SQL Injection Turns an Oracle Database into a Platform for Windows Attacks
Exploits SQL injection in Oracle databases to deploy the khunt toolkit, enabling Windows attacks and credential dumping, with risk reduction tips.
Illustrative image generated with AI
Initial Access Through a Search Endpoint
On July 27, 2026, Huntress identified credential theft activity on a server hosting an Oracle database.
The intrusion appears to have begun with SQL injection against a public search and autocomplete endpoint. The feature was integrated into a Java application running on Apache Tomcat and did not properly validate incoming input.
The attackers were therefore able to insert SQL commands into requests sent to the database. The malicious activity was traced to 178.162.151[.]229.
The versions of Oracle, Apache Tomcat, Java and Windows involved have not been disclosed.
Khunt Installed Directly in the Oracle Schema
Rather than copying an executable to the server, the attackers inserted the khunt post-exploitation toolkit into the database as a Java object.
The technique leverages Oracle’s embedded JVM and the CREATE JAVA SOURCE statement, which allows Java code to be stored and compiled within the schema. The resulting objects can then be invoked through SQL.
When the necessary permissions are available, these objects can execute commands on the operating system. Huntress describes this approach as rarely documented in real-world attacks.
The toolkit includes several modules:
- KhuntCmd, for executing commands through
cmd.exeand SQL statements; - KhuntHash, for accessing Oracle’s internal user table and writing usernames and passwords to a file;
- KhuntFS and KhuntFS2, for browsing, reading, searching, and checking file sizes;
- KhuntT, for verifying whether the installation succeeded;
- KhuntUnzip, for extracting compressed archives;
- PL/SQL wrappers for command execution, credential theft, and file management.
Windows Commands and Possible Credential Dumping
The attackers executed:
cmd.exe /c whoami
The output indicated SYSTEM privileges on the Windows server, the highest operating privilege level described in the case.
They subsequently used PowerShell and Windows utilities to copy the SAM, SECURITY, and SYSTEM registry hives. These files can be used to recover password hashes for local accounts.
Huntress considers credential dumping likely, but has not confirmed that the hives were actually exfiltrated from the system.
The attackers also ran:
tasklist /svc
The output, containing a list of active processes and services, was saved to khunttasks.txt.
This attack chain turned the Oracle database into a persistence and high-privilege execution point within the corporate network. The source does not assign a CVSS score or formal classification, but the operational significance is high.
Controls and Risk-Reduction Measures
Exposed applications must validate and sanitize all input, including search and autocomplete functions. Accounts used to connect to Oracle should also have only the permissions they strictly require.
In particular, these accounts should be prevented from:
- creating Java sources through
CREATE JAVA SOURCE; - executing unnecessary stored procedures;
- performing administrative operations on the database or operating system.
Security teams should review Apache logs and anomalous SQL queries, while also looking for the creation of Oracle Java objects.
On Windows systems, teams should monitor the launch of cmd.exe, PowerShell, and tasklist, as well as access to or copying of the SAM, SECURITY, and SYSTEM hives. Each indicator in isolation may have a legitimate explanation; their combination requires immediate investigation.
Sources
This article is an original reworking based on the sources below.




