Attackers exploited a classic SQL injection flaw in a public-facing Java application on Apache Tomcat to compromise an Oracle database server and deploy a custom post-exploitation toolkit, khunt, directly inside the database. Huntress reported that the intruders abused Oracle's CREATE JAVA SOURCE capability and embedded JVM to upload and compile Java modules as database objects, then exposed them through PL/SQL wrappers. The toolkit provided operating system command execution, file access, archive extraction, installation checks, and credential access from Oracle user tables, turning the database itself into a stealthy execution platform rather than limiting the intrusion to data theft or manipulation.
The attackers then pivoted from the Oracle database to the underlying Windows host and executed commands with SYSTEM-level privileges, enumerated running services, and copied the SAM, SECURITY, and SYSTEM registry hives using PowerShell and native Windows tools, indicating likely preparation for credential dumping and broader lateral movement. Huntress said the activity was detected after credential-theft behavior was observed on July 27 and linked initial access to requests from 178.162.151[.]229, warning that database-resident Java classes and PL/SQL objects can create a detection blind spot for many endpoint security tools if public-facing applications retain excessive database privileges.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-06, Huntress published a detailed incident response report describing the SQL-injection-to-Oracle attack chain, including use of the khunt toolkit and fileless Java-based post-exploitation inside Oracle. The report highlighted abuse of CREATE JAVA privileges and OS command execution from the database on Windows hosts.
On 2026-07-27, Huntress investigated suspicious activity on an endpoint hosting the Oracle database server and detected credential-theft-related activity, including attempts to copy the SAM, SECURITY, and SYSTEM registry hives. This investigation led to discovery of the broader intrusion chain.
Huntress shared indicators of compromise for the Oracle intrusion, including file hashes, malicious Java artifacts, SQL statements, and search terms. The firm also advised defenders to inspect Oracle environments for unexpected Java source objects, compiled Java classes, and stored procedures tied to OJVM abuse.
Following the pivot to Windows, the attackers used PowerShell and native Windows tools to copy the SAM, SECURITY, and SYSTEM registry hives and ran tasklist /svc to enumerate running services. Outputs were saved on the compromised host, indicating likely preparation for credential dumping or further post-compromise activity.
Using khunt's command-execution functionality, the attackers ran operating system commands from the Oracle database on the underlying Windows server. A whoami command confirmed the activity was executing with SYSTEM-level privileges.
After gaining database access, the attackers used Oracle's CREATE JAVA SOURCE capability to upload and compile a custom Java-based post-exploitation toolkit named khunt directly inside the database engine. The toolkit was stored as Oracle schema objects with PL/SQL wrappers for execution.
Attackers abused an input-validation flaw in a public-facing web application, including a vulnerable autocomplete/search feature in a Java application on Apache Tomcat, to execute SQL against an Oracle database. Huntress traced malicious requests to IP address 178.162.151[.]229.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecert.ug
Open sourcecyberveille.ch
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.