INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
| 2026-08-19 18:09 CRITICAL MEDIUMExecutive Summary AI-generated
The Dahua IP camera hacking incident, dubbed CameraSwarm, has compromised over 14,500 cameras in Ukraine and Russia. The attack chain was global, targeting Russian telecom netblocks, with the operator's focus settling on Russian and CIS telecom netblocks. Researchers found vulnerabilities such as CVE-2021-33044 and CVE-2021-33045 to be exploited using a tool called p2pwn, installing persistent backdoors on cameras. The incident also highlighted the importance of disabling P2P when not needed and applying firmware updates for vulnerable Dahua devices. A 35-day campaign ran between June 17 and July 22, compromising devices by brute-forcing logins, exploiting offline recovery codes from serial numbers, and using cloud-relay attacks to reach cameras behind NAT. The incident has been attributed to a single organization, with the researchers recommending users disable P2P when not needed and apply firmware updates for vulnerable Dahua devices.
Technical Mitigations AI-generated
* Use secure protocols such as HTTPS and SSH to encrypt data transmitted between devices and the internet.
* Implement access controls, such as user authentication and authorization, to restrict access to sensitive areas of a system or network.
* Regularly update and patch software and firmware to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Use strong passwords and multi-factor authentication (MFA) to prevent unauthorized access to devices and systems.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation CameraSwarmOperation CameraSwarm
CVE-2025-31702CVE-2025-31702
CVE-2024-39943CVE-2024-39943
CVE-2021-33045CVE-2021-33045
CVE-2021-33044CVE-2021-33044
Target & Sectors
CIS
CIS
Incident Timeline
July 22
The Dahua web cameras were compromised by threat actors on June 17 and remained vulnerable for at least 35 days.
Click on any entity below to view its context and source!
general_metric
17 June
The operation ran for at least 35 days between June 17 and July 22, compromising devices by exploiting vulnerabilities, brute-forcing logins, and using offline recovery codes from serial numbers for cloud-registered cameras.
July 22, 2026
Threat actors used a vulnerability in Dahua's IP camera software to compromise 14,500 web cameras.
23 July
Hunt.io's AttackCapture system exploited a vulnerability in Dahua web cameras to download 407 MB of files from an HTTP directory on 23 July.
Click on any entity below to view its context and source!
data_breach
407 MB
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
data_breach
2,616 files
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
general_metric
234 directories
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
organisation
MB
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
August 10
Hunt.io notified national CERTs and Dahua's PSIRT about the CameraSwarm campaign on August 10.
Click on any entity below to view its context and source!
organisation
CERTs
On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.
2026/08/12
Threat actors compromised 14,500 Dahua web cameras using a purpose-built platform targeting Russian-speaking operators.
Click on any entity below to view its context and source!
target_region
Russian Federation
Where last week’s investigation centered on a
Russian-speaking operator running a purpose-built platform against 58 camera
s, this one is a different scale entirely.”
general_metric
58 camera s
Where last week’s investigation centered on a
Russian-speaking operator running a purpose-built platform against 58 camera
s, this one is a different scale entirely.”
between June 17 and July 22, 2026
Ukraine's and Russian Federation's 14,000 Dahua web cameras were compromised over a 35-day period.
Click on any entity below to view its context and source!
target_region
Ukraine
A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia.
target_region
Russian Federation
A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia.
general_metric
14,000 Cameras exposed operator directory
A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia.
2026/08/19
The hackers used a cloud-relay attack to compromise 14,500 Dahua web cameras in Ukraine and Russia by exploiting vulnerabilities in the camera's SDK.
Click on any entity below to view its context and source!
organisation
CameraSwarm
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
organisation
Dahua IP
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
infrastructure
14,500 Dahua IP cameras
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
organisation
CVE-2021
Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras.
organisation
CVE-2021-33044
Additionally, users are recommended to disable P2P when not needed, and apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version.
organisation
CVE-2021-33045
Additionally, users are recommended to disable P2P when not needed, and apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version.
organisation
CVE-2025-31702
The researchers found two misleading vulnerability references in the toolkit, CVE-2024-39943 and CVE-2025-31702, which are not exploited in the observed attacks.
organisation
CVE
The tool links its persistent backdoor technique to CVE-2024-39943, but that CVE actually refers to a different command-injection flaw in Rejetto’s HTTP File Server.
organisation
CVE-2025
Likewise, the relay abuse is not CVE-2025-31702, which Dahua describes as a narrower authenticated privilege-escalation flaw.
organisation
TCP
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
organisation
IP
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
A third path skipped IP addresses entirely and reached 283 cameras purely by serial number, through Dahua’s own cloud relay.
infrastructure
14,530 Dahua IP cameras
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
infrastructure
12,324 unique IP addresses
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
organisation
Dahua
A third path skipped IP addresses entirely and reached 283 cameras purely by serial number, through Dahua’s own cloud relay.
organisation
Telegram
It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform.
organisation
NAT
A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications.
Dahua’s cloud relay lets any app reach a camera sitting behind NAT using nothing but its serial number, and authentication to that relay runs on credentials baked identically into every Dahua client ever shipped.
organisation
SDK
A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications.
Obtaining that token requires only the fixed SDK credentials shared by every legitimate Dahua application.” continues the report.
organisation
Dahua’s
The recovery code generation mechanism in the attack toolkit leverages the camera serial number, which allows the CameraSwarm operator to redeem new codes via Dahua’s standard password-recovery process without knowing the current admin password.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
data_breach
407 MB
Hunt.io recovered
407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.
data_breach
2,616 files
Hunt.io recovered
407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.
infrastructure
Windows
That single slip handed researchers the operator’s scanning engine, exploit chains, exfiltration bot, and a Windows stealer staged on the same box.
Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
organisation
Swann
For anyone running Dahua gear, or the OEM-rebranded lines built on the same backend (Amcrest, Lorex, Annke, Swann, among others), the practical checklist is short: check for a p2pwn account and remove it, disable P2P on any device where it isn’t actually needed, confirm firmware is patched against the 2021 bypass pair, and rotate every credential that camera ever held, since the exfiltration bot grabbed those too.
organisation
UPX
Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
organisation
SalatStealer
Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
organisation
Group Policy
Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
Tactical Metrics
Metrics
infrastructure
14,500
Dahua Ip Cameras
Click for context!
In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
Metrics
infrastructure
14,530
Dahua Ip Cameras
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
Metrics
infrastructure
12,324
Unique Ip Addresses
CameraSwarm campaign overview
Source: Hunt.io
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses.
Metrics
data_breach
407
Mb
Hunt.io recovered
407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
Metrics
data_breach
2,616
Files
Hunt.io recovered
407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.
On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open.
Metrics
infrastructure
Windows
Affected Product
That single slip handed researchers the operator’s scanning engine, exploit chains, exfiltration bot, and a Windows stealer staged on the same box.
Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
Intelligence Sources
BleepingComputer
2026-08-19
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
BleepingComputer
Security Affairs
2026-08-19
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-20T07:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
CameraSwarm
entity
9x
timeline
Temporal Reference
35-day
date
4x
vulnerability
Exploited CVE
CVE-2021-33044
cve
3x
target region
Target Country
Ukraine
country
2x
infrastructure
Dahua Ip Cameras
14,500
dahua ip cameras
2x
general metric
Cameras
1,923
cameras
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
Contextual Telemetry
Context Block
19 METRICS
source region
Origin Country
Russian Federation
country
target region
Target Region
CIS
region
general metric
Sa-2021
130
sa-2021
general metric
Dahua Web Cameras
14,500
dahua web cameras
general metric
June
17
june
infrastructure
Unique Ip Addresses
12,324
unique ip addresses
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
data breach
Mb
407
mb
data breach
Files
2,616
files
general metric
Directories
234
directories
general metric
%
89
%
campaign
Campaign
Operation CameraSwarm
operation
general metric
Cameras Exposed Operator Directory
14,000
cameras exposed operator directory
general metric
Camera S
58
camera s
tactic
Cyber Operation Type
Exfiltration
tactic
infrastructure
Affected Product
Windows
software
general metric
Unique Addresses
12,300
unique addresses
general metric
Dahua Vulnerabilities
2,021
dahua vulnerabilities
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.