Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

IoT Security

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.

Camera hacking

A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports.

The activity, referred to as Operation CameraSwarm, occurred between June 17 and July 22. It initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges, but later focused on Russian and CIS telecom netblocks.

Hunt.io says it gained access to the threat actor’s servers, where it found 2,616 files across 234 subdirectories, or approximately 407 MB of data, left in an open HTTP directory that the hackers exposed themselves.

Analysis of the data revealed the compromise of over 14,530 devices within the 35-day-long campaign. A brute-force engine was used to target 12,324 unique addresses.

The threat actor deployed a persistent backdoor account on 1,923 cameras over Remote Procedure Call (RPC). The account uses the p2pwn/p2password username and password pair.

“It is stored independently of the admin password and survives a password change and, on most firmware, a factory reset,” Hunt.io says.

Advertisement. Scroll to continue reading.

For credential brute-forcing, the threat actor used a publicly available asyncio framework. Additionally, they relied on a compiled Go binary for authentication bypass, chaining three vulnerabilities, including the CVE-2021-33044 and CVE-2021-33045 bypasses, and CVE-20244-39943 to deploy the backdoor account.

“CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers: when clientType is NetKeyboard, the password field is never evaluated. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection,” Hunt.io says.

The bypasses return a full administrator session unauthenticated, and the binary drops the p2pwn / p2password account over RPC.

In some instances, the attackers abused Dahua’s cloud relay to reach cameras behind NATs, using only their serial numbers.

Hunt.io discovered that the threat actor set up the infrastructure used in the campaign at least one year before the attacks, and that its toolkit contains both their own code and modified code from at least four other developers.

“We assess with moderate confidence that the toolkit was built to hand access to a third party, based on the transferable recovery-code design and the enterprise-format export pipeline. That is narrower than a confirmed commercial operation, which the evidence does not support,” Hunt.io says.

The report does not establish the operator’s ultimate motivation or intended use of the compromised cameras.

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.