Hackers used a SQL injection flaw in a public-facing Java application to implant the khunt toolkit directly inside an Oracle database and then execute commands on a Windows server with SYSTEM privileges. Huntress linked the attack to IP address 178.162.151[.]229 and recommended stricter input validation and lower database permissions for internet-facing applications. #Oracle #khunt #Huntress
Keypoints
- Attackers exploited a SQL injection vulnerability in an Oracle-backed web application.
- The intrusion was detected by Huntress on July 27, 2026.
- The malicious traffic originated from IP address 178.162.151[.]229.
- The khunt toolkit was compiled and stored directly inside the Oracle database as a Java object.
- The attackers used database execution to run commands, dump registry hives, and enumerate system services.