All incidents

Operation CameraSwarm compromises over 14,000 Dahua cameras

incidentopenAug 19, 2026 — Aug 26, 2026
Operation CameraSwarm compromises over 14,000 Dahua cameras

OVER fourteen thousand Dahua IP cameras were hijacked in a campaign dubbed Operation CameraSwarm, with the majority of infected devices located in Ukraine and Russia (source). The intrusion began in mid‑August 2026 and continued for more than a week, during which attackers gained live video streams, configuration files and stored recordings from the compromised units. Security researchers first noticed the activity after discovering an exposed directory on a public server that contained the attacker’s tools and logs. The scale of the compromise highlights how quickly a large IoT base can be turned into a surveillance platform when basic protections are missing.

The attackers used three complementary methods to gain control (details). First, they launched credential‑stuffing attempts against devices that still shipped with factory usernames and passwords or weak administrator codes. Second, they exploited two vulnerabilities that were disclosed in 2021, which allowed them to create a hidden backdoor account on cameras that were reachable over the web. Third, they abused Dahua’s peer‑to‑peer relay service, which lets anyone connect to a camera by supplying only its serial number, bypassing any authentication check.

The exposed directory that gave researchers visibility into the operation contained a custom brute‑forcer that had probed 12,300 unique IP addresses looking for Dahua devices (report). Inside the same folder were scripts that added a privileged user to 1,923 cameras by exploiting the 2021 flaws, plus notes describing how the P2P relay was used to hop onto devices without needing a password. Many of the compromised cameras were directly reachable from the internet, their video feeds accessible through standard RTSP ports, which made the harvested footage easy to exfiltrate.

No single threat actor has been publicly tied to Operation CameraSwarm, but the server that hosted the tools also held samples of unrelated malware, indicating the infrastructure may have been repurposed from other campaigns (source). The incident demonstrates how default credentials and unrestricted P2P access can transform a large base of IoT devices into a versatile foothold for espionage, distributed denial‑of‑service attacks or further malware distribution. The attackers operated for over a week before the exposed directory was taken down, suggesting they had ample time to collect intelligence.

Defenders should begin by confirming that every Dahua unit is running the latest firmware, which patches the 2021 flaws exploited in this campaign (details). Next, replace any default or easily guessed passwords with long, unique passphrases and disable the P2P relay unless it is strictly required for remote viewing. Placing the cameras behind a firewall that blocks inbound connections from the internet, while allowing only approved management traffic, will greatly reduce the chance of a repeat compromise.

Administrators should also audit the user list on each camera to make sure no unknown accounts have been added, and segment the camera subnet from critical network zones to limit lateral movement. Enabling detailed authentication logs and setting alerts for repeated failed login attempts will help spot brute‑force activity early. Finally, subscribing to reputable threat‑intelligence feeds ensures that new vulnerabilities or abuse trends affecting Dahua equipment are identified before they can be exploited at scale.

Intelligence briefing updated Aug 26, 2026

Root sourcehunt.io
Timeline Coverage

Swipe to explore timeline