Threat reportThreat IntelligenceTL-2026-2075

CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia

highACTIVE

CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras (TL-2026-2075), also tracked as Operation CameraSwarm, is a high-severity tracked intrusion set, first published 2026-08-19. It has no confirmed attribution, affects Dahua Technology IPC-HX3XXX Series IP Cameras, references 2 CVEs (CVE-2021-33044, CVE-2021-33045), maps to 15 MITRE ATT&CK techniques (T1027.002, T1046, T1059.001), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2075

Threat ID
TL-2026-2075
Also known as
Operation CameraSwarm
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
government administration, telecoms, critical-infrastructure, commercial
Target regions
ukraine, russia, mexico, vietnam, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

Malware and tooling: SalatStealer, asleep_scanner, p2pwn, scannerdahua

How CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras works

Between June 17 and July 22, 2026, a single Russian-speaking operator compromised over 14,530 Dahua IP cameras across Ukraine and Russia using three parallel attack vectors: credential brute-forcing on TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 via the p2pwn tool, and cloud-relay abuse against cameras behind NAT. The operator's exposed HTTP server yielded 407 MB of operational data including source code, logs, credentials, camera snapshots, and shell history. A persistent backdoor account (p2pwn/p2password) survives password changes and factory resets on 1,923+ devices.

Hunt.io discovered the CameraSwarm campaign when their AttackCapture system crawled an unprotected HTTP directory on the operator's server (154.86.119.60) on July 23, 2026, recovering 2,616 files across 234 subdirectories (407 MB). The exposure was caused by a Python HTTP server bound to 0.0.0.0:80 from /root, preserved in the operator's shell history.

The campaign employed three parallel attack methods. First, a purpose-built asyncio credential brute-force engine (asleep_scanner, publicly available under the handle d34db33f-1007) targeted Dahua's Easy4IP binary protocol on TCP/37777, compromising 12,324 unique IPs. The engine used masscan at 10 million packets per second, first sweeping Russian address space then the global IPv4 range. It implemented adaptive concurrency scaling to 4,000 workers, kernel tuning for connection tracking, and Dahua-specific binary protocol opcodes (0xA0 login, 0xA8 channel enumeration, 0x11 snapshot capture). Captured credentials and snapshots were exfiltrated to a Telegram channel with a hardcoded VKontakte community link. The engine also produced SMART PSS-compatible XML exports for Dahua's enterprise camera management platform.

Second, the p2pwn tool (a compiled Go binary, SHA-256: 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8) chained CVE-2021-33044 and CVE-2021-33045 — both critical authentication bypass vulnerabilities (CVSS 9.8, CISA KEV since August 2024). CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers, sending the literal string 'Not Used' as the password. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection, claiming to originate from 127.0.0.1. After bypass, p2pwn installs the account p2pwn/p2password over RPC, which survives password changes and, on most firmware, factory resets. Approximately 1,923 cameras were compromised via this vector across 11 runs.

Third, the cloud-relay attack exploited Dahua's P2P relay infrastructure (easy4ipcloud.com:8800) to reach cameras behind NAT using only serial numbers. The relay uses fixed AES-256-OFB keys and IVs identical across every Dahua client ever shipped, with session-specific keys derived via PBKDF2-HMAC-SHA256 (20,000 iterations). The operator's tooling recovered that 89.4% of live serials returned an open, no-authentication channel. Approximately 283 cameras were reached through this vector. The scannerdahua toolkit further automated serial enumeration across 13 serial prefixes, each brute-forced across a 5-hex-digit suffix (1,048,576 candidates per prefix).

An offline recovery-code generation tool (seria2/asfefwq.py) replicated Dahua's account-recovery flow, deriving valid recovery codes from serial numbers alone — granting cloud-level administrative access independent of device credentials. The hardcoded console title 'CCTV Scanner | discord.gg/cctv' indicates the tool was sourced from a Dahua-exploitation Discord community.

The operator also staged a UPX-packed Windows binary (xeno.exe/1.exe, SHA-256: de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c) classified as SalatStealer — a Go-based commodity credential and cryptocurrency stealer sold as a service. A five-method PowerShell Defender evasion script was staged alongside it, targeting C:\ wholesale with SYSTEM-context scheduled tasks and Group Policy registry keys, indicating an intended enterprise victim. The identical binary appeared on a second host (185.132.53.56) two days later.

The operator's server hosted a cloned/masqueraded rbc.ru certificate on port 443, shared across over 11,000 addresses worldwide on proxy-typical ports, attributed to a shared proxy-tool default certificate rather than a compromise of RBC or Qrator. A 'Telemt Panel' React SPA management interface was observed on port 8080 (July 28-August 1, 2026), consistent with a Rust-based MTProto circumvention proxy (MTProxyMax).

The article assesses with moderate confidence that the transferable recovery-code design and enterprise-format export pipeline indicate the toolkit was built to hand access to a third party, but this falls short of a confirmed commercial operation. Dahua exploitation is common ground across multiple actors, including a separate Iran-aligned cluster and a Telnet-based Dahua DVR campaign.

