SQL Injection Attack Planted Credential-Stealing Toolkit Inside Oracle Database
On July 27, 2026, cybersecurity firm Huntress detected a credential theft incident targeting an Oracle Database server via a SQL injection flaw in a public Apache Tomcat application's autocomplete feature. The attacker exploited poor input validation to execute a CREATE JAVA SOURCE command through an over-privileged JDBC connection, embedding a custom toolkit called 'khunt' directly as a compiled Oracle schema object. Once resident inside the database, khunt's components ran OS commands through oracle.exe with SYSTEM-level privileges, enabling filesystem enumeration, registry hive dumping, and credential harvesting from Oracle's internal user table. Tools including cmd.exe, PowerShell, reg.exe, and esentutl.exe were spawned from oracle.exe to copy SAM and SECURITY hives, which were staged on the Oracle data drive. Because the malicious toolkit existed as a database object rather than a conventional executable, many endpoint detection and antivirus tools failed to flag its initial deployment.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in