
Attackers hijacked more than 14,500 Dahua IP cameras in a campaign that threat intelligence firm Hunt.io has dubbed CameraSwarm. The operation, which ran from June 17 to July 22, focused mainly on devices in Ukraine and Russia, according to research covered by BleepingComputer.
Hunt.io discovered the campaign after finding an unprotected HTTP server directory. The uncovered data totaled 407 MB across 2,616 files in 234 directories and included source code, logs, credentials, captured camera images, shell history, and exploitation results. This cache allowed the researchers to reconstruct the campaign's scope and methods.
The operator used three attack techniques in parallel: exploiting vulnerabilities, brute-forcing login credentials, and generating offline recovery codes from camera serial numbers. The recovery-code method is particularly significant—it allowed the attacker to redeem new codes through Dahua's standard password-recovery process without knowing the current admin password, effectively bypassing authentication for cloud-registered cameras.
The toolkit contained references to CVE-2024-39943 and CVE-2025-31702, but Hunt.io determined these were not actually exploited in the observed attacks. The report recommends applying Dahua firmware update SA-2021-0130, which addresses CVE-2021-33044 and CVE-2021-33045, though the source does not confirm which specific vulnerabilities were actively used.
Scanning activity was global, initially focusing on Russian address space before expanding to the entire IPv4 range. Hunt.io noted that the operator's attention ultimately settled on Russian and CIS telecom netblocks. Modified public tools contained Russian comments, but the source does not attribute the campaign to a specific threat actor.
Hunt.io advises that any Dahua camera reachable on port 37777 between June and July should be treated as potentially compromised. Administrators should check for a backdoor account named 'p2pwn' and remove it. However, removing this account does not invalidate recovery codes already generated; those remain usable until Dahua changes the server-side derivation mechanism. Users are also recommended to disable P2P when not needed and apply the relevant firmware updates.
Hunt.io notified national CERTs and Dahua's PSIRT on August 10. BleepingComputer's report does not state whether Dahua has publicly responded.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

