Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

0
High
Campaign
Published: 08/19/2026 (08/19/2026, 18:09:13 UTC)
Source: Bleeping Computer

Description

The CameraSwarm campaign compromised over 14,500 Dahua IP cameras primarily in Ukraine and Russia over a 35-day period by exploiting vulnerabilities, brute-forcing logins, and abusing recovery codes. The attackers installed persistent backdoor accounts that survive password changes and factory resets on many firmware versions. The campaign used three parallel attack methods including scanning TCP port 37777, exploiting CVE-2021-33044 and CVE-2021-33045, and a cloud-relay attack leveraging serial numbers and embedded SDK credentials. Dahua has released firmware updates addressing the exploited CVEs, and users are advised to check for and remove the backdoor account and disable P2P if not needed. Recovery codes remain valid until Dahua changes the server-side derivation mechanism.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/19/2026, 18:22:25 UTC

Technical Analysis

Researchers discovered a large-scale campaign named CameraSwarm that compromised 14,530 Dahua IP cameras mostly in Ukraine and Russia between June 17 and July 22, 2026. The attackers used three main methods: brute forcing TCP port 37777 to access 12,324 devices, exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities to install a persistent backdoor account on 1,923 cameras, and a cloud-relay attack targeting 283 cameras behind NAT using serial numbers and embedded SDK credentials. The backdoor account (p2pwn) persists through password changes and factory resets on most firmware versions. The attackers also abused Dahua's password recovery process by generating recovery codes from camera serial numbers, allowing access without knowing the current admin password. Hunt.io notified Dahua and national CERTs on August 10, 2026. Dahua recommends applying firmware updates addressing CVE-2021-33044 and CVE-2021-33045 and disabling P2P if not needed. Removing the backdoor account does not invalidate recovery codes, which remain usable until Dahua modifies the server-side mechanism.

Potential Impact

The campaign resulted in unauthorized access to over 14,500 Dahua IP cameras, enabling attackers to capture camera snapshots and maintain persistent backdoor access on many devices. The backdoor account survives password changes and factory resets, increasing the difficulty of remediation. The abuse of the password recovery mechanism allows attackers to regain access without the current admin password. This compromises the confidentiality and integrity of the affected cameras and potentially any data or environments they monitor. The attack focused mainly on devices in Ukraine and Russia but involved global scanning. The persistence and multiple attack vectors increase the risk of long-term unauthorized surveillance and control.

Defensive Guidance

Dahua has released firmware updates addressing CVE-2021-33044 and CVE-2021-33045 vulnerabilities; applying these updates or later versions is strongly recommended. Users should check their devices for the presence of the 'p2pwn' backdoor account and remove it if found. Disabling P2P functionality when not required can reduce exposure. Note that removing the backdoor account does not invalidate recovery codes generated by the attack toolkit; these remain valid until Dahua changes the server-side recovery code derivation mechanism. Owners of Dahua cameras reachable via TCP port 37777 during the campaign period should treat them as potentially compromised and take appropriate remediation steps.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/","fetched":true,"fetchedAt":"2026-08-19T18:22:12.504Z","wordCount":766}

Threat ID: 6a85f455acd9273b49722b9f

Added to database: 08/19/2026, 18:22:13 UTC

Last enriched: 08/19/2026, 18:22:25 UTC

Last updated: 08/19/2026, 22:30:20 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses