Cybersecurity researchers at Hunt.io have uncovered a campaign that compromised more than 14,530 Dahua devices between June 17 and July 22, 2026.
The campaign, tracked as Operation CameraSwarm, used credential attacks, authentication bypasses, and Dahua’s peer-to-peer (P2P) system.
Researchers discovered an exposed 407 MB working directory containing tools, logs, target lists, and other campaign data.
The findings show how attackers combined several methods to reach large numbers of internet-connected devices.

Most of the compromised devices were located in Ukraine and Russia during the campaign.
Credential attacks were the largest part of the operation, involving 12,324 unique IP addresses across 13,229 campaign records.
Attackers also targeted Dahua devices using CVE-2021-33044 and CVE-2021-33045, both critical authentication-bypass vulnerabilities.
Hunt.io identified 1,923 cameras that were accessed through these vulnerabilities and configured with a persistent account.

The two vulnerabilities allow attackers to bypass device authentication using specially crafted requests.
CVE-2021-33044 can be triggered through a specific NetKeyboard client type, while CVE-2021-33045 involves a loopback login request.
Both vulnerabilities were previously patched by Dahua and are listed in CISA’s Known Exploited Vulnerabilities catalog.
They also carry a CVSS severity score of 9.8, making unpatched devices a serious security concern.

Attackers also abused Dahua’s P2P relay functionality to reach 283 cameras, including devices located behind network address translation.
The technique used device serial numbers to identify cameras and establish communication through Dahua’s Easy4IP relay infrastructure.
Hunt.io’s testing found that 89.4% of live serial numbers returned an open channel without authentication.
However, researchers noted that this percentage has not been independently reproduced by Dahua or other security organizations.

The P2P technique is separate from the two authentication-bypass vulnerabilities and does not represent another CVE exploitation chain.
Earlier research by ITRES Labs found that older Dahua firmware could allow valid serial numbers to establish relay paths before device authentication.
Dahua later strengthened this behavior in firmware released after mid-2024, reducing the exposure identified in earlier research.
Hunt.io also clarified that two CVEs found in the recovered tools were unrelated to the P2P technique.

The recovered files showed that attackers installed persistent accounts on 1,923 cameras during the campaign.
This allowed access to remain on some devices even after the initial compromise.
Hunt.io identified Russian-language clues in the recovered material but did not link the campaign to a known threat group.
Researchers also assessed with moderate confidence that some of the toolkit may have been designed to transfer camera access to another party.

Security teams using affected Dahua products should apply the latest firmware and security updates provided by the vendor.
ITRES Labs recommends disabling P2P where it is not needed, using strong unique passwords, and removing unnecessary accounts.
Organizations should also isolate cameras and recording systems from critical business networks wherever possible.
These measures can reduce the risk of attackers using compromised surveillance devices as an entry point.

The campaign highlights the security risks created when internet-connected surveillance devices remain exposed or poorly protected.
The 14,530-plus compromised-device figure comes from Hunt.io’s investigation, rather than independent confirmation of every affected device.
However, the authentication vulnerabilities and earlier P2P security concerns have been documented by security researchers.
Keeping Dahua devices updated, restricting unnecessary access, and monitoring for suspicious accounts can help reduce the threat.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news