# CameraSwarm Campaign Compromises 14,500 Dahua IP Cameras Across Ukraine and Russia

> Between June 17 and July 22, 2026, a single Russian-speaking operator compromised over 14,530 Dahua IP cameras across Ukraine and Russia using three parallel attack vectors: credential brute-forcing on TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 via the p2pwn tool, and cloud-relay abuse against cameras behind NAT. The operator's exposed HTTP server yielded 407 MB of operational data including source code, logs, credentials, camera snapshots, and shell history. A persistent backdoor account (p2pwn/p2password) survives password changes and factory resets on 1,923+ devices.

- **Published:** 2026-08-19T00:00:00Z
- **Last reviewed:** 2026-08-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2075
- **ID:** TL-2026-2075
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-33044, CVE-2021-33045

## Description

Hunt.io discovered the CameraSwarm campaign when their AttackCapture system crawled an unprotected HTTP directory on the operator's server (154.86.119.60) on July 23, 2026, recovering 2,616 files across 234 subdirectories (407 MB). The exposure was caused by a Python HTTP server bound to 0.0.0.0:80 from /root, preserved in the operator's shell history.

The campaign employed three parallel attack methods. First, a purpose-built asyncio credential brute-force engine (asleep_scanner, publicly available under the handle d34db33f-1007) targeted Dahua's Easy4IP binary protocol on TCP/37777, compromising 12,324 unique IPs. The engine used masscan at 10 million packets per second, first sweeping Russian address space then the global IPv4 range. It implemented adaptive concurrency scaling to 4,000 workers, kernel tuning for connection tracking, and Dahua-specific binary protocol opcodes (0xA0 login, 0xA8 channel enumeration, 0x11 snapshot capture). Captured credentials and snapshots were exfiltrated to a Telegram channel with a hardcoded VKontakte community link. The engine also produced SMART PSS-compatible XML exports for Dahua's enterprise camera management platform.

Second, the p2pwn tool (a compiled Go binary, SHA-256: 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8) chained CVE-2021-33044 and CVE-2021-33045 — both critical authentication bypass vulnerabilities (CVSS 9.8, CISA KEV since August 2024). CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers, sending the literal string 'Not Used' as the password. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection, claiming to originate from 127.0.0.1. After bypass, p2pwn installs the account p2pwn/p2password over RPC, which survives password changes and, on most firmware, factory resets. Approximately 1,923 cameras were compromised via this vector across 11 runs.

Third, the cloud-relay attack exploited Dahua's P2P relay infrastructure (easy4ipcloud.com:8800) to reach cameras behind NAT using only serial numbers. The relay uses fixed AES-256-OFB keys and IVs identical across every Dahua client ever shipped, with session-specific keys derived via PBKDF2-HMAC-SHA256 (20,000 iterations). The operator's tooling recovered that 89.4% of live serials returned an open, no-authentication channel. Approximately 283 cameras were reached through this vector. The scannerdahua toolkit further automated serial enumeration across 13 serial prefixes, each brute-forced across a 5-hex-digit suffix (1,048,576 candidates per prefix).

An offline recovery-code generation tool (seria2/asfefwq.py) replicated Dahua's account-recovery flow, deriving valid recovery codes from serial numbers alone — granting cloud-level administrative access independent of device credentials. The hardcoded console title 'CCTV Scanner | discord.gg/cctv' indicates the tool was sourced from a Dahua-exploitation Discord community.

The operator also staged a UPX-packed Windows binary (xeno.exe/1.exe, SHA-256: de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c) classified as SalatStealer — a Go-based commodity credential and cryptocurrency stealer sold as a service. A five-method PowerShell Defender evasion script was staged alongside it, targeting C:\ wholesale with SYSTEM-context scheduled tasks and Group Policy registry keys, indicating an intended enterprise victim. The identical binary appeared on a second host (185.132.53.56) two days later.

The operator's server hosted a cloned/masqueraded rbc.ru certificate on port 443, shared across over 11,000 addresses worldwide on proxy-typical ports, attributed to a shared proxy-tool default certificate rather than a compromise of RBC or Qrator. A 'Telemt Panel' React SPA management interface was observed on port 8080 (July 28-August 1, 2026), consistent with a Rust-based MTProto circumvention proxy (MTProxyMax).

The article assesses with moderate confidence that the transferable recovery-code design and enterprise-format export pipeline indicate the toolkit was built to hand access to a third party, but this falls short of a confirmed commercial operation. Dahua exploitation is common ground across multiple actors, including a separate Iran-aligned cluster and a Telnet-based Dahua DVR campaign.

## MITRE ATT&CK

- T1595.001 Scanning IP Blocks
- T1596.005 Search Open Technical Databases: Scan Databases
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1588.002 Obtain Capabilities: Tool
- T1190 Exploit Public-Facing Application
- T1078.001 Valid Accounts: Default Accounts
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1136.001 Create Account: Local Account
- T1027.002 Obfuscated Files or Information: Software Packing
- T1685 Disable or Modify Tools
- T1110.003 Brute Force: Password Spraying
- T1046 Network Service Discovery
- T1113 Screen Capture
- T1572 Protocol Tunneling
- T1567.004 Exfiltration Over Web Service: Exfiltration Over Webhook

## Sources

- [Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia](https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised)
- [Hackers compromise 14,500 Dahua web cameras in 35-day campaign](https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/)
- [CVE-2021-33044 - NVD Detail](https://nvd.nist.gov/vuln/detail/CVE-2021-33044)
- [CVE-2021-33045 - NVD Detail](https://nvd.nist.gov/vuln/detail/CVE-2021-33045)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2021-33044](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Dahua Security Advisory SA-2021-0130](https://www.dahuasecurity.com/support/cybersecurity/details/957)
- [p2pwn - Dahua Camera Exploitation Tool](https://github.com/thebadinteger/p2pwn)
- [asleep_scanner - Dahua DVR Brute-Forcing Tool](https://github.com/S0Ulle33/asleep_scanner)
- [SalatStealer Go-Compiled RAT Analysis](https://intel.breakglass.tech/post/salat-stealer-go-compiled-rat-with-dns-over-https-c2-resolution-62-crypto-wallet-extensions-and-a-live-maas-panel-on-russian-infrastructure)
- [Dahua Authentication Bypass PoC (PacketStorm)](https://packetstormsecurity.com/files/164423/Dahua-Authentication-Bypass.html)
- [CVE-2025-31702 - Dahua EoP Research (ITRES Labs)](https://labs.itresit.es/2025/10/15/dahua-cve-2025-31702-p2p-auto-update-eop/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2075
