Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek .
AI Analysis
Technical Summary
A threat actor conducted Operation CameraSwarm, compromising over 14,530 Dahua IP cameras between June 17 and July 22, 2026, focusing on Russian and CIS telecom netblocks. The attacker used a brute-force engine targeting 12,324 unique IP addresses and deployed a persistent backdoor account (username/password: p2pwn/p2password) via Remote Procedure Call (RPC). This backdoor account is independent of the admin password and survives password changes and factory resets on most firmware versions. The attacker chained three vulnerabilities, including CVE-2021-33044 and CVE-2021-33045, to bypass authentication and gain full administrator sessions without credentials. They also exploited Dahua's cloud relay to reach cameras behind NATs using serial numbers. The attack infrastructure was established at least one year prior, and the toolkit includes code from at least four other developers. The report does not specify the attacker’s ultimate goal or use of the compromised devices.
Potential Impact
The compromise of over 14,000 IP cameras allows the threat actor persistent unauthorized access, including a backdoor account that cannot be removed by password changes or factory resets on most affected firmware. This undermines the security and privacy of the affected devices and networks, potentially enabling surveillance, manipulation, or use of the cameras in further attacks. The exploitation of multiple authentication bypass vulnerabilities and abuse of cloud relay services increases the attack surface and reach of the threat actor.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The backdoor account persists through password changes and factory resets on most firmware, so simple credential changes or resets are insufficient. Users should monitor vendor advisories for official patches addressing CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943. Network-level mitigations such as restricting access to camera RPC services and disabling cloud relay features where possible may reduce exposure until patches are available.
Affected Countries
Ukraine, Russia
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Description
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A threat actor conducted Operation CameraSwarm, compromising over 14,530 Dahua IP cameras between June 17 and July 22, 2026, focusing on Russian and CIS telecom netblocks. The attacker used a brute-force engine targeting 12,324 unique IP addresses and deployed a persistent backdoor account (username/password: p2pwn/p2password) via Remote Procedure Call (RPC). This backdoor account is independent of the admin password and survives password changes and factory resets on most firmware versions. The attacker chained three vulnerabilities, including CVE-2021-33044 and CVE-2021-33045, to bypass authentication and gain full administrator sessions without credentials. They also exploited Dahua's cloud relay to reach cameras behind NATs using serial numbers. The attack infrastructure was established at least one year prior, and the toolkit includes code from at least four other developers. The report does not specify the attacker’s ultimate goal or use of the compromised devices.
Potential Impact
The compromise of over 14,000 IP cameras allows the threat actor persistent unauthorized access, including a backdoor account that cannot be removed by password changes or factory resets on most affected firmware. This undermines the security and privacy of the affected devices and networks, potentially enabling surveillance, manipulation, or use of the cameras in further attacks. The exploitation of multiple authentication bypass vulnerabilities and abuse of cloud relay services increases the attack surface and reach of the threat actor.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The backdoor account persists through password changes and factory resets on most firmware, so simple credential changes or resets are insufficient. Users should monitor vendor advisories for official patches addressing CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943. Network-level mitigations such as restricting access to camera RPC services and disabling cloud relay features where possible may reduce exposure until patches are available.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/","fetched":true,"fetchedAt":"2026-08-20T13:22:12.182Z","wordCount":1121}
Threat ID: 6a86ff84acd9273b49a96b1e
Added to database: 08/20/2026, 13:22:12 UTC
Last enriched: 08/20/2026, 13:22:30 UTC
Last updated: 08/20/2026, 22:59:25 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.