[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpDp-BWuokBusckw246aQV48lC7eBWnsm1cvcUA8EOek":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"5dd9388a-b803-4c45-b2bc-6ceccf6ebfbf","Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia","threat-actor-hacks-14-000-ip-cameras-in-ukraine-and-russia-7c3527","Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.","A threat actor, known as Operation CameraSwarm, has compromised over 14,000 Dahua IP cameras, primarily in Ukraine and Russia, between June 17 and July 22. The campaign utilized a brute-force engine and chained three vulnerabilities (CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943) to deploy a persistent backdoor account with the credentials 'p2pwn'\u002F'p2password'. The attackers also leveraged Dahua's cloud relay to access cameras behind NATs, and the infrastructure for the campaign was established at least a year prior.","Threat actor Operation CameraSwarm compromises 14,000+ Dahua IP cameras in Ukraine and Russia.","A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports. The activity, referred to as Operation CameraSwarm, occurred between June 17 and July 22. It initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges, but later focused on Russian and CIS telecom netblocks. Hunt.io says it gained access to the threat actor’s servers, where it found 2,616 files across 234 subdirectories, or approximately 407 MB of data, left in an open HTTP directory that the hackers exposed themselves. Analysis of the data revealed the compromise of over 14,530 devices within the 35-day-long campaign. A brute-force engine was used to target 12,324 unique addresses. The threat actor deployed a persistent backdoor account on 1,923 cameras over Remote Procedure Call (RPC). The account uses the p2pwn\u002Fp2password username and password pair. “It is stored independently of the admin password and survives a password change and, on most firmware, a factory reset,” Hunt.io says.Advertisement. Scroll to continue reading. For credential brute-forcing, the threat actor used a publicly available asyncio framework. Additionally, they relied on a compiled Go binary for authentication bypass, chaining three vulnerabilities, including the CVE-2021-33044 and CVE-2021-33045 bypasses, and CVE-20244-39943 to deploy the backdoor account. “CVE-2021-33044 exploits unconditional trust in clients identifying as NetKeyboard hardware controllers: when clientType is NetKeyboard, the password field is never evaluated. CVE-2021-33045 exploits the firmware reading the claimed source address from the request body rather than the TCP connection,” Hunt.io says. The bypasses return a full administrator session unauthenticated, and the binary drops the p2pwn \u002F p2password account over RPC. In some instances, the attackers abused Dahua’s cloud relay to reach cameras behind NATs, using only their serial numbers. Hunt.io discovered that the threat actor set up the infrastructure used in the campaign at least one year before the attacks, and that its toolkit contains both their own code and modified code from at least four other developers. “We assess with moderate confidence that the toolkit was built to hand access to a third party, based on the transferable recovery-code design and the enterprise-format export pipeline. That is narrower than a confirmed commercial operation, which the evidence does not support,” Hunt.io says. The report does not establish the operator’s ultimate motivation or intended use of the compromised cameras. Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign Related: Fortune 500 Companies Hit in Azure Data Theft Campaign Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Prevalent AI Raises $22 Million to Expand Data Fabric PlatformUS Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of ThemCISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities943 Patches Rolled Out With Oracle’s August 2026 Security UpdateChrome, Firefox Updates Patch Dozens of VulnerabilitiesXpander Raises $7.5 Million for AI Management and Governance300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin FlawHeights Finance Data Breach Impacts at Least 1.2 Million Individuals Latest News Atlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesMLflow Vulnerability Exploited for Cloud Credential TheftCisco Patches Critical Crosswork, Secure Workload VulnerabilitiesAI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCritical GitLab Flaw Exploited Shortly After DisclosureHackers Using AI to Target Siemens PLCs in Critical US Sectors Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDali Rajic is joining OpenAI as Chief Revenue Officer.Erika Dean has been appointed Chief Information Security Officer at Tricentis.C1 has named Jeff St. Clair Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fthreat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Fcamera.webp","2026-08-20T13:16:35+00:00","2026-08-20T14:00:11.725312+00:00",8,[18,21],{"name":19,"type":20},"Dahua IP cameras","product",{"name":22,"type":23},"Operation CameraSwarm","campaign","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":24,"icon":26,"name":27,"slug":28},null,"Threat Intelligence","threat-intelligence",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},[43,47],{"type":44,"value":45,"context":46},"cve","CVE-2021-33044","Vulnerability used for authentication bypass",{"type":44,"value":48,"context":46},"CVE-2021-33045"]