securityaffairs.com 8/19/2026, 6:01:23 PM · external

Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras

Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
CyberSIXT Evidence Panel
Primary Source hunt.io

OPERATION CameraSwarm details how an attacker compromised over 14,000 Dahua cameras in Ukraine and Russia without requiring passwords for most. The operation was revealed through an exposed directory that contained the attacker's tools, including a brute-force engine that accessed 12,300 unique IP addresses. The attacker utilized two vulnerabilities from 2021 to create a backdoor account on 1,923 cameras, with most devices exposed online without authentication.

Dahua's cloud relay allowed access using serial numbers, significantly increasing vulnerability. Researchers highlighted critical flaws in referenced CVEs and noted the presence of unrelated malware on the same server. Recommendations for Dahua device owners include removing unauthorized accounts, disabling unnecessary P2P connections, patching firmware, and rotating credentials.

View Primary Source Via securityaffairs.com

Article by CyberSIXT