www.infosecurity-magazine.com 8/6/2026, 3:59:37 PM · external

Khunt toolkit hides in Oracle DB, hijacks Windows via SQLi

Khunt toolkit hides in Oracle DB, hijacks Windows via SQLi
CyberSIXT Evidence Panel
Primary Source huntress.com

A toolkit named 'khunt' has been discovered embedded within an Oracle database, allowing attackers to execute commands on the associated Windows server without detection from conventional security tools. The intrusion was detected by Huntress on July 27 following credential theft alerts. The attack exploited an SQL injection vulnerability in a public-facing Java application, which passed unvalidated input to the database.

The khunt toolkit comprised modules for various malicious actions, such as opening command shells and dumping credentials, leveraging the database's Java Virtual Machine. This incident highlights the need for improved input sanitization and user permission management to prevent such exploits.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT