Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
DEVICES

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Devices / news

Dahua Camera Campaign Compromises Over 14,500 Devices in Ukraine and Russia

Researchers at Hunt.io uncovered a 35-day operation, named CameraSwarm, that hijacked thousands of Dahua IP cameras using vulnerability exploits, credential brute forcing, and serial-number recovery codes.

Featured image for Dahua Camera Campaign Compromises Over 14,500 Devices in Ukraine and Russia
Featured image for Dahua Camera Campaign Compromises Over 14,500 Devices in Ukraine and Russia

Attackers hijacked more than 14,500 Dahua IP cameras in a campaign that threat intelligence firm Hunt.io has dubbed CameraSwarm. The operation, which ran from June 17 to July 22, focused mainly on devices in Ukraine and Russia, according to research covered by BleepingComputer.

Hunt.io discovered the campaign after finding an unprotected HTTP server directory. The uncovered data totaled 407 MB across 2,616 files in 234 directories and included source code, logs, credentials, captured camera images, shell history, and exploitation results. This cache allowed the researchers to reconstruct the campaign's scope and methods.

The operator used three attack techniques in parallel: exploiting vulnerabilities, brute-forcing login credentials, and generating offline recovery codes from camera serial numbers. The recovery-code method is particularly significant—it allowed the attacker to redeem new codes through Dahua's standard password-recovery process without knowing the current admin password, effectively bypassing authentication for cloud-registered cameras.

The toolkit contained references to CVE-2024-39943 and CVE-2025-31702, but Hunt.io determined these were not actually exploited in the observed attacks. The report recommends applying Dahua firmware update SA-2021-0130, which addresses CVE-2021-33044 and CVE-2021-33045, though the source does not confirm which specific vulnerabilities were actively used.

Scanning activity was global, initially focusing on Russian address space before expanding to the entire IPv4 range. Hunt.io noted that the operator's attention ultimately settled on Russian and CIS telecom netblocks. Modified public tools contained Russian comments, but the source does not attribute the campaign to a specific threat actor.

Hunt.io advises that any Dahua camera reachable on port 37777 between June and July should be treated as potentially compromised. Administrators should check for a backdoor account named 'p2pwn' and remove it. However, removing this account does not invalidate recovery codes already generated; those remain usable until Dahua changes the server-side derivation mechanism. Users are also recommended to disable P2P when not needed and apply the relevant firmware updates.

Hunt.io notified national CERTs and Dahua's PSIRT on August 10. BleepingComputer's report does not state whether Dahua has publicly responded.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'