Threat reportVulnerabilityTL-2026-2067
khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation
khunt Toolkit (TL-2026-2067), also tracked as khunt, is a high-severity software vulnerability, first published 2026-08-18. It has no confirmed attribution, affects Unspecified Public-facing Java/Apache Tomcat web application, maps to 10 MITRE ATT&CK techniques (T1003, T1003.002, T1005), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-2067
- Threat ID
- TL-2026-2067
- Also known as
- khunt, KHunt Toolkit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in khunt Toolkit
Malware and tooling: khunt, Reg - S0075, cmd - S0106, esentutl - S0404
How khunt Toolkit works
Threat actors exploited an unauthenticated SQL injection flaw in a public-facing Java/Tomcat application's autocomplete search feature to reach an over-permissioned Oracle JDBC account, then used Oracle's CREATE JAVA SOURCE statement to compile the 'khunt' post-exploitation toolkit as database schema objects. Khunt gave the attackers SYSTEM-level OS command execution, Oracle credential-table dumping, file-system enumeration, and archive handling, which they used to confirm SYSTEM privileges, enumerate services, and stage copies of the SAM, SECURITY, and SYSTEM registry hives for exfiltration.
On 27 July 2026, Huntress investigated credential-theft detections on a customer's Windows server hosting Oracle Database and traced the activity back to an unauthenticated SQL injection vulnerability in the autocomplete search feature of a public-facing Java/Apache Tomcat web application. The application passed unvalidated user input directly into SQL statements executed over a JDBC connection using a database account that was permissioned to create Java objects — no novel or exotic vulnerability was required, since the autocomplete field alone was sufficient to reach PL/SQL and, from there, the underlying operating system.
Rather than dropping a conventional OS-level binary, the attackers abused Oracle's embedded Java Virtual Machine and its CREATE JAVA SOURCE statement to compile malicious Java code directly into the database as compiled schema objects, paired with khunt_-prefixed PL/SQL wrapper procedures that exposed the underlying Java methods to ordinary SQL calls. Because the payload lives as Java classes and PL/SQL wrappers inside the database rather than as files or processes on disk, it falls outside the visibility of most endpoint security tooling, which is built to inspect processes, binaries, and the filesystem rather than database schema objects.
The resulting toolkit, dubbed 'khunt', consists of six named Java objects: KhuntCmd (loads cmd.exe to run arbitrary OS commands issued as SQL), KhuntHash (extracts usernames and password data from Oracle's internal user tables to a file), KhuntFS and KhuntFS2 (file-system explorers for listing, reading, searching, and sizing files), KhuntT (a toolkit-reachability/connectivity check), and KhuntUnzip (archive decompression). Huntress noted the architecture closely mirrors Marco Ivaldi's 2006 raptor_oraexec.sql exploitation suite — a Java-source-object-plus-PL/SQL-wrapper technique for Oracle RCE that has long been publicly documented but, per Huntress, rarely observed exploited in the wild until this incident.
Using khunt, the attackers ran `cmd.exe /c whoami` via KhuntCmd to confirm that commands executed through the Oracle database inherited SYSTEM-level privileges on the underlying Windows host — a consequence of the Oracle service account itself running as SYSTEM. They then ran `tasklist /svc` to enumerate running services (saved as khunttasks.txt) and used `reg.exe` save operations together with `esentutl.exe` (the Extensible Storage Engine utility, used to copy files normally locked by the OS) to copy the SAM, SECURITY, and SYSTEM registry hives, staging the resulting .hiv files under an `F:\Oracle\` directory ahead of likely exfiltration. Huntress's investigation did not confirm that exfiltration of the staged hives actually completed. No CVE was assigned, since the root cause is an application-specific input-validation failure combined with database-account overprovisioning rather than a product vulnerability; no CVSS score was published by the source. Huntress publicly disclosed the technique, IOCs, and hunting guidance on 5 August 2026, and it was subsequently covered by BleepingComputer, The Hacker News, CSO Online, GBHackers, and Infosecurity Magazine, among others.
