Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days from June 17 to July 22. It took control of devices by finding weak spots, guessing passwords, and using offline recovery codes from serial numbers for cloud-connected cameras.

Researchers at the threat intelligence company Hunt.io found the campaign when they came across an open directory on an HTTP server that the operator did not protect.
Hunt.io found 407 MB of data made up of 2,616 files in 234 folders. This included source code, logs, user credentials, camera images, shell history, and results from exploits, which helped them understand a big operation.
According to their findings, the CameraSwarm campaign lasted 35 days and affected 14,530 Dahua IP cameras. It used three ways to attack at the same time: a brute-forcing system checked TCP port 37777 and took control of devices at 12,324 unique IP addresses.
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform.
Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. The account survives password changes and, on most firmware versions, factory resets.

A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications. Data indicates that 89.4% of live serials exposed an access channel without authentication.
The tool creates recovery codes using the camera’s serial number. This lets the CameraSwarm operator get new codes through Dahua’s usual password-recovery method, even if they don’t know the current admin password.
The researchers discovered two misleading vulnerability links in the toolkit, CVE-2024-39943 and CVE-2025-31702, which were not used in the attacks they saw.
Hunt.io’s analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, “the operator’s focus settled on Russian and CIS telecom netblocks.”
The researchers also found Russian comments in altered code added to reused public tools. On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.
Dahua cameras that can be accessed through port 37777 from June to July may be unsafe. Owners need to check for a ‘p2pwn’ account and delete it. Hunt.io says that taking away the backdoor account does not make the recovery codes useless. They can still be used until Dahua changes the server settings.
Users should turn off P2P when it’s not needed. They should also update to the Dahua SA-2021-0130 firmware for CVE-2021-33044 and CVE-2021-33045, or use a newer firmware version.
Related news:
CISA warns of Dahua cameras flaws being actively exploited
Dahua Cameras 0day Vulnerability offer to sell
Dahua patches multiple critical vulnerabilities in its products
InfoSecBulletin Cybersecurity for mankind
