# Inside an Oracle Database SQL Injection Attack | Huntress

DevFeed: [Inside an Oracle Database SQL Injection Attack | Huntress](<https://devfeed.tech/articles/inside-an-oracle-database-sql-injection-attack-huntress-54442.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/khunt-malware-sql-injection-oracle>)

Author: Ben Nahorney; Michael Tigges

Published: 2026-08-05T13:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Oracle Database](<https://devfeed.tech/topics/oracle-database.md>), [Database](<https://devfeed.tech/topics/database.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Java](<https://devfeed.tech/topics/java.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [java](<https://devfeed.tech/tags/java.md>), [oracle](<https://devfeed.tech/tags/oracle.md>), [rce](<https://devfeed.tech/tags/rce.md>), [sql](<https://devfeed.tech/tags/sql.md>), [sql-injection](<https://devfeed.tech/tags/sql-injection.md>), [sql-injection-attack](<https://devfeed.tech/tags/sql-injection-attack.md>)

## AI overview

Huntress investigates a SQL injection attack against a public-facing application with an Oracle backend. The attackers used Oracle's embedded JVM and CREATE JAVA SOURCE to compile Java code inside the database and deploy a post-exploitation toolkit, leading to credential theft and OS-level remote code execution.

## Source excerpt

See how a SQL injection bug led to full OS-level RCE, as attackers abused Oracle Java Source to deploy the khunt post-exploitation toolkit.