MITRE ATT&CK techniques used in TL-2026-2067
Credential Access
T1003 OS Credential Dumping; T1003.002 Security Account Manager
Collection
T1005 Data from Local System; T1074.001 Local Data Staging
Discovery
T1007 System Service Discovery; T1033 System Owner/User Discovery
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell
Initial Access
T1190 Exploit Public-Facing Application
Persistence
Affected products and versions in khunt Toolkit
- Unspecified — Public-facing Java/Apache Tomcat web application (autocomplete search feature) with Oracle JDBC backend
Vulnerable versions: Application-specific SQL injection flaw; no product version disclosed - Oracle — Oracle Database (embedded Java Virtual Machine / CREATE JAVA SOURCE capability)
Vulnerable versions: Any Oracle Database instance with JVM enabled and a JDBC application account permissioned to CREATE JAVA SOURCE
Remediation for khunt Toolkit
Immediate actions
- Search Oracle schema objects and stored-procedure catalogs for names matching 'Khunt%' or unexpected CREATE JAVA SOURCE objects
- Review SQL/audit logs for 'KHUNT%' patterns and for unexpected CREATE JAVA SOURCE / CREATE PROCEDURE statements originating from application service accounts
- Check for staged registry hive exports (SAM/SECURITY/SYSTEM .hiv files) in unusual locations such as application data directories
- Rotate credentials for any Oracle JDBC service account used by the affected public-facing application
Workarounds
- Disable or restrict the JVM/CREATE JAVA SOURCE capability on Oracle instances that do not require it
- Ensure the autocomplete/search input in the affected application is fully parameterized and does not concatenate user input into SQL
Longer-term hardening
- Enforce least-privilege on database accounts used by public-facing applications: remove CREATE JAVA SOURCE, CREATE PROCEDURE, and other administrative privileges that are unnecessary for normal application function
- Deploy database-activity monitoring capable of alerting on Java class compilation and PL/SQL wrapper creation, since endpoint/EDR tooling does not inspect in-database schema objects
- Run the Oracle listener and RDBMS service account with the minimum OS privileges required, rather than as SYSTEM/root, to limit blast radius of any in-database code execution
Weaknesses (CWE) in khunt Toolkit
Timeline of khunt Toolkit
- Attacker uses reg.exe and esentutl.exe to copy the SAM, SECURITY, and SYSTEM registry hives, staging them as khuntSAM.hiv, khuntSECURITY.hiv, khunt_SECURITY.hiv, and khuntSYSTEM.hiv under F:\Oracle\ ahead of likely exfiltration
- Attacker runs `tasklist /svc` to enumerate running Windows services, saving output to khunttasks.txt
- Attacker runs `cmd.exe /c whoami` via KhuntCmd, confirming OS commands issued through Oracle execute with SYSTEM-level privileges on the Windows host
- Attacker uses CREATE JAVA SOURCE statements to compile the khunt Java objects (KhuntCmd, KhuntHash, KhuntFS, KhuntFS2, KhuntT, KhuntUnzip) and PL/SQL wrappers into the database schema
- Attacker exploits the unauthenticated SQL injection flaw in the application's autocomplete search feature, reaching the Oracle JDBC backend from source IP 178.162.151.229
- Huntress investigates credential-theft detections on a customer's Oracle Database server, initiating the incident response that uncovers the khunt toolkit
- BleepingComputer, The Hacker News, CSO Online, GBHackers, and Infosecurity Magazine republish and analyze the Huntress findings
- Huntress publishes 'Inside an Oracle Database SQL Injection Attack', detailing the khunt toolkit, attack chain, IOCs, and hunting guidance
Sources cited for khunt Toolkit
- Inside an Oracle Database SQL Injection Attack
- Hackers run khunt post-exploitation toolkit from Oracle database
- Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
- Attackers hid malware inside Oracle Database after SQL injection breach
- KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
- Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
- raptor_oraexec.sql — Oracle Java-source-object RCE exploitation suite (2006)
Detection coverage for TL-2026-2067
As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2067 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.