IoT Security

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.

Camera hacking

A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports.

The activity, referred to as Operation CameraSwarm, occurred between June 17 and July 22. It initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges, but later focused on Russian and CIS telecom netblocks.

Hunt.io says it gained access to the threat actor’s servers, where it found 2,616 files across 234 subdirectories, or approximately 407 MB of data, left in an open HTTP directory that the hackers exposed themselves.

Analysis of the data revealed the compromise of over 14,530 devices within the 35-day-long campaign. A brute-force engine was used to target 12,324 unique addresses.

The threat actor deployed a persistent backdoor account on 1,923 cameras over Remote Procedure Call (RPC). The account uses the p2pwn/p2password username and password pair.

“It is stored independently of the admin password and survives a password change and, on most firmware, a factory reset,” Hunt.io says.

Advertisement. Scroll to continue reading.

For credential brute-forcing, the threat actor used a publicly available asyncio framework. Additionally, they relied on a compiled Go binary for authentication bypass, chaining three vulnerabilities, including the CVE-2021-33044 and CVE-2021-33045 bypasses, and CVE-20244-39943 to deploy the backdoor account.

“CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers: when clientType is NetKeyboard, the password field is never evaluated. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection,” Hunt.io says.

The bypasses return a full administrator session unauthenticated, and the binary drops the p2pwn / p2password account over RPC.

In some instances, the attackers abused Dahua’s cloud relay to reach cameras behind NATs, using only their serial numbers.

Hunt.io discovered that the threat actor set up the infrastructure used in the campaign at least one year before the attacks, and that its toolkit contains both their own code and modified code from at least four other developers.

“We assess with moderate confidence that the toolkit was built to hand access to a third party, based on the transferable recovery-code design and the enterprise-format export pipeline. That is narrower than a confirmed commercial operation, which the evidence does not support,” Hunt.io says.

The report does not establish the operator’s ultimate motivation or intended use of the compromised cameras.

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Related Content

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Mobile & Wireless

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Cyberwarfare

The move targeted people and entities accused of links to an online spying network that the EU claims targeted governments and carried out sabotage...

Government

UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.

Malware & Threats

Turla has been using the backdoor against government and military organizations in Ukraine for espionage.

IoT Security

The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version