A mass-hacking campaign dubbed Operation CameraSwarm compromised over 14,000 Dahua IP cameras in Ukraine and Russia between June 17 and July 22. Hunt.io's analysis revealed that the attackers leveraged brute-force methods on 12,324 unique addresses, deploying a persistent backdoor on 1,923 cameras via Remote Procedure Call (RPC). They exploited multiple vulnerabilities (CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943) to bypass authentication and maintained access despite passwords and resets.
The attackers also utilized Dahua's cloud relay to access devices behind NATs. While the attacker's broader motivations remain unclear, indications suggest they were prepared for the campaign well in advance with a sophisticated toolkit.