In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.
The operation ran for at least 35 days between June 17 and July 22, compromising devices by exploiting vulnerabilities, brute-forcing logins, and using offline recovery codes from serial numbers for cloud-registered cameras.
Researchers at threat intelligence company Hunt.io discovered the campaign after finding a working directory on an HTTP server that the operator left unprotected.
Hunt.io recovered 407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.
According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:
The recovery code generation mechanism in the attack toolkit leverages the camera serial number, which allows the CameraSwarm operator to redeem new codes via Dahua’s standard password-recovery process without knowing the current admin password.
The researchers found two misleading vulnerability references in the toolkit, CVE-2024-39943 and CVE-2025-31702, which are not exploited in the observed attacks.
Hunt.io’s analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, “the operator’s focus settled on Russian and CIS telecom netblocks.”
However, the researchers also found Russian comments in modified code inserted in repurposed public tools.
On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.
Dahua cameras reachable through port 37777 between June and July should be treated as potentially compromised. Owners should examine them for the presence of a ‘p2pwn’ account and remove it.
Hunt.io warns that removing the backdoor account does not invalidate recovery codes generated by the toolkit, and they remain usable until Dahua alters the derivation server-side.
Additionally, users are recommended to disable P2P when not needed, and apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Signal adds new security feature to thwart man-in-the-middle attacks
New Spectre v2 attack impacts Linux systems on Intel CPUs
Google Blogger locks hundreds of blogs in malware false positive
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
GitHub, PyPI add time-based defenses against supply chain attacks
Publicly accessible cameras.. Corp-Internal flat networks with cameras accessible to workstations… Any NVR camera that talks to anything but the NVR is a risk What a joke..
Microsoft confirms GitHub is down worldwide
Hacker claims 3.6 million Azure account records stolen from major companies
Microsoft working on Defender patch for ShieldBreak zero-day
91% of AI Apps Appeared in 16 Months. Get Material’s OAuth Risk Report
Signature-based prevention fell to 50%. See what your controls still stop.
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Stop AI slopsquatting attacks. Secure open source package ingestion before it hits your build.
Certighost CVE is new. The privilege behind it isn’t. Discover where yours is hiding.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



