Khunt is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
Khunt is a malware family tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed August 5, 2026; most recent activity August 6, 2026.
On July 27, 2026, Huntress identified a SQL injection attack that allowed threat actors to install a post-exploitation toolkit named Khunt directly within an Oracle database. The attackers exploited a vulnerability in a…
Khunt is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
The most recent intelligence report mentioning Khunt on ThreatCluster is dated August 6, 2026. Activity was first observed August 5, 2026, giving a tracked span from then to August 6, 2026.
Across ThreatCluster reporting, Khunt most frequently co-occurs with Malware, Sql Injection, Cwe-89 - SQL Injection, T1003 - OS Credential Dumping, T1041 - Exfiltration Over C2 Channel, among 12 tracked related entities.
The most significant recent cluster is “SQL Injection Attack Leads to Malware Hosting in Oracle Database” (5 articles · Updated August 6, 2026). Khunt appears across 1 threat cluster in total, listed above with sources.
Khunt appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.