logo

Inside an Oracle Database SQL Injection Attack | Huntress

ID: 2912b9f4-baaa-51f8-9a8f-749374368d9e

STIX ID: report--2912b9f4-baaa-51f8-9a8f-749374368d9e

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-08-05

Date Updated: 2026-08-19

...
...

On July 27, 2026 Huntress investigated an SQL injection attack against a public-facing Java/Tomcat application backed by Oracle. The attackers used CREATE JAVA SOURCE via the JDBC connection to install a database-resident post-exploitation toolkit called 'khunt', achieved SYSTEM-level RCE, dumped registry hives (SAM/SECURITY/SYSTEM) for credential extraction, and collected task/service listings; the report includes IOCs (file paths, object names, attacker IP) and mitigation guidance to prevent SQLi and overprivileged DB accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.