logo

SQL Injection Attack Enables Malware Deployment in Oracle Database

ID: 082bc25c-fa21-5051-a70b-0fadea900916

STIX ID: report--082bc25c-fa21-5051-a70b-0fadea900916

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

...
...

On July 27, 2026 Huntress observed an SQL injection against a public-facing Java application that allowed attackers to upload a post-exploitation toolkit called 'khunt' into an Oracle database; the toolkit used Oracle's embedded Java to achieve SYSTEM-level command execution on the Windows host and to dump registry hives for possible credential theft. The incident highlights a shift where databases are used as attack platforms and underscores the need for input validation and strict database privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.