Hackers compromise 14,500 Dahua web cameras in 35-day campaign

Cybersecurity researchers have uncovered a massive and sophisticated hacking campaign that compromised over 14,500 Dahua web cameras in just 35 days. The operation, dubbed CameraSwarm, targeted devices mostly in Ukraine and Russia, with the hackers using multiple methods to gain control of the cameras.

The hackers exploited vulnerabilities, brute-forced login credentials, and used offline recovery codes from serial numbers for cloud-registered cameras. They also deployed a backdoor account on compromised devices, allowing them to access camera feeds without needing valid admin passwords. The researchers estimate that 89.4% of live serials exposed an access channel without authentication.

The CameraSwarm campaign was uncovered by researchers at threat intelligence company Hunt.io, who discovered a working directory on an HTTP server left unprotected by the operator. By analyzing data recovered from the compromised cameras, including source code, logs, and captured images, they mapped out the scope of the operation. The hackers used three attack methods in parallel: brute-forcing login credentials, exploiting vulnerabilities using a tool called p2pwn, and a cloud-relay attack that relied on serial numbers and SDK credentials.

The use of offline recovery codes to access camera feeds is particularly concerning, as it allows the hackers to bypass traditional authentication mechanisms. The researchers found that the recovery code generation mechanism in the attack toolkit leverages the camera serial number, allowing the CameraSwarm operator to redeem new codes without knowing the current admin password. This tactic could be used by other attackers, making it essential for Dahua users to take immediate action.

The compromised devices are mostly located in Ukraine and Russia, with some scattered across other regions. The researchers found that scanning was global, first checking the Russian address space before moving on to the entire IPv4 range. However, they also discovered that the operator’s focus settled on Russian and CIS telecom netblocks.

Dahua has been notified about the campaign, along with national CERTs, and users are advised to examine their cameras for signs of compromise. Those reachable through port 37777 between June and July should be treated as potentially compromised, and owners should remove any ‘p2pwn’ accounts found. It’s also essential to apply Dahua SA-2021-0130 firmware updates or later versions to address the exploited vulnerabilities.

The CameraSwarm campaign serves as a stark reminder of the importance of robust cybersecurity measures in IoT devices. With attackers able to access camera feeds using valid credentials, prevention scores can drop sharply once initial access is gained. To mitigate this risk, Dahua users should prioritize secure configurations, such as disabling P2P when not needed and applying firmware updates.

As the cybersecurity landscape continues to evolve, it’s essential for users to stay vigilant and take proactive steps to protect their devices from emerging threats. By staying informed about potential vulnerabilities and taking prompt action to address them, individuals can significantly reduce the risk of falling victim to sophisticated hacking campaigns like CameraSwarm.


Source: Bleeping Computer — 2026-08-19