Hackers compromise 14,500 Dahua web cameras in 35-day campaign
The CameraSwarm campaign compromised over 14,500 Dahua IP cameras primarily in Ukraine and Russia over a 35-day period by exploiting vulnerabilities, brute-forcing logins, and abusing recovery codes. The attackers installed persistent backdoor accounts that survive password changes and factory resets on many firmware versions. The campaign used three parallel attack methods including scanning TCP port 37777, exploiting CVE-2021-33044 and CVE-2021-33045, and a cloud-relay attack leveraging serial numbers and embedded SDK credentials. Dahua has released firmware updates addressing the exploited CVEs, and users are advised to check for and remove the backdoor account and disable P2P if not needed. Recovery codes remain valid until Dahua changes the server-side derivation mechanism.
AI Analysis
Technical Summary
Researchers discovered a large-scale campaign named CameraSwarm that compromised 14,530 Dahua IP cameras mostly in Ukraine and Russia between June 17 and July 22, 2026. The attackers used three main methods: brute forcing TCP port 37777 to access 12,324 devices, exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities to install a persistent backdoor account on 1,923 cameras, and a cloud-relay attack targeting 283 cameras behind NAT using serial numbers and embedded SDK credentials. The backdoor account (p2pwn) persists through password changes and factory resets on most firmware versions. The attackers also abused Dahua's password recovery process by generating recovery codes from camera serial numbers, allowing access without knowing the current admin password. Hunt.io notified Dahua and national CERTs on August 10, 2026. Dahua recommends applying firmware updates addressing CVE-2021-33044 and CVE-2021-33045 and disabling P2P if not needed. Removing the backdoor account does not invalidate recovery codes, which remain usable until Dahua modifies the server-side mechanism.
Potential Impact
The campaign resulted in unauthorized access to over 14,500 Dahua IP cameras, enabling attackers to capture camera snapshots and maintain persistent backdoor access on many devices. The backdoor account survives password changes and factory resets, increasing the difficulty of remediation. The abuse of the password recovery mechanism allows attackers to regain access without the current admin password. This compromises the confidentiality and integrity of the affected cameras and potentially any data or environments they monitor. The attack focused mainly on devices in Ukraine and Russia but involved global scanning. The persistence and multiple attack vectors increase the risk of long-term unauthorized surveillance and control.
Mitigation Recommendations
Dahua has released firmware updates addressing CVE-2021-33044 and CVE-2021-33045 vulnerabilities; applying these updates or later versions is strongly recommended. Users should check their devices for the presence of the 'p2pwn' backdoor account and remove it if found. Disabling P2P functionality when not required can reduce exposure. Note that removing the backdoor account does not invalidate recovery codes generated by the attack toolkit; these remain valid until Dahua changes the server-side recovery code derivation mechanism. Owners of Dahua cameras reachable via TCP port 37777 during the campaign period should treat them as potentially compromised and take appropriate remediation steps.
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
Description
The CameraSwarm campaign compromised over 14,500 Dahua IP cameras primarily in Ukraine and Russia over a 35-day period by exploiting vulnerabilities, brute-forcing logins, and abusing recovery codes. The attackers installed persistent backdoor accounts that survive password changes and factory resets on many firmware versions. The campaign used three parallel attack methods including scanning TCP port 37777, exploiting CVE-2021-33044 and CVE-2021-33045, and a cloud-relay attack leveraging serial numbers and embedded SDK credentials. Dahua has released firmware updates addressing the exploited CVEs, and users are advised to check for and remove the backdoor account and disable P2P if not needed. Recovery codes remain valid until Dahua changes the server-side derivation mechanism.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers discovered a large-scale campaign named CameraSwarm that compromised 14,530 Dahua IP cameras mostly in Ukraine and Russia between June 17 and July 22, 2026. The attackers used three main methods: brute forcing TCP port 37777 to access 12,324 devices, exploiting CVE-2021-33044 and CVE-2021-33045 vulnerabilities to install a persistent backdoor account on 1,923 cameras, and a cloud-relay attack targeting 283 cameras behind NAT using serial numbers and embedded SDK credentials. The backdoor account (p2pwn) persists through password changes and factory resets on most firmware versions. The attackers also abused Dahua's password recovery process by generating recovery codes from camera serial numbers, allowing access without knowing the current admin password. Hunt.io notified Dahua and national CERTs on August 10, 2026. Dahua recommends applying firmware updates addressing CVE-2021-33044 and CVE-2021-33045 and disabling P2P if not needed. Removing the backdoor account does not invalidate recovery codes, which remain usable until Dahua modifies the server-side mechanism.
Potential Impact
The campaign resulted in unauthorized access to over 14,500 Dahua IP cameras, enabling attackers to capture camera snapshots and maintain persistent backdoor access on many devices. The backdoor account survives password changes and factory resets, increasing the difficulty of remediation. The abuse of the password recovery mechanism allows attackers to regain access without the current admin password. This compromises the confidentiality and integrity of the affected cameras and potentially any data or environments they monitor. The attack focused mainly on devices in Ukraine and Russia but involved global scanning. The persistence and multiple attack vectors increase the risk of long-term unauthorized surveillance and control.
Defensive Guidance
Dahua has released firmware updates addressing CVE-2021-33044 and CVE-2021-33045 vulnerabilities; applying these updates or later versions is strongly recommended. Users should check their devices for the presence of the 'p2pwn' backdoor account and remove it if found. Disabling P2P functionality when not required can reduce exposure. Note that removing the backdoor account does not invalidate recovery codes generated by the attack toolkit; these remain valid until Dahua changes the server-side recovery code derivation mechanism. Owners of Dahua cameras reachable via TCP port 37777 during the campaign period should treat them as potentially compromised and take appropriate remediation steps.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/","fetched":true,"fetchedAt":"2026-08-19T18:22:12.504Z","wordCount":766}
Threat ID: 6a85f455acd9273b49722b9f
Added to database: 08/19/2026, 18:22:13 UTC
Last enriched: 08/19/2026, 18:22:25 UTC
Last updated: 08/19/2026, 22:30:20 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.