objects
  • Review SQL/audit logs for 'KHUNT%' patterns and for unexpected CREATE JAVA SOURCE / CREATE PROCEDURE statements originating from application service accounts
  • Check for staged registry hive exports (SAM/SECURITY/SYSTEM .hiv files) in unusual locations such as application data directories
  • Rotate credentials for any Oracle JDBC service account used by the affected public-facing application

Workarounds

  • Disable or restrict the JVM/CREATE JAVA SOURCE capability on Oracle instances that do not require it
  • Ensure the autocomplete/search input in the affected application is fully parameterized and does not concatenate user input into SQL

Longer-term hardening

  • Enforce least-privilege on database accounts used by public-facing applications: remove CREATE JAVA SOURCE, CREATE PROCEDURE, and other administrative privileges that are unnecessary for normal application function
  • Deploy database-activity monitoring capable of alerting on Java class compilation and PL/SQL wrapper creation, since endpoint/EDR tooling does not inspect in-database schema objects
  • Run the Oracle listener and RDBMS service account with the minimum OS privileges required, rather than as SYSTEM/root, to limit blast radius of any in-database code execution

Weaknesses (CWE) in khunt Toolkit

CWE-89

Timeline of khunt Toolkit

  • Attacker uses reg.exe and esentutl.exe to copy the SAM, SECURITY, and SYSTEM registry hives, staging them as khuntSAM.hiv, khuntSECURITY.hiv, khunt_SECURITY.hiv, and khuntSYSTEM.hiv under F:\Oracle\ ahead of likely exfiltration
  • Attacker runs `tasklist /svc` to enumerate running Windows services, saving output to khunttasks.txt
  • Attacker runs `cmd.exe /c whoami` via KhuntCmd, confirming OS commands issued through Oracle execute with SYSTEM-level privileges on the Windows host
  • Attacker uses CREATE JAVA SOURCE statements to compile the khunt Java objects (KhuntCmd, KhuntHash, KhuntFS, KhuntFS2, KhuntT, KhuntUnzip) and PL/SQL wrappers into the database schema
  • Attacker exploits the unauthenticated SQL injection flaw in the application's autocomplete search feature, reaching the Oracle JDBC backend from source IP 178.162.151.229
  • Huntress investigates credential-theft detections on a customer's Oracle Database server, initiating the incident response that uncovers the khunt toolkit
  • BleepingComputer, The Hacker News, CSO Online, GBHackers, and Infosecurity Magazine republish and analyze the Huntress findings
  • Huntress publishes 'Inside an Oracle Database SQL Injection Attack', detailing the khunt toolkit, attack chain, IOCs, and hunting guidance

Sources cited for khunt Toolkit

Detection coverage for TL-2026-2067

As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2067 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats