{"id":561,"date":"2026-08-07T14:48:02","date_gmt":"2026-08-07T09:18:02","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=561"},"modified":"2026-08-18T14:55:34","modified_gmt":"2026-08-18T09:25:34","slug":"khunt-toolkit-runs-inside-oracle-database-after-sql-injection","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/","title":{"rendered":"khunt Toolkit Runs Inside Oracle Database After SQL Injection"},"content":{"rendered":"<h2>How did the khunt toolkit attack work?<\/h2>\n<p>The khunt toolkit was installed directly inside an Oracle database after attackers exploited a SQL injection vulnerability in a public-facing Java application. Rather than relying on a conventional executable payload, the attackers abused Oracle&#8217;s Java functionality and later achieved SYSTEM-level command execution on the underlying Windows server.<\/p>\n<table style=\"font-weight: 400; width: 98.0779%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Attack stage<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Observed activity<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Initial access<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">SQL injection through a Java autocomplete feature<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Application server<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Apache Tomcat<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Database<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Oracle Database<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Abused capability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Oracle JVM and <code>CREATE JAVA SOURCE<\/code><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Post-exploitation toolkit<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">khunt<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">OS execution<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">KhuntCmd\u00a0launching <code>cmd.exe<\/code><\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Execution privilege<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">SYSTEM<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Host discovery<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><code><span data-contrast=\"auto\">tasklist\u00a0\/svc<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/code><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Credential-access activity<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">SAM, SECURITY and SYSTEM registry hives copied<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Confirmed hive exfiltration<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 37.7236%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Threat actor attribution<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 112.358%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Unknown<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>What makes the <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-run-khunt-post-exploitation-toolkit-from-oracle-database\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=khunt_toolkit\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">incident<\/a> notable is the role of the database. Oracle was not simply a target for unauthorized queries. The attackers used its legitimate Java functionality as part of the post-exploitation chain.<\/p>\n<h2>How did the khunt Oracle attack begin?<\/h2>\n<p>The attackers exploited <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-sql-injection\/\">SQL injection<\/a> in an autocomplete search feature within a public-facing Java application running on Apache Tomcat.<\/p>\n<p>The feature did not adequately validate user-controlled input before passing it to the backend Oracle database. This allowed the attackers to issue commands against Oracle.<\/p>\n<p>Huntress discovered the intrusion after identifying credential-theft activity on the Windows server hosting the database. Apache access logs subsequently helped investigators trace the activity back to the vulnerable search endpoint.<\/p>\n<p>The SQL injection provided the initial foothold. However, the more distinctive part of the attack followed when the attackers began using Oracle&#8217;s Java capabilities for post-exploitation.<\/p>\n<h2>How was the khunt toolkit installed inside Oracle?<\/h2>\n<p>The attackers abused Oracle&#8217;s embedded Java functionality, including <code>CREATE JAVA SOURCE<\/code>, to create Java source schema objects for khunt; Oracle can also create class schema objects for classes defined by that source.<\/p>\n<p>Oracle Database includes an embedded Java Virtual Machine and supports Java code stored within the database. The attackers used this legitimate functionality to establish the khunt toolkit inside Oracle, with PL\/SQL wrappers exposing its capabilities.<\/p>\n<p>Observed khunt components included:<\/p>\n<ul>\n<li><strong>KhuntCmd<\/strong>: Executed operating system commands through <code>cmd.exe<\/code>.<\/li>\n<li><strong>KhuntHash<\/strong>: Accessed Oracle user information and could write username and password data to a file.<\/li>\n<li><strong>KhuntFS and KhuntFS2<\/strong>: Supported file browsing, reading, searching and file-size operations.<\/li>\n<li><strong>KhuntT<\/strong>: Validated the toolkit&#8217;s installation.<\/li>\n<li><strong>KhuntUnzip<\/strong>: Provided archive-extraction functionality.<\/li>\n<\/ul>\n<p>This database-resident design distinguishes khunt from post-exploitation tooling deployed primarily as conventional executable files.<\/p>\n<p>File-focused monitoring alone may provide an incomplete view when malicious code is stored as database objects. Once khunt interacted with Windows, however, the attack also generated activity at the endpoint layer.<\/p>\n<h2>How did khunt achieve SYSTEM-level execution on Windows?<\/h2>\n<p>Khunt achieved SYSTEM-level Windows execution through KhuntCmd, which caused <code>cmd.exe<\/code> to launch as a child process of <code>oracle.exe<\/code>.<\/p>\n<p>The attackers executed:<\/p>\n<p><code>cmd.exe \/c whoami<\/code><\/p>\n<p>The output showed that commands launched through Oracle were running with SYSTEM-level permissions on the Windows server.<\/p>\n<p>They also executed:<\/p>\n<p><code>tasklist \/svc<\/code><\/p>\n<p>This command enumerated running processes and their associated Windows services. Its output was written to <code>khunttasks.txt<\/code>.<\/p>\n<p>This marked a critical transition in the attack chain. A vulnerability in a public-facing application had progressed through Oracle to privileged operating system execution. Although khunt resided inside the database, the resulting child-process execution created host-level activity that defenders could investigate.<\/p>\n<h2>Did the khunt attackers steal Windows credentials?<\/h2>\n<p>Confirmed Windows credential theft has not been established. The attackers copied the SAM, SECURITY and SYSTEM registry hives, but available reporting does not confirm successful exfiltration or credential recovery.<\/p>\n<p>The attackers used PowerShell and native Windows functionality to copy:<\/p>\n<ul>\n<li>SAM<\/li>\n<li>SECURITY<\/li>\n<li>SYSTEM<\/li>\n<\/ul>\n<p>The SAM, SYSTEM and SECURITY hives can provide credential-related material used in Windows credential-dumping workflows, including local account password hashes and other stored secrets.<\/p>\n<p>Therefore, the distinction between <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-credential-access\/\">credential-access<\/a> activity and confirmed credential theft is important. Copying the hives demonstrates collection of credential-relevant data, but it does not establish that the attackers successfully removed the files from the environment or recovered usable credentials.<\/p>\n<h2>How can organizations defend against attacks like khunt?<\/h2>\n<p>Defending against the khunt attack path requires controls across the application, database and endpoint layers, particularly input validation, least-privilege database access, Oracle Java auditing and endpoint investigation.<\/p>\n<h3>Prevent SQL injection at the application layer<\/h3>\n<p>Use prepared statements with parameterized queries to keep SQL code separate from user-supplied data, supported by appropriate server-side input validation.<\/p>\n<p>In this incident, the vulnerable autocomplete feature provided the initial route into Oracle.<\/p>\n<h3>Restrict application database privileges<\/h3>\n<p>Application-facing database accounts should have only the permissions required for their intended functions.<\/p>\n<p>If an application does not need to create Java source objects, the associated database account should not have that capability. As a result, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-least-privilege-access\/\">least privilege<\/a> can limit the actions available to an attacker after an application-to-database connection is compromised.<\/p>\n<h3>Audit unexpected Oracle Java activity<\/h3>\n<p>Organizations using Oracle Java functionality should identify where they expect Java schema objects and investigate any unexpected creation or modification.<\/p>\n<p>In the khunt attack, the attackers used Oracle&#8217;s Java capabilities to establish the post-exploitation toolkit inside the database.<\/p>\n<h3>Investigate execution that crosses onto the host<\/h3>\n<p>Database compromise should not be investigated in isolation once database-resident code begins launching operating system processes.<\/p>\n<p>Unexpected <code>cmd.exe<\/code> or PowerShell execution, unusual command lines, registry access and file operations can provide evidence of post-exploitation activity on the underlying server.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1.webp?format=webp\" class=\"resource-box__image\" alt=\"introduction-to-hexnode-xdr-300x168\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/introduction-to-hexnode-xdr-300x168-1-179x100.webp?format=webp 179w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" title=\"introduction-to-hexnode-xdr-300x168\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore how Hexnode XDR brings endpoint visibility, threat detection, investigation and response together for enterprise security teams.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How can Hexnode XDR help investigate khunt-related endpoint activity?<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> supports endpoint investigation and response when attacks following the khunt pattern generate suspicious process, file or registry activity on supported endpoints. Its role in this attack chain begins at the endpoint layer.<\/p>\n<p>Hexnode XDR does not address the initial SQL injection, inspect Oracle SQL statements or identify malicious Java schema objects within Oracle. Application security and database-specific controls address those stages of the attack.<\/p>\n<p>Once malicious activity reaches the endpoint, Hexnode XDR provides endpoint-focused detection, investigation and response capabilities. Security teams can use its endpoint telemetry to investigate documented events, including:<\/p>\n<ul>\n<li>Process creation<\/li>\n<li>Process access<\/li>\n<li>Process termination<\/li>\n<li>File creation or deletion<\/li>\n<li>Registry key creation or deletion<\/li>\n<\/ul>\n<p>For remediation, Hexnode XDR supports targeting an associated process tree during process termination. It also supports response actions including:<\/p>\n<ul>\n<li>Process termination<\/li>\n<li>Endpoint isolation<\/li>\n<li>File quarantine<\/li>\n<\/ul>\n<p>These capabilities complement application security and Oracle database monitoring rather than replace them. That distinction is particularly relevant to the khunt attack: the toolkit resided inside the database, while part of its post-exploitation activity occurred on the Windows host.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/5-Ways-Hexnode-Strengthens-Your-Incident-Response-Plan-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>5 Ways Hexnode Strengthens Your Incident Response Plan<\/h4><p>See how endpoint telemetry, and remediation actions can strengthen enterprise incident-response workflows.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/5-ways-hexnode-strengthens-your-incident-response-plan\/\" aria-label=\"5 Ways Hexnode Strengthens Your Incident Response Plan\"><\/a><\/div><\/div><\/div>\n<h2>What can security teams learn from the khunt attack?<\/h2>\n<p>The primary lesson from khunt is that defenders need visibility across the point where database compromise becomes operating system execution.<\/p>\n<p>The incident began with SQL injection, but its impact expanded because the attackers could use Oracle Java functionality to establish database-resident tooling and execute Windows commands with SYSTEM privileges.<\/p>\n<p>The attack highlights four practical priorities:<\/p>\n<ul>\n<li>Prevent SQL injection through secure input handling and parameterized queries.<\/li>\n<li>Apply least privilege to application-facing database accounts.<\/li>\n<li>Audit unexpected creation or modification of Oracle Java objects.<\/li>\n<li>Investigate suspicious endpoint activity when database processes interact with the operating system.<\/li>\n<\/ul>\n<p>The khunt toolkit incident is ultimately defined by its SQL-to-SYSTEM transition. Malicious code did not need to arrive as a conventional Windows executable to produce significant host-level activity.<\/p>\n<p>Security teams can follow that execution path from the vulnerable application to Oracle and then to Windows to assess the scope of the compromise and determine where to investigate and respond.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen endpoint threat investigation with Hexnode<\/h5><p>Explore Hexnode\u2019s endpoint management and security capabilities with a 14-day free trial.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How did the khunt toolkit attack work? The khunt toolkit was installed directly inside an&#8230;<\/p>\n","protected":false},"author":4,"featured_media":566,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,16],"class_list":["post-561","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-windows","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>khunt Toolkit Runs Inside Oracle Database After SQL Injection<\/title>\n<meta name=\"description\" content=\"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"khunt Toolkit Runs Inside Oracle Database After SQL Injection\" \/>\n<meta property=\"og:description\" content=\"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-07T09:18:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:25:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"khunt Toolkit Runs Inside Oracle Database After SQL Injection\",\"datePublished\":\"2026-08-07T09:18:02+00:00\",\"dateModified\":\"2026-08-18T09:25:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/\"},\"wordCount\":1206,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/\",\"name\":\"khunt Toolkit Runs Inside Oracle Database After SQL Injection\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp\",\"datePublished\":\"2026-08-07T09:18:02+00:00\",\"dateModified\":\"2026-08-18T09:25:34+00:00\",\"description\":\"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"khunt Toolkit Runs Inside Oracle Database After SQL Injection\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"khunt Toolkit Runs Inside Oracle Database After SQL Injection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"khunt Toolkit Runs Inside Oracle Database After SQL Injection","description":"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/","og_locale":"en_US","og_type":"article","og_title":"khunt Toolkit Runs Inside Oracle Database After SQL Injection","og_description":"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-07T09:18:02+00:00","article_modified_time":"2026-08-18T09:25:34+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"khunt Toolkit Runs Inside Oracle Database After SQL Injection","datePublished":"2026-08-07T09:18:02+00:00","dateModified":"2026-08-18T09:25:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/"},"wordCount":1206,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp","articleSection":["Identity Abuse","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/","url":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/","name":"khunt Toolkit Runs Inside Oracle Database After SQL Injection","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp","datePublished":"2026-08-07T09:18:02+00:00","dateModified":"2026-08-18T09:25:34+00:00","description":"Attackers used SQL injection to install the khunt toolkit inside an Oracle database and execute Windows commands with SYSTEM privileges.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/khunt-Toolkit-Runs-Inside-Oracle-Database-After-SQL-Injection.jpeg?format=webp","width":1340,"height":754,"caption":"khunt Toolkit Runs Inside Oracle Database After SQL Injection"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/khunt-toolkit-runs-inside-oracle-database-after-sql-injection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"khunt Toolkit Runs Inside Oracle Database After SQL Injection"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=561"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/561\/revisions"}],"predecessor-version":[{"id":568,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/561\/revisions\/568"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/566"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}