logo

KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft

ID: 85fb63ae-9d4c-51b7-b25f-03a84723088e

STIX ID: report--85fb63ae-9d4c-51b7-b25f-03a84723088e

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Mayura Kathir

...
...

**KHunt intrusion summary:** Attackers leveraged a SQL injection in a Java/Tomcat application to push Java source into Oracle via CREATE JAVA SOURCE, compiled a stealthy toolkit (khunt) inside the database, achieved SYSTEM-level command execution on the Windows host, and staged registry hive copies for credential theft; Huntress observed telemetry and published IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.