Threat reportThreat IntelligenceTL-2026-2075
CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia
CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras (TL-2026-2075), also tracked as Operation CameraSwarm, is a high-severity tracked intrusion set, first published 2026-08-19. It has no confirmed attribution, affects Dahua Technology IPC-HX3XXX Series IP Cameras, references 2 CVEs (CVE-2021-33044, CVE-2021-33045), maps to 15 MITRE ATT&CK techniques (T1027.002, T1046, T1059.001), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2075
- Threat ID
- TL-2026-2075
- Also known as
- Operation CameraSwarm
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- government administration, telecoms, critical-infrastructure, commercial
- Target regions
- ukraine, russia, mexico, vietnam, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
Malware and tooling: SalatStealer, asleep_scanner, p2pwn, scannerdahua
How CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras works
Between June 17 and July 22, 2026, a single Russian-speaking operator compromised over 14,530 Dahua IP cameras across Ukraine and Russia using three parallel attack vectors: credential brute-forcing on TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 via the p2pwn tool, and cloud-relay abuse against cameras behind NAT. The operator's exposed HTTP server yielded 407 MB of operational data including source code, logs, credentials, camera snapshots, and shell history. A persistent backdoor account (p2pwn/p2password) survives password changes and factory resets on 1,923+ devices.
Hunt.io discovered the CameraSwarm campaign when their AttackCapture system crawled an unprotected HTTP directory on the operator's server (154.86.119.60) on July 23, 2026, recovering 2,616 files across 234 subdirectories (407 MB). The exposure was caused by a Python HTTP server bound to 0.0.0.0:80 from /root, preserved in the operator's shell history.
The campaign employed three parallel attack methods. First, a purpose-built asyncio credential brute-force engine (asleep_scanner, publicly available under the handle d34db33f-1007) targeted Dahua's Easy4IP binary protocol on TCP/37777, compromising 12,324 unique IPs. The engine used masscan at 10 million packets per second, first sweeping Russian address space then the global IPv4 range. It implemented adaptive concurrency scaling to 4,000 workers, kernel tuning for connection tracking, and Dahua-specific binary protocol opcodes (0xA0 login, 0xA8 channel enumeration, 0x11 snapshot capture). Captured credentials and snapshots were exfiltrated to a Telegram channel with a hardcoded VKontakte community link. The engine also produced SMART PSS-compatible XML exports for Dahua's enterprise camera management platform.
Second, the p2pwn tool (a compiled Go binary, SHA-256: 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8) chained CVE-2021-33044 and CVE-2021-33045 — both critical authentication bypass vulnerabilities (CVSS 9.8, CISA KEV since August 2024). CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers, sending the literal string 'Not Used' as the password. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection, claiming to originate from 127.0.0.1. After bypass, p2pwn installs the account p2pwn/p2password over RPC, which survives password changes and, on most firmware, factory resets. Approximately 1,923 cameras were compromised via this vector across 11 runs.
Third, the cloud-relay attack exploited Dahua's P2P relay infrastructure (easy4ipcloud.com:8800) to reach cameras behind NAT using only serial numbers. The relay uses fixed AES-256-OFB keys and IVs identical across every Dahua client ever shipped, with session-specific keys derived via PBKDF2-HMAC-SHA256 (20,000 iterations). The operator's tooling recovered that 89.4% of live serials returned an open, no-authentication channel. Approximately 283 cameras were reached through this vector. The scannerdahua toolkit further automated serial enumeration across 13 serial prefixes, each brute-forced across a 5-hex-digit suffix (1,048,576 candidates per prefix).
An offline recovery-code generation tool (seria2/asfefwq.py) replicated Dahua's account-recovery flow, deriving valid recovery codes from serial numbers alone — granting cloud-level administrative access independent of device credentials. The hardcoded console title 'CCTV Scanner | discord.gg/cctv' indicates the tool was sourced from a Dahua-exploitation Discord community.
The operator also staged a UPX-packed Windows binary (xeno.exe/1.exe, SHA-256: de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c) classified as SalatStealer — a Go-based commodity credential and cryptocurrency stealer sold as a service. A five-method PowerShell Defender evasion script was staged alongside it, targeting C:\ wholesale with SYSTEM-context scheduled tasks and Group Policy registry keys, indicating an intended enterprise victim. The identical binary appeared on a second host (185.132.53.56) two days later.
The operator's server hosted a cloned/masqueraded rbc.ru certificate on port 443, shared across over 11,000 addresses worldwide on proxy-typical ports, attributed to a shared proxy-tool default certificate rather than a compromise of RBC or Qrator. A 'Telemt Panel' React SPA management interface was observed on port 8080 (July 28-August 1, 2026), consistent with a Rust-based MTProto circumvention proxy (MTProxyMax).
The article assesses with moderate confidence that the transferable recovery-code design and enterprise-format export pipeline indicate the toolkit was built to hand access to a third party, but this falls short of a confirmed commercial operation. Dahua exploitation is common ground across multiple actors, including a separate Iran-aligned cluster and a Telnet-based Dahua DVR campaign.
