{"id":9039,"date":"2026-08-06T12:04:12","date_gmt":"2026-08-06T12:04:12","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9039"},"modified":"2026-08-06T12:04:12","modified_gmt":"2026-08-06T12:04:12","slug":"attackers-hid-malware-inside-oracle-database-after-sql-injection-breach","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9039","title":{"rendered":"Attackers hid malware inside Oracle Database after SQL injection breach"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Huntress has documented a case where the Oracle database itself became the malware host.<\/p>\n<p class=\"wp-block-paragraph\">The security firm disclosed a campaign in which threat actors exploited a <a href=\"https:\/\/www.csoonline.com\/article\/564663\/what-is-sql-injection-how-these-attacks-work-and-how-to-prevent-them.html\">SQL injection<\/a> vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform\u2019s built-in Java capabilities.<\/p>\n<p class=\"wp-block-paragraph\">Huntress became aware of the intrusion after investigating a credential theft activity on a server running Oracle Database. The researchers learned that rather than simply executing commands through SQL injection, the attackers had leveraged Oracle\u2019s embedded Java Virtual Machine (OJVM) to upload, compile, and execute malicious Java code directly from within the database.<\/p>\n<p class=\"wp-block-paragraph\">The approach reportedly allowed the attackers to blend into legitimate database functionality while maintaining a persistent foothold on the compromised server.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe attackers managed to gain initial access in this attack thanks to a classic SQL injection,\u201d Huntress researchers said in a blog <a href=\"https:\/\/www.huntress.com\/blog\/khunt-malware-sql-injection-oracle\" target=\"_blank\" rel=\"noopener\">post<\/a>. \u201cThere was no need for a novel vulnerability because the autocomplete search feature in the public-facing application was enough to reach PL\/SQL and then the operating system.\u201d<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Exploitation beyond SQL injection<\/h2>\n<p class=\"wp-block-paragraph\">The attack revolved around Khunt, a Java-based toolkit that attackers stored as a database object using Oracle\u2019s \u201cCREATE JAVA SOURCE\u201d functionality. Oracle Database includes an embedded Java Virtual Machine that allows organizations to execute Java code from within the database for legitimate business applications.<\/p>\n<p class=\"wp-block-paragraph\">Once compiled inside the database, the Java code could be run through SQL statements to execute operating system commands on the underlying host where Oracle was configured. The malware inserted within the database schema would be considerably harder to detect, Huntress noted.<\/p>\n<p class=\"wp-block-paragraph\">After setting up the code execution path from within the database, the attackers could (and did) carry out post-compromise activities, including credential theft.<\/p>\n<p class=\"wp-block-paragraph\">In the incident Huntress investigated, the attackers ultimately compromised the Windows server hosting Oracle Database, escalating from <a href=\"https:\/\/www.csoonline.com\/article\/573101\/sql-injection-xss-vulnerabilities-continue-to-plague-organizations.html\">SQL injection<\/a> to SYSTEM-level command execution. With that level of access, they were able to dump the Windows SAM, SECURITY, and SYSTEM registry hives, enabling offline extraction of local account password hashes.<\/p>\n<p class=\"wp-block-paragraph\">The campaign\u2019s non-reliance on noisy malware binaries and incorporation of the malice entirely within Oracle\u2019s native functionality was flagged by researchers as an evolved operation that calls for targeted detection.<\/p>\n<p class=\"wp-block-paragraph\">Oracle did not immediately respond to CSO\u2019s requests for comment.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Mitigation focused on post-exploitation toolkit\u00a0<\/h2>\n<p class=\"wp-block-paragraph\"><strong><br \/><\/strong>While the SQL injection pathway provided the initial foothold, Huntress argues that the more important lesson lies in what happened after exploitation.<\/p>\n<p class=\"wp-block-paragraph\">The attackers could have simply extracted or manipulated data through SQL injection, but instead, they expanded the exploit to include long-term persistence and remote command execution. Huntress warned that this is a dangerous evolution.<\/p>\n<p class=\"wp-block-paragraph\">Features such as Oracle\u2019s embedded JVM, while valuable for enterprise workloads, can also expand the blast radius with sufficient database privileges. \u201cTo avoid these types of attacks, it is important to ensure the forms aren\u2019t injectable,\u201d the researchers said. \u201cIt\u2019s also important to ensure that users with the ability to execute queries aren\u2019t overprovisioned.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Huntress recommended looking beyond indicators of SQL injection during incident response. Examining Oracle environments for unexpected Java source objects, compiled Java classes, and stored procedures could indicate abuse of the embedded Java Virtual Machine, it said. The firm also shared indicators of compromise (IOCs), including file hashes, malicious Java artifacts, SQL statements, and search terms to help defenders identify affected systems.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform\u2019s built-in Java capabilities. Huntress became aware of the intrusion after investigating [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9040,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9039","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9039"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9039"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9039\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9040"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9039"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9039"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}