{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/khunt/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Oracle Database"],"_cs_severities":["high"],"_cs_tags":["sqli","remote-code-execution","khunt","oracle","credential-theft"],"_cs_type":"advisory","_cs_vendors":["Oracle"],"content_html":"\u003cp\u003eOn July 27, 2026, researchers observed a sophisticated attack chain targeting an organization's Oracle Database server. The attackers leveraged a SQL injection vulnerability in a public-facing web application to execute malicious commands within the database engine. A novel component of this attack involved the abuse of the 'CREATE JAVA SOURCE' functionality, which permits the storage and execution of Java code directly as database schema objects. The attackers utilized this mechanism to drop and compile a custom post-exploitation toolkit dubbed 'khunt'. The toolkit, which included modules such as 'khuntCmd' and 'khuntHash', enabled the threat actor to execute arbitrary operating system commands, write data to local files, and facilitate the collection of sensitive Windows system information. This attack highlights the persistent risk of traditional SQL injection when combined with database-native code execution features.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a SQL injection vulnerability in a public-facing web application connected to an Oracle Database.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the injection vector to execute administrative SQL commands within the database engine.\u003c/li\u003e\n\u003cli\u003eThe attacker utilizes the 'CREATE JAVA SOURCE' feature to inject custom Java code into the database schema as a stored object.\u003c/li\u003e\n\u003cli\u003eThe database engine compiles the injected Java source into a malicious utility, specifically the 'khunt' toolkit components (e.g., khuntCmd).\u003c/li\u003e\n\u003cli\u003eThe attacker invokes the stored Java object via SQL to execute arbitrary commands at the OS level on the database host.\u003c/li\u003e\n\u003cli\u003eThe 'khunt' toolkit is used to interact with the Windows filesystem, specifically writing task lists and interacting with registry hive files.\u003c/li\u003e\n\u003cli\u003eThe attacker targets the SAM, SECURITY, and SYSTEM registry hives to dump credentials for offline analysis.\u003c/li\u003e\n\u003cli\u003eFinal objectives include exfiltrating these registry hives to an external, attacker-controlled server (178.162.151.229).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful deployment of the 'khunt' toolkit granted the attacker OS-level remote code execution on the database host. This enabled the unauthorized access and exfiltration of critical Windows registry hives, potentially leading to total credential compromise and further lateral movement within the victim environment. The use of legitimate database features to hide malicious logic presents a significant detection challenge.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy Sigma rules to monitor for unauthorized 'CREATE JAVA SOURCE' commands or the presence of suspicious Java source objects in Oracle databases.\u003c/li\u003e\n\u003cli\u003eBlock the identified attacker IP 178.162.151.229 at the network perimeter and egress points.\u003c/li\u003e\n\u003cli\u003eAudit Oracle database logs for the execution of Java objects, specifically monitoring for instances containing the string 'KHUNT%'.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all web applications interfacing with database backends to prevent SQL injection.\u003c/li\u003e\n\u003cli\u003eRestrict database service account permissions on the underlying host OS to prevent them from accessing sensitive files like registry hives (SAM, SYSTEM, SECURITY).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T20:51:07Z","date_published":"2026-08-18T20:51:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-oracle-sql-injection/","summary":"A threat actor exploited SQL injection in a public-facing application to achieve OS-level remote code execution by abusing Oracle Java Source to deploy the custom 'khunt' post-exploitation toolkit.","title":"Oracle Database SQL Injection Leads to OS-Level RCE and khunt Toolkit Deployment","url":"https://feed.craftedsignal.io/briefs/2026-08-oracle-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Khunt","version":"https://jsonfeed.org/version/1.1"}