Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026

    Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe

    August 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility
    • Israel and America Agree on Ali Shaath as Gaza’s New Leader
    • Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe
    • 81-year-old admits German cold-case murder of US tourist in 1994
    • AI will not solve cash crisis for UK councils, warn experts
    • Burnham announces plans to clean up illegal waste dumps – UK politics live | Politics
    • How to use your TV as a PC monitor in 3 simple steps (and without buying anything)
    • Critical Zimbra RCE flaw now actively exploited in attacks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, August 20
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers compromise 14,500 Dahua web cameras in 35-day campaign

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 20, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia.

    The operation ran for at least 35 days between June 17 and July 22, compromising devices by exploiting vulnerabilities, brute-forcing logins, and  using offline recovery codes from serial numbers for cloud-registered cameras.

    Researchers at threat intelligence company Hunt.io discovered the campaign after finding a working directory on an HTTP server that the operator left unprotected.

    image

    Hunt.io recovered 407 MB of data comprising 2,616 files across 234 directories, including source code, logs, credentials, captured camera images, shell history, and exploitation results, which helped them map an impressive operation.

    Campaign overview
    CameraSwarm campaign overview
    Source: Hunt.io

    According to their findings, the 35-day CameraSwarm campaign compromised 14,530 Dahua IP cameras using three attack methods in parallel:

    1. A brute-forcing system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. It captured usable camera snapshots, sent results to Telegram, and exported them for Dahua’s SMART PSS platform.
    2. Exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities using a tool called p2pwn that installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. The account survives password changes and, on most firmware versions, factory resets.
    3. A cloud-relay attack reached 283 cameras behind NAT using only serial numbers and SDK credentials embedded in Dahua applications. Data indicates that 89.4% of live serials exposed an access channel without authentication.

    The recovery code generation mechanism in the attack toolkit leverages the camera serial number, which allows the CameraSwarm operator to redeem new codes via Dahua’s standard password-recovery process without knowing the current admin password.

    The researchers found two misleading vulnerability references in the toolkit, CVE-2024-39943 and CVE-2025-31702, which are not exploited in the observed attacks.

    The observed attack chain
    The observed attack chain
    Source: Hunt.io

    Hunt.io’s analysis uncovered that scanning was global, first checking the Russian address space, then scanning the entire IPv4 range. According to the researchers, “the operator’s focus settled on Russian and CIS telecom netblocks.”

    However, the researchers also found Russian comments in modified code inserted in repurposed public tools.

    On August 10, Hunt.io notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign.

    Dahua cameras reachable through port 37777 between June and July should be treated as potentially compromised. Owners should examine them for the presence of a ‘p2pwn’ account and remove it.

    Hunt.io warns that removing the backdoor account does not invalidate recovery codes generated by the toolkit, and they remain usable until Dahua alters the derivation server-side.

    Additionally, users are recommended to disable P2P when not needed, and apply the Dahua SA-2021-0130 firmware updates for CVE-2021-33044 and CVE-2021-33045, or a later firmware version.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    35day cameras campaign compromise Dahua hackers Web
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Zimbra RCE flaw now actively exploited in attacks

    Microsoft says August Windows updates may cause gaming issues

    Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

    Sakura Internet hack exposes data of up to 1.36 million accounts

    CareCloud Data Breach Impact Grows to 3.7 Million Individuals

    Rogue ransomware affiliate poses as recovery firm to steal payments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026

    Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe

    August 20, 2026

    81-year-old admits German cold-case murder of US tourist in 1994

    August 20, 2026
    Latest Posts

    DHS Official Resigns, Citing ‘War on Immigrants’

    July 27, 2026

    Police make inquiries after Farage reports Polanski post for ‘inciting murder’ | Nigel Farage

    July 27, 2026

    A Japanese town wrestles with identity after protests over its first mosque

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Poland’s Orlen locks in Norwegian crude supplies with Equinor amid oil market volatility

    August 20, 2026

    Israel and America Agree on Ali Shaath as Gaza’s New Leader

    August 20, 2026

    Liberia’s former Vice-President Jewel Howard-Taylor charged in drug-trafficking probe

    August 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.