HomeCyber AttacksResearchers Find Campaign That Hijacked More Than 14,000 Dahua Security Cameras

Researchers Find Campaign That Hijacked More Than 14,000 Dahua Security Cameras

A single attacker gained access to more than 14,500 internet-connected security cameras made by the Chinese manufacturer Dahua over a five-week period this summer, according to research published by threat intelligence firm Hunt.io on August 18. The cameras were located mostly in Ukraine and Russia, and the attacker appears to have combined three separate techniques to reach devices that were both openly exposed online and hidden behind home or business routers.

Hunt.io says it found the operation almost by accident. Its AttackCapture tool spotted an open web directory sitting on a server the attacker had set up, and that folder turned out to contain more than 2,600 files, including the attacker’s own tools, activity logs, and records of which cameras had been reached. The exposed data let researchers piece together a detailed timeline of the campaign, which ran from June 17 to July 22, 2026.

Three ways in

The first and simplest method was straightforward credential guessing. The attacker ran automated software that tried common or previously leaked usernames and passwords against roughly 12,300 unique IP addresses on the network port Dahua devices use for its Easy4IP service. Hunt.io says the tool could scale up to 4,000 simultaneous connection attempts and was built to skip cameras that appeared offline or showed a blank picture, so the attacker’s effort went toward devices actually worth accessing.

The second method relied on two authentication bypass flaws that Dahua disclosed back in 2021, tracked as CVE-2021-33044 and CVE-2021-33045. One of the flaws exploits how certain Dahua cameras unconditionally trust a type of hardware accessory called a NetKeyboard controller, while the other tricks a camera into thinking a login request is coming from itself, using the address 127.0.0.1, rather than from an outside attacker. Both bugs carry a severity score of 9.8 out of 10 from the National Vulnerability Database and remain on the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog as of this week, meaning federal agencies are required to patch them. According to Hunt.io, the attacker’s tool chained the two flaws together and could break into an unpatched camera in under a second. Cameras compromised this way received a hidden backdoor account that survived password changes and, in most cases, factory resets, because it was stored separately from the normal admin login.

The third technique targeted cameras that were not directly reachable from the internet, typically because they sat behind a home router performing network address translation, or NAT. Dahua cameras support a cloud relay feature called Easy4IP that lets an owner view their camera remotely without configuring their router, using nothing but the camera’s serial number. Hunt.io found the attacker abusing hardcoded credentials built into every Dahua client to reach 283 cameras this way. In a related finding shared with Hunt.io, the research group ITRES Labs said that of the working serial numbers it tested against Dahua’s relay, 89.4 percent returned a live video channel with no authentication required at all.

Signs the access was meant to be resold

Hunt.io said it recovered offline recovery codes in the attacker’s files that granted cloud-level administrative control over a camera using only its serial number, with no password needed. The researchers describe this as the strongest evidence that the toolkit was built to hand off access to someone else rather than for the operator’s own use, though they frame this as a moderate-confidence assessment rather than a confirmed fact. Based on language artifacts in the recovered files, including a hardcoded link to a Russian-language VKontakte community, Hunt.io assesses the operator is likely Russian-speaking, but the firm has not attributed the campaign to any named group or government.

Most of the tools involved were not written from scratch. Hunt.io found that the operator assembled components credited to several outside developers, including a P2P protocol implementation, a serial number generator, and a backdoor exploit, rather than building the entire toolkit alone.

What Dahua and CISA say

Hunt.io said it notified Dahua’s product security team on August 10 and held its findings under a restricted disclosure period until August 18 to give the vendor time to review the research. Dahua’s own 2021 advisory for the authentication bypass flaws, DHCC-SA-202106-001, already lists updated firmware that fixes both issues, and the company has separately released repair tools for affected models. The Hacker News reported that it reached out to Dahua for comment on the scope of the campaign and did not receive a response by the time of publication.

For camera owners, the practical takeaway is simple even if the attack chain was not. Devices running firmware from before Dahua patched the 2021 flaws remain vulnerable to near-instant compromise, and the cloud relay feature can expose a camera to anyone who has, or can guess, its serial number. Security researchers generally recommend updating camera firmware to the latest version, replacing any default or reused password with a unique one, and disabling cloud relay or remote access features on devices that do not need them.

Source: Hunt.io, “Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia”, with additional reporting from The Hacker News.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular