Thursday , August 20 2026
Operation CameraSwarm
AI generated

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days from June 17 to July 22. It took control of devices by finding weak spots, guessing passwords, and using offline recovery codes from serial numbers for cloud-connected cameras.

                                               CameraSwarm campaign overview Source: Hunt.io

Researchers at the threat intelligence company Hunt.io found the campaign when they came across an open directory on an HTTP server that the operator did not protect.

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
Cl0p Ransomware Listed 40+ Victims of PTC Windchill Campaign

Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw

500+ critical infrastructure hit by Medusa ransomware

Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa...
Read More
500+ critical infrastructure hit by Medusa ransomware

Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
Critical WordPress Plugin Flaw Exposes 600,000 Sites to Attacks

Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users...
Read More
Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS

DoNot (APT-C-35) Targeting Bangladesh Military Personnel

Bangladesh's military and defense system is actively under targeted attack linked to DoNot Team, or APT-C-35, as stated in a...
Read More
DoNot (APT-C-35) Targeting Bangladesh Military Personnel

McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

A large Azure data theft campaign is surfacing on the dark web. A hacker is offering employee lists taken from...
Read More
McDonald’s, Vodafone Affected by Azure Theft Campaign Exposing Millions of Records

NIST to Modernize NVD in the Age of Artificial Intelligence

National Institute of Standards and Technology (NIST) demands feedback from industry and the government on how to update the National...
Read More
NIST to Modernize NVD in the Age of Artificial Intelligence

ALERT
Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

TP-Link has revealed several serious security flaws in Aginet networking products managed by ISPs. This includes mesh systems, routers, PON...
Read More
ALERT  Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges

Hunt.io found 407 MB of data made up of 2,616 files in 234 folders. This included source code, logs, user credentials, camera images, shell history, and results from exploits, which helped them understand a big operation.

According to their findings, the CameraSwarm campaign lasted 35 days and affected 14,530 Dahua IP cameras. It used three ways to attack at the same time: a brute-forcing system checked TCP port 37777 and took control of devices at 12,324 unique IP addresses.

A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform.

Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. The account survives password changes and, on most firmware versions, factory resets.

                                                     The observed attack chain Source: Hunt.io

A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications. Data indicates that 89.4% of live serials exposed an access channel without authentication.

The tool creates recovery codes using the camera’s serial number. This lets the CameraSwarm operator get new codes through Dahua’s usual password-recovery method, even if they don’t know the current admin password.

The researchers discovered two misleading vulnerability links in the toolkit, CVE-2024-39943 and CVE-2025-31702, which were not used in the attacks they saw.

Hunt.io’s analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, “the operator’s focus settled on Russian and CIS telecom netblocks.”

The researchers also found Russian comments in altered code added to reused public tools. On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.

Dahua cameras that can be accessed through port 37777 from June to July may be unsafe. Owners need to check for a ‘p2pwn’ account and delete it. Hunt.io says that taking away the backdoor account does not make the recovery codes useless. They can still be used until Dahua changes the server settings.

Users should turn off P2P when it’s not needed. They should also update to the Dahua SA-2021-0130 firmware for CVE-2021-33044 and CVE-2021-33045, or use a newer firmware version.

Related news:

CISA warns of Dahua cameras flaws being actively exploited
Dahua Cameras 0day Vulnerability offer to sell
Dahua patches multiple critical vulnerabilities in its products

Check Also

gunra ransomware

Gunra Ransomware Leverage Fortinet VPN Flaws to Evade MFA Obtaining Enterprise Data

A joint warning from the FBI, CISA, the Department of Defense Cyber Crime Center, the …