MITRE ATT&CK techniques used in TL-2026-2075

Defense Evasion

T1027.002 Obfuscated Files or Information: Software Packing

Discovery

T1046 Network Service Discovery

Execution

T1059.001 Command and Scripting Interpreter: PowerShell

Initial Access

T1078.001 Valid Accounts: Default Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1110.003 Brute Force: Password Spraying

Collection

T1113 Screen Capture

Persistence

T1136.001 Create Account: Local Account

Exfiltration

T1567.004 Exfiltration Over Web Service: Exfiltration Over Webhook

Command and Control

T1572 Protocol Tunneling

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.002 Obtain Capabilities: Tool

Reconnaissance

T1595.001 Scanning IP Blocks; T1596.005 Search Open Technical Databases: Scan Databases

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

  • Dahua Technology — IPC-HX3XXX Series IP Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: Firmware 2.800.0000000.29.r.210630 and later
  • Dahua Technology — IPC-HX5XXX Series IP Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — IPC-HUM7XXX Series IP Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — DH-IPC-K15P / K35P / K35AP / A35P IP Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — VTO75X95X / VTO65XXX Video Intercoms
    Vulnerable versions: Firmware before December 2019
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — NVR1XXX / NVR2XXX / NVR5XXX / NVR6XX Network Video Recorders
    Vulnerable versions: Firmware before December 2019
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — XVR4xxx / XVR5xxx / XVR7xxx XVR Recorders
    Vulnerable versions: Firmware before December 2019
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — SD1A1 / SD22 / SD49 / SD50 / SD52C / SD6AL PTZ Dome Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: SA-2021-0130 patched firmware
  • Dahua Technology — TPC-BF1241 / TPC-BF2221 / TPC-SD2221 Thermal Cameras
    Vulnerable versions: Firmware before June 2021
    Fixed in: SA-2021-0130 patched firmware
  • OEM Rebrands (Amcrest, Lorex, Annke, Swann, RVi, ST-XVR, QVC, AC-D, SNR) — Rebranded Dahua Cameras and Recorders
    Vulnerable versions: Firmware before June 2021
    Fixed in: Check individual vendor for Dahua-based firmware updates

Remediation for CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

Patches

  • Apply Dahua SA-2021-0130 firmware patches (available since September 2021) addressing CVE-2021-33044 and CVE-2021-33045
  • Apply firmware updates addressing CVE-2025-31702 (post-authentication privilege escalation)
  • Apply mid-2024 or later firmware that restricts P2P relay serial-number-only access

Immediate actions

  • Audit all Dahua camera account lists for the account 'p2pwn' and remove it
  • Rotate every stored credential on compromised cameras (the chain performs a nine-call credential drain)
  • Block TCP port 37777 at perimeter firewalls
  • Isolate IoT/camera devices on a separate VLAN with no direct internet access
  • Assume recovery codes generated during the campaign remain valid — removing the backdoor account does not invalidate them

Workarounds

  • Disable P2P/Easy4IP in camera settings (Settings > Network > Access Platform)
  • Block outbound connections to Dahua relay backend addresses (165.154.164.0/23, 128.14.224.0/20, AS135377 UCLOUD)
  • Use VPN for remote camera access instead of direct internet exposure
  • Change default credentials on all cameras and disable unused accounts

Longer-term hardening

  • Disable P2P relay on all cameras where not actively required
  • Implement network segmentation for all IoT/surveillance devices
  • Deploy behavioral detection for Dahua-specific protocol anomalies
  • Monitor for Defender exclusion paths set to C:\, CIM method invocations against MSFT_MpPreference, and unscheduled Group Policy refreshes on Windows estates
  • Replace Dahua cameras with patched firmware or alternative vendors where possible

CVEs associated with CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

CVE-2021-33044, CVE-2021-33045

Weaknesses (CWE) in CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

CWE-287

Timeline of CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

  • Earliest operating system generation recorded on the operator VPS address (154.86.119.60) — Ubuntu 22.04 with OpenSSH 8.9p1
  • CameraSwarm campaign begins: VPS activated with speedtest measuring uplink at 11:24:08 UTC; masscan rate configured at 10 million packets per second
  • Operator server transitions to Debian 13 (OpenSSH 10.0p2) — OS used for the remainder of the campaign
  • Operator server transitions from Ubuntu 22.04 to Ubuntu 24.04 (OpenSSH 9.6p1 on port 20001)
  • Brute-force engine (asleep_scanner) deployed; largest single credential haul recovered, skewed toward Mexican and Vietnamese consumer ISP ranges
  • Operator first tested the P2P cloud relay workflow against cameras behind NAT
  • Targeting shifted to Russian and CIS telecom netblocks after initial Mexican/Vietnamese sweeps
  • p2pwn CVE-2021-33044/CVE-2021-33045 authentication bypass chain deployed against Ukrainian camera ranges, nearly 3 weeks after relay testing began
  • Largest wave of activity; campaign concludes after 35 days with 14,530+ cameras compromised
  • Hunt.io AttackCapture system crawls the operator's exposed HTTP directory at 11:45 UTC, recovering 2,616 files (407 MB) across 234 subdirectories
  • SalatStealer binary (identical SHA-256) restaged on second host 185.132.53.56 under original filename xeno.exe
  • Telemt Panel (React SPA management interface, consistent with MTProxyMax) observed active on port 8080 of the operator server, observed through August 1
  • Hunt.io notified relevant national CERTs and Dahua PSIRT of the campaign findings
  • Hunt.io publishes Operation CameraSwarm technical report detailing the full attack chain, infrastructure, and IOCs

Sources cited for CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras

Detection coverage for TL-2026-2075

As of 2026-08-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2075 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats