A massive campaign of cyberattacks has compromised over 14,500 Dahua web cameras across Ukraine and Russia in a 35-day operation that has left owners scrambling to secure their devices. Dubbed CameraSwarm by researchers at Hunt.io, the attack highlights the vulnerabilities inherent in internet-connected devices and the need for robust security measures.
The attackers, who used three different methods to breach the cameras, were able to exploit weaknesses in Dahua’s firmware and capture sensitive data, including login credentials and camera images. The compromised devices, which number over 14,530, are mostly located in Ukraine and Russia, with a smaller number found in other parts of the world.
The researchers at Hunt.io discovered the operation after stumbling upon an unsecured directory on an HTTP server used by the attackers. By digging through the data recovered from this server, they were able to map out the scope of the attack and identify the vulnerabilities that were exploited. The data included not only logs and credentials but also source code, shell history, and even captured camera images.
The attackers used three different methods to breach the cameras: brute-force login attempts, exploiting known vulnerabilities using a tool called p2pwn, and a cloud-relay attack that utilized serial numbers and SDK credentials embedded in Dahua applications. The recovery code generation mechanism in the toolkit allowed the attackers to redeem new codes via Dahua’s standard password-recovery process without knowing the current admin password.
The researchers found that scanning was global, with the operator first checking Russian address space before moving on to scan the entire IPv4 range. This suggests that the attackers were targeting devices in Russia and the Commonwealth of Independent States (CIS). However, it’s worth noting that the presence of Russian comments in modified code inserted into repurposed public tools raises questions about the origin and motivations of the attackers.
On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign. Owners of Dahua cameras reachable through port 37777 between June and July should be treated as potentially compromised and examined for the presence of a ‘p2pwn’ account. Removing this backdoor account does not invalidate recovery codes generated by the toolkit, which remain usable until Dahua alters the derivation server-side.
To prevent similar attacks in the future, users are recommended to disable P2P when not needed, apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version. Additionally, owners should be aware that once attackers have valid credentials, prevention measures can drop sharply, making it essential to stay vigilant and proactive in securing their devices.
The CameraSwarm campaign serves as a stark reminder of the importance of robust security measures for internet-connected devices. As more and more devices become connected to the web, the potential for large-scale attacks grows exponentially. By staying informed and taking proactive steps to secure our devices, we can mitigate these risks and prevent similar campaigns from succeeding in the future.
Source: Bleeping Computer — 2026-08-19