CameraSwarm Operation Compromises 14,500 Dahua Security Cameras

Operation CameraSwarm Dahua security camera vulnerability and backdoor compromise

In a stunning display of cyber aggression, a lone operator successfully infiltrated over 14,500 Dahua security cameras within a mere five weeks. Alarmingly, the attacker meticulously planted a hidden backdoor account on nearly 2,000 of these compromised devices. Consequently, this insidious modification guarantees the intruder continued access, even if the legitimate owner dutifully changes the primary password. The extensive Operation CameraSwarm campaign raged from June 17 to July 22, 2026. While the operation affected devices globally, Ukraine and Russia suffered the highest concentration of confirmed security breaches.

Uncovering the Attack Infrastructure

The cybersecurity experts at Hunt.io serendipitously discovered this massive operation following a critical error made by the malicious actor. The attacker inadvertently exposed a server containing their operational files to the public internet via HTTP. Seizing this opportunity, the diligent specialists swiftly downloaded 407 megabytes of highly sensitive data. This treasure trove encompassed 2,616 files distributed across 234 directories. Inside, they found custom programs, detailed operational logs, extensive scanning results, and comprehensive intelligence regarding the compromised camera systems.

Exploiting Weak Passwords and Known Vulnerabilities

The primary vector for this widespread infiltration involved aggressive password brute-forcing, specifically targeting devices with port 37777 exposed. Through this blunt method, the operator successfully harvested access credentials for 12,324 unique IP addresses. However, when confronting cameras fortified with robust passwords, the attacker seamlessly pivoted to older, known vulnerabilities. Specifically, they weaponized CVE-2021-33044 and CVE-2021-33045, both of which allow unauthorized users to completely bypass authentication protocols.

Dahua originally issued critical patches to close both vulnerabilities in 2021. Furthermore, the United States Cybersecurity and Infrastructure Security Agency previously confirmed that threat actors actively utilized these precise exploits in real-world attacks.

The Persistent p2pwn Backdoor

Following a successful security bypass, the malicious software surreptitiously generated a hidden account named p2pwn on the camera. The attacker cleverly assigned a separate, highly secure password to this backdoor account. Investigators discovered this stealthy persistence mechanism active on 1,923 devices. Because this rogue account operates entirely independently of the primary administrator credentials, a standard password change does not sever the attacker’s access. Disturbingly, on the majority of firmware versions, this concealed account stubbornly survives even a complete factory reset of the camera.

Abusing the Dahua Cloud Infrastructure

Furthermore, the attacker managed to locate and compromise an additional 283 cameras utilizing only their serial numbers. They achieved this by exploiting the native Dahua cloud infrastructure. According to the meticulous CameraSwarm operational logs, a staggering 89.4 percent of the devices accessed through this specific method required absolutely no credentials. The operator also systematically generated recovery codes capable of granting administrative access via the cloud, completely independent of the camera’s local password configuration. A separate Dahua security advisory details the related CVE-2025-31702 vulnerability. However, Hunt.io sternly warns that the exploitation mechanism discovered in the wild is significantly broader than the manufacturer’s published description.

Automated Data Exfiltration and Mitigation Recommendations

The attacker automated the exfiltration process, seamlessly transmitting captured images and stolen credentials directly to a dedicated Telegram channel. Concurrently, they meticulously formatted the compromised camera intelligence to ensure perfect compatibility with the Dahua SmartPSS management system. Specialists strongly suspect this highly organized structure indicates an intention to easily transfer ready-made access to other malicious actors. However, they found no concrete evidence confirming the actual sale of this access.

Security experts urgently advise all Dahua owners to immediately update their device firmware. Furthermore, they must thoroughly audit their user lists, actively searching for the unauthorized p2pwn account. Owners should immediately change all saved passwords and critically restrict internet access to port 37777. Finally, if the P2P cloud connection is not strictly necessary for daily operations, administrators should disable it entirely. Proactively, Hunt.io alerted various national computer emergency response teams and the dedicated Dahua PSIRT team prior to publishing their comprehensive report.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply