Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised via Three Attack Vectors
Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised via Three Attack Vectors 1. Basic Information Article Title : Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia Publisher : Hunt.io Publication Date : 2026-08-18 Severity : High Original Source : Hunt.io Related Sources : BleepingComputer Related Entities : CameraSwarm, Dahua IP Camera, p2pwn,…
The Operation CameraSwarm campaign affected more than 14,000 Dahua cameras across Ukraine and Russia, employing three distinct attack methods. Firstly, attackers utilized masscan to scan the internet for TCP/37777 port openings, attempting a limited number of credentials on responsive Dahua devices. Upon successful authentication, images were filtered and transferred to Telegram, while device details were saved in an XML file for SMART PSS.
Secondly, attackers exploited known vulnerabilities CVE-2021-33044 and CVE-2021-33045 to bypass authentication and gain administrator access to the cameras. By impersonating a NetKeyboard device or altering the source IP to 127.0.0.1, they created p2pwn accounts using RPC. This allowed them to reconnect after changes to administrator passwords or even after factory resets, thereby obtaining ONVIF credentials and recovering passwords for NVR connections.
The third attack vector involved collecting serial numbers of Dahua devices from Shodan or DDNS names, then connecting to the Dahua cloud relay using standard embedded SDK credentials. With 89.4% success rate, attackers queried the relay channel with serial numbers, bypassing device authentication to acquire cloud management rights using offline-generated recovery codes.
Attackers operated from various locations using Virtual Private Servers, and connected to devices either directly or through official Dahua cloud relays. Administrators may not notice the compromise as video services continued functioning normally, but administrators would notice unusual logins or unexpected accounts like p2pwn. Additionally, traffic via cloud relays might be challenging to detect using solely the source IP.
For successful compromises, stolen camera videos, device credentials, and NVR connection credentials were obtained. Persistent accounts allowed re-entry even after admin passwords were changed. Compromised devices could be managed via the SMART PSS format, and cloud management rights could be regained even after account deletion as long as the recovery codes remained valid.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.