KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
ID: 85fb63ae-9d4c-51b7-b25f-03a84723088e
STIX ID: report--85fb63ae-9d4c-51b7-b25f-03a84723088e
Feed Name: GBHackers
Threat Score
**KHunt intrusion summary:** Attackers leveraged a SQL injection in a Java/Tomcat application to push Java source into Oracle via CREATE JAVA SOURCE, compiled a stealthy toolkit (khunt) inside the database, achieved SYSTEM-level command execution on the Windows host, and staged registry hive copies for credential theft; Huntress observed telemetry and published IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
