Multiple reports describe an intrusion in which attackers use a SQL injection vulnerability to compromise an organization’s public-facing web application and gain access to an Oracle database. After establishing access, the attackers install a post-exploitation toolkit referred to as “khunt” directly within the Oracle environment. Instead of dropping a traditional executable onto a server, the attackers provide Java source code to Oracle, which then compiles that code into stored database schema objects. The attackers then run commands from within the database engine, leveraging Oracle’s capabilities to execute actions needed for further access and post-exploitation steps.

One source notes that the toolkit is used as part of the attackers’ workflow to breach a corporate network. Another source adds that this approach turns the initial SQL injection into deeper operating-system-level access, including execution in the context of elevated Windows privileges (described as “SYSTEM”). The reporting also cites Huntress as tracking and naming the toolkit as khunt.