# khunt Toolkit: SQL Injection Against Oracle/Tomcat Enables In-Database Post-Exploitation

> Threat actors exploited an unauthenticated SQL injection flaw in a public-facing Java/Tomcat application's autocomplete search feature to reach an over-permissioned Oracle JDBC account, then used Oracle's CREATE JAVA SOURCE statement to compile the 'khunt' post-exploitation toolkit as database schema objects. Khunt gave the attackers SYSTEM-level OS command execution, Oracle credential-table dumping, file-system enumeration, and archive handling, which they used to confirm SYSTEM privileges, enumerate services, and stage copies of the SAM, SECURITY, and SYSTEM registry hives for exfiltration.

- **Published:** 2026-08-18T00:00:00Z
- **Last reviewed:** 2026-08-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2067
- **ID:** TL-2026-2067
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 27 July 2026, Huntress investigated credential-theft detections on a customer's Windows server hosting Oracle Database and traced the activity back to an unauthenticated SQL injection vulnerability in the autocomplete search feature of a public-facing Java/Apache Tomcat web application. The application passed unvalidated user input directly into SQL statements executed over a JDBC connection using a database account that was permissioned to create Java objects — no novel or exotic vulnerability was required, since the autocomplete field alone was sufficient to reach PL/SQL and, from there, the underlying operating system.

Rather than dropping a conventional OS-level binary, the attackers abused Oracle's embedded Java Virtual Machine and its CREATE JAVA SOURCE statement to compile malicious Java code directly into the database as compiled schema objects, paired with khunt_-prefixed PL/SQL wrapper procedures that exposed the underlying Java methods to ordinary SQL calls. Because the payload lives as Java classes and PL/SQL wrappers inside the database rather than as files or processes on disk, it falls outside the visibility of most endpoint security tooling, which is built to inspect processes, binaries, and the filesystem rather than database schema objects.

The resulting toolkit, dubbed 'khunt', consists of six named Java objects: KhuntCmd (loads cmd.exe to run arbitrary OS commands issued as SQL), KhuntHash (extracts usernames and password data from Oracle's internal user tables to a file), KhuntFS and KhuntFS2 (file-system explorers for listing, reading, searching, and sizing files), KhuntT (a toolkit-reachability/connectivity check), and KhuntUnzip (archive decompression). Huntress noted the architecture closely mirrors Marco Ivaldi's 2006 raptor_oraexec.sql exploitation suite — a Java-source-object-plus-PL/SQL-wrapper technique for Oracle RCE that has long been publicly documented but, per Huntress, rarely observed exploited in the wild until this incident.

Using khunt, the attackers ran `cmd.exe /c whoami` via KhuntCmd to confirm that commands executed through the Oracle database inherited SYSTEM-level privileges on the underlying Windows host — a consequence of the Oracle service account itself running as SYSTEM. They then ran `tasklist /svc` to enumerate running services (saved as khunttasks.txt) and used `reg.exe` save operations together with `esentutl.exe` (the Extensible Storage Engine utility, used to copy files normally locked by the OS) to copy the SAM, SECURITY, and SYSTEM registry hives, staging the resulting .hiv files under an `F:\Oracle\` directory ahead of likely exfiltration. Huntress's investigation did not confirm that exfiltration of the staged hives actually completed. No CVE was assigned, since the root cause is an application-specific input-validation failure combined with database-account overprovisioning rather than a product vulnerability; no CVSS score was published by the source. Huntress publicly disclosed the technique, IOCs, and hunting guidance on 5 August 2026, and it was subsequently covered by BleepingComputer, The Hacker News, CSO Online, GBHackers, and Infosecurity Magazine, among others.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1505.001 SQL Stored Procedures
- T1059.003 Windows Command Shell
- T1059.001 PowerShell
- T1033 System Owner/User Discovery
- T1007 System Service Discovery
- T1003 OS Credential Dumping
- T1003.002 Security Account Manager
- T1005 Data from Local System
- T1074.001 Local Data Staging

## Sources

- [Inside an Oracle Database SQL Injection Attack](https://www.huntress.com/blog/khunt-malware-sql-injection-oracle)
- [Hackers run khunt post-exploitation toolkit from Oracle database](https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database/)
- [Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access](https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html)
- [Attackers hid malware inside Oracle Database after SQL injection breach](https://www.csoonline.com/article/4206096/attackers-hid-malware-inside-oracle-database-after-sql-injection-breach.html)
- [KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft](https://gbhackers.com/khunt-exposes-credentials/)
- [Toolkit Hidden Inside Oracle Database Evades Endpoint Tools](https://www.infosecurity-magazine.com/news/khunt-toolkit-oracle-database-sql/)
- [raptor_oraexec.sql — Oracle Java-source-object RCE exploitation suite (2006)](https://github.com/0xdea/exploits/blob/master/oracle/raptor_oraexec.sql)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2067