MITRE ATT&CK techniques used in TL-2026-2075
Defense Evasion
T1027.002 Obfuscated Files or Information: Software Packing
Discovery
T1046 Network Service Discovery
Execution
T1059.001 Command and Scripting Interpreter: PowerShell
Initial Access
T1078.001 Valid Accounts: Default Accounts; T1190 Exploit Public-Facing Application
Credential Access
T1110.003 Brute Force: Password Spraying
Collection
Persistence
T1136.001 Create Account: Local Account
Exfiltration
T1567.004 Exfiltration Over Web Service: Exfiltration Over Webhook
Command and Control
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.002 Obtain Capabilities: Tool
Reconnaissance
T1595.001 Scanning IP Blocks; T1596.005 Search Open Technical Databases: Scan Databases
defense-impairment
Affected products and versions in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
- Dahua Technology — IPC-HX3XXX Series IP Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: Firmware 2.800.0000000.29.r.210630 and later - Dahua Technology — IPC-HX5XXX Series IP Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — IPC-HUM7XXX Series IP Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — DH-IPC-K15P / K35P / K35AP / A35P IP Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — VTO75X95X / VTO65XXX Video Intercoms
Vulnerable versions: Firmware before December 2019
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — NVR1XXX / NVR2XXX / NVR5XXX / NVR6XX Network Video Recorders
Vulnerable versions: Firmware before December 2019
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — XVR4xxx / XVR5xxx / XVR7xxx XVR Recorders
Vulnerable versions: Firmware before December 2019
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — SD1A1 / SD22 / SD49 / SD50 / SD52C / SD6AL PTZ Dome Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: SA-2021-0130 patched firmware - Dahua Technology — TPC-BF1241 / TPC-BF2221 / TPC-SD2221 Thermal Cameras
Vulnerable versions: Firmware before June 2021
Fixed in: SA-2021-0130 patched firmware - OEM Rebrands (Amcrest, Lorex, Annke, Swann, RVi, ST-XVR, QVC, AC-D, SNR) — Rebranded Dahua Cameras and Recorders
Vulnerable versions: Firmware before June 2021
Fixed in: Check individual vendor for Dahua-based firmware updates
Remediation for CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
Patches
- Apply Dahua SA-2021-0130 firmware patches (available since September 2021) addressing CVE-2021-33044 and CVE-2021-33045
- Apply firmware updates addressing CVE-2025-31702 (post-authentication privilege escalation)
- Apply mid-2024 or later firmware that restricts P2P relay serial-number-only access
Immediate actions
- Audit all Dahua camera account lists for the account 'p2pwn' and remove it
- Rotate every stored credential on compromised cameras (the chain performs a nine-call credential drain)
- Block TCP port 37777 at perimeter firewalls
- Isolate IoT/camera devices on a separate VLAN with no direct internet access
- Assume recovery codes generated during the campaign remain valid — removing the backdoor account does not invalidate them
Workarounds
- Disable P2P/Easy4IP in camera settings (Settings > Network > Access Platform)
- Block outbound connections to Dahua relay backend addresses (165.154.164.0/23, 128.14.224.0/20, AS135377 UCLOUD)
- Use VPN for remote camera access instead of direct internet exposure
- Change default credentials on all cameras and disable unused accounts
Longer-term hardening
- Disable P2P relay on all cameras where not actively required
- Implement network segmentation for all IoT/surveillance devices
- Deploy behavioral detection for Dahua-specific protocol anomalies
- Monitor for Defender exclusion paths set to C:\, CIM method invocations against MSFT_MpPreference, and unscheduled Group Policy refreshes on Windows estates
- Replace Dahua cameras with patched firmware or alternative vendors where possible
CVEs associated with CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
CVE-2021-33044, CVE-2021-33045
Weaknesses (CWE) in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
Timeline of CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
- Earliest operating system generation recorded on the operator VPS address (154.86.119.60) — Ubuntu 22.04 with OpenSSH 8.9p1
- CameraSwarm campaign begins: VPS activated with speedtest measuring uplink at 11:24:08 UTC; masscan rate configured at 10 million packets per second
- Operator server transitions to Debian 13 (OpenSSH 10.0p2) — OS used for the remainder of the campaign
- Operator server transitions from Ubuntu 22.04 to Ubuntu 24.04 (OpenSSH 9.6p1 on port 20001)
- Brute-force engine (asleep_scanner) deployed; largest single credential haul recovered, skewed toward Mexican and Vietnamese consumer ISP ranges
- Operator first tested the P2P cloud relay workflow against cameras behind NAT
- Targeting shifted to Russian and CIS telecom netblocks after initial Mexican/Vietnamese sweeps
- p2pwn CVE-2021-33044/CVE-2021-33045 authentication bypass chain deployed against Ukrainian camera ranges, nearly 3 weeks after relay testing began
- Largest wave of activity; campaign concludes after 35 days with 14,530+ cameras compromised
- Hunt.io AttackCapture system crawls the operator's exposed HTTP directory at 11:45 UTC, recovering 2,616 files (407 MB) across 234 subdirectories
- SalatStealer binary (identical SHA-256) restaged on second host 185.132.53.56 under original filename xeno.exe
- Telemt Panel (React SPA management interface, consistent with MTProxyMax) observed active on port 8080 of the operator server, observed through August 1
- Hunt.io notified relevant national CERTs and Dahua PSIRT of the campaign findings
- Hunt.io publishes Operation CameraSwarm technical report detailing the full attack chain, infrastructure, and IOCs
Sources cited for CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras
- Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign
- CVE-2021-33044 - NVD Detail
- CVE-2021-33045 - NVD Detail
- CISA Known Exploited Vulnerabilities Catalog - CVE-2021-33044
- Dahua Security Advisory SA-2021-0130
- p2pwn - Dahua Camera Exploitation Tool
- asleep_scanner - Dahua DVR Brute-Forcing Tool
- SalatStealer Go-Compiled RAT Analysis
- Dahua Authentication Bypass PoC (PacketStorm)
- CVE-2025-31702 - Dahua EoP Research (ITRES Labs)
Detection coverage for TL-2026-2075
As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2075 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.