All incidents

Operation CameraSwarm compromises over 14,000 Dahua IP cameras

incidentopenAug 19, 2026 — Aug 20, 2026
Brute force attack hijacks Dahua cameras in Ukraine and Russia

OVER 14,000 Dahua IP cameras were hijacked in a brute‑force campaign that spanned Ukraine and Russia, an operation dubbed CameraSwarm. The assault unfolded between 17 June and 22 July 2026, with attackers guessing credentials and installing a backdoor on a subset of devices. The activity was first uncovered by Hunt.io and subsequently covered by SecurityWeek and SecurityAffairs.

Researchers found that the adversaries probed 12,324 unique IP addresses using automated brute‑forcing tools, successfully gaining remote procedure call access on 1,923 cameras. On those systems they created unauthorized accounts and deployed a persistent payload that survived password changes and factory resets. The intrusion relied on exploiting three vulnerabilities: CVE-2021-33044, CVE-2021-33045 and the lesser known CVE-20244-39943, which together allowed authentication bypass and privilege escalation.

Additionally, the attackers abused Dahua’s cloud relay service to reach devices positioned behind NATs, turning the manufacturer’s own convenience feature into a pivot point.

The campaign came to light after an exposed directory on a compromised server revealed the attacker’s toolkit, including scripts for credential guessing, account creation and RPC interaction. No threat actor has been publicly attributed, but the level of preparation and the use of multiple zero‑day‑age exploits point to a well‑funded operation. Analysts also observed unrelated malware residing on the same server, suggesting the infrastructure may have been shared with other criminal ventures.

Despite the broad scope, the attackers did not appear to seek ransom; instead they seemed focused on maintaining long‑term access to the video feeds.

Defenders should begin by rotating all default and weak passwords on Dahua equipment, ensuring that each device uses a strong, unique credential. If the remote procedure call interface is not required for legitimate operations, it ought to be disabled at the device level or blocked by perimeter firewalls. Inbound traffic to the cloud relay ports should be restricted to known management networks, preventing external abuse of the manufacturer’s tunnelling mechanism.

Administrators must then search for any unfamiliar user accounts, remove them immediately, and apply the latest firmware updates that patch CVE-2021-33044, CVE-2021-33045 and CVE-20244-39943. Finally, continuous monitoring of authentication logs for anomalous login spikes can help detect any repeat attempts at compromise.

Beyond credential hygiene, organisations should isolate camera traffic onto a dedicated VLAN or separate subnet, limiting lateral movement from compromised devices to critical servers. Disabling unnecessary peer‑to‑peer (P2P) capabilities reduces the attack surface, while using a virtual private network for remote administration keeps management channels encrypted and out of the public internet.

Regular firmware checks and a formal end‑of‑life review are advisable, especially for models that no longer receive security updates from Dahua. Where feasible, consider replacing ageing units with newer hardware that enforces stronger default security controls and signed boot processes.

Sharing indicators of compromise with trusted information‑sharing groups and reporting the incident to national computer emergency response teams can amplify defensive efforts across the sector. Treating IoT assets as part of the organisation’s critical infrastructure encourages investment in hardening measures and regular red‑team testing. By staying vigilant and applying these controls, security teams can reduce the likelihood of similar hijacks and protect the integrity of their video surveillance networks.

Intelligence briefing updated Aug 20, 2026

CVE-2021-33044 9.8 KEV CVE-2021-33045 9.8 KEV
Root sourcehunt.io
Timeline Coverage

Swipe to explore timeline