SQL Injection Attack Leads to Malware Hosting in Oracle Database

SQL Injection Attack Leads to Malware Hosting in Oracle Database

First seen 6 Aug 2026, 12:37 UTC Huntressmedium.comBleepingcomputerCsoonline 80% similarity 69.0

Article Content

Browse articles
ThreatCluster

On July 27, 2026, Huntress identified a SQL injection attack that allowed threat actors to install a post-exploitation toolkit named Khunt directly within an Oracle database. The attackers exploited a vulnerability in a public-facing Java application that failed to validate user input, enabling them to execute SQL commands. They utilized Oracle's embedded Java Virtual Machine to upload and compile malicious Java code, which facilitated SYSTEM-level command execution on the compromised Windows server. The attack resulted in the theft of sensitive credentials by dumping registry hives (SAM, SECURITY, SYSTEM). Huntress traced the attack to the IP address 178.162.151[.]229. The use of this technique, while rarely documented, demonstrates a sophisticated approach to maintaining persistence and evading detection. Organizations are advised to implement strict input validation and limit database account privileges to mitigate similar attacks.

Key Points: • Attackers exploited a SQL injection vulnerability in a public-facing Java application. • Malware named Khunt was installed directly in the Oracle database using Java capabilities. • The attack led to credential theft through the dumping of Windows registry hives.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
SQL injection attack detected
Huntress discovered credential theft activity on an Oracle database server, traced to a SQL injection vulnerability.
Huntress
2026-07-27
Khunt toolkit installed
Attackers uploaded and compiled a post-exploitation toolkit named Khunt directly within the Oracle database.
Csoonline
2026-08-05
Attack details published
Huntress published findings detailing the SQL injection attack and the use of Khunt for credential theft.
Huntress
2026-08-06
Further reporting on attack
CSO Online and BleepingComputer reported on the attack's implications and the sophisticated use of Oracle's Java capabilities.
Csoonline

Community

Browse all →