Wednesday , September 9 2026
Operation CameraSwarm
AI generated

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days from June 17 to July 22. It took control of devices by finding weak spots, guessing passwords, and using offline recovery codes from serial numbers for cloud-connected cameras.

                                               CameraSwarm campaign overview Source: Hunt.io

Researchers at the threat intelligence company Hunt.io found the campaign when they came across an open directory on an HTTP server that the operator did not protect.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Hunt.io found 407 MB of data made up of 2,616 files in 234 folders. This included source code, logs, user credentials, camera images, shell history, and results from exploits, which helped them understand a big operation.

According to their findings, the CameraSwarm campaign lasted 35 days and affected 14,530 Dahua IP cameras. It used three ways to attack at the same time: a brute-forcing system checked TCP port 37777 and took control of devices at 12,324 unique IP addresses.

A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform.

Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. The account survives password changes and, on most firmware versions, factory resets.

                                                     The observed attack chain Source: Hunt.io

A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications. Data indicates that 89.4% of live serials exposed an access channel without authentication.

The tool creates recovery codes using the camera’s serial number. This lets the CameraSwarm operator get new codes through Dahua’s usual password-recovery method, even if they don’t know the current admin password.

The researchers discovered two misleading vulnerability links in the toolkit, CVE-2024-39943 and CVE-2025-31702, which were not used in the attacks they saw.

Hunt.io’s analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, “the operator’s focus settled on Russian and CIS telecom netblocks.”

The researchers also found Russian comments in altered code added to reused public tools. On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.

Dahua cameras that can be accessed through port 37777 from June to July may be unsafe. Owners need to check for a ‘p2pwn’ account and delete it. Hunt.io says that taking away the backdoor account does not make the recovery codes useless. They can still be used until Dahua changes the server settings.

Users should turn off P2P when it’s not needed. They should also update to the Dahua SA-2021-0130 firmware for CVE-2021-33044 and CVE-2021-33045, or use a newer firmware version.

Related news:

CISA warns of Dahua cameras flaws being actively exploited
Dahua Cameras 0day Vulnerability offer to sell
Dahua patches multiple critical vulnerabilities in its products

Check Also

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit’s claims about a breach and stolen data. The ransomware …