mimile
Back to feed

CameraSwarm campaign compromises 14,530 Dahua devices in Ukraine, Russia

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

CameraSwarm campaign compromises 14,530 Dahua devices in Ukraine, Russia

Hackers compromised more than 14,500 Dahua IP cameras in Ukraine and Russia between June 17 and July 22, 2026, Hunt.io researchers said. The 35-day operation used credential attacks, two authentication-bypass vulnerabilities, and a P2P relay to install persistent backdoor accounts on some devices. Both vulnerabilities remained in CISA's Known Exploited Vulnerabilities catalog as of August 19, 2026.

Key Facts

  • Hunt.io documented 14,530 compromised Dahua devices across three attack paths between June 17 and July 22, 2026.
  • Brute-forcing of TCP port 37777 compromised 12,324 unique IP addresses and exported camera snapshots to Telegram and Dahua SMART PSS.
  • The p2pwn tool exploited CVE-2021-33044 and CVE-2021-33045 to install a persistent p2pwn/p2password backdoor account on 1,923 cameras.
  • A separate P2P relay path reached 283 cameras by serial number, including devices behind NAT.
  • Both flaws remained in CISA's Known Exploited Vulnerabilities catalog as of August 19, 2026, with NVD CVSS 9.8 and Dahua advisory 8.1.

Attack Methods

The 35-day operation combined credential attacks, two authentication-bypass vulnerabilities, and a P2P relay path to compromise 14,530 Dahua IP cameras. Brute-forcing targeted TCP port 37777 and reached 12,324 unique IP addresses, with campaign records totaling 13,229. Captured camera snapshots were sent to Telegram and exported for Dahua's SMART PSS platform. The exposed working directory contained 407 MB of data across 2,616 files and 234 subdirectories, including logs, credentials, and exploitation results. The operators also used offline recovery codes from serial numbers for cloud-registered cameras.

Authentication-Bypass Flaws

Attackers used the p2pwn tool to exploit CVE-2021-33044 and CVE-2021-33045 and install a persistent backdoor account on 1,923 cameras. The p2pwn/p2password backdoor account survives password changes and, on most firmware versions, factory resets, according to Hunt.io. Dahua's advisory rates both vulnerabilities at CVSS 8.1 and lists fixed firmware, while NVD assigns each a CVSS score of 9.8. A NetKeyboard client type triggers CVE-2021-33044 during authentication, and CVE-2021-33045 involves a loopback login request using 127.0.0.1. Both flaws remained in CISA's Known Exploited Vulnerabilities catalog as of August 19, 2026, with mitigation or discontinuation advised.

P2P Relay Path

A separate P2P relay path reached 283 cameras by serial number, including devices behind network address translation. The relay establishes a route without prior authentication, leaving login checks to the device's web application, according to ITRES Labs. The public p2pwn repository remained accessible as of August 19, 2026 and confirms the tool accepts Dahua serial numbers, checks both CVEs, and contains a default dummy-account configuration. Hunt.io advised users to apply vendor fixes or newer firmware, and ITRES Labs recommended disabling P2P where not required.

2 sources

CameraSwarm campaign compromises 14,530 Dahua devices in Ukraine, Russia