← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Over 14,500 Dahua Devices Compromised via Credential Attacks, Auth Bypasses, and P2P

🔄 Updated 42d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 14,530+ Dahua devices compromised between June 17 and July 22, 2026.
  • Attack methods included credential attacks, CVE-2021-33044, CVE-2021-33045, and P2P relay.
  • Compromises concentrated in Ukraine and Russia.
  • Vulnerabilities CVE-2021-33044 and CVE-2021-33045 are in CISA's KEV catalog.
  • The campaign was dubbed CameraSwarm.
  • Hunt.io discovered the campaign.
  • Hunt.io recovered 407 MB of data from an unprotected HTTP server.
  • Brute-forcing system scanned TCP port 37777.
  • Threat actor deployed a persistent backdoor account on 1,923 cameras.
  • The backdoor account uses the username and password pair p2pwn/p2password.
  • The backdoor account survives password changes and factory resets on most firmware.
  • The campaign initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges.
  • The campaign later focused on Russian and CIS telecom netblocks.
  • Hunt.io found 2,616 files across 234 subdirectories on the threat actor's servers.
  • The brute-force engine targeted 12,324 unique addresses.

Operation CameraSwarm Details

Cybersecurity researchers at Hunt.io identified a campaign, dubbed "Operation CameraSwarm," that compromised more than 14,530 Dahua devices. The activity occurred between June 17 and July 22, 2026, and was reconstructed from an exposed 407 MB working directory containing tooling, logs, and campaign records. Confirmed compromises were primarily located in Ukraine and Russia.

Attack Vectors Used

The attackers utilized three primary methods to gain access to the Dahua devices. Credential attacks accounted for 12,324 unique IP addresses. Authentication bypass flaws, specifically CVE-2021-33044 and CVE-2021-33045, were used to compromise 1,923 cameras, which were also configured with a persistent account. Additionally, 283 cameras were accessed via a peer-to-peer (P2P) relay technique, including devices behind Network Address Translation (NAT).

Vulnerability Background

CVE-2021-33044 and CVE-2021-33045 are authentication-bypass vulnerabilities affecting Dahua cameras and related products. Dahua's advisory rates these flaws at 8.1 on the CVSS scoring system, while the U.S. National Vulnerability Database (NVD) assigns them a CVSS score of 9.8. These vulnerabilities allow attackers to bypass device identity authentication by constructing malicious data packets. Both flaws remain listed in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog as of August 19, 2026.

Recommendations for Users

Users of affected Dahua products are advised to install the corresponding fix software or newer firmware provided by the vendor. ITRES Labs also recommends disabling P2P functionality when it is not required and regularly checking firmware against the vendor's download site to ensure devices are up to date and secured against known vulnerabilities.

Updates

🕒 2026-08-20 · new reporting from SecurityWeek
  • Threat actor deployed a persistent backdoor account on 1,923 cameras.
  • The backdoor account uses the username and password pair p2pwn/p2password.
  • The backdoor account survives password changes and factory resets on most firmware.
  • The campaign initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges.
  • The campaign later focused on Russian and CIS telecom netblocks.
  • Hunt.io found 2,616 files across 234 subdirectories on the threat actor's servers.
  • The brute-force engine targeted 12,324 unique addresses.
🕒 2026-08-19 · new reporting from BleepingComputer
  • The campaign was dubbed CameraSwarm.
  • Hunt.io discovered the campaign.
  • Hunt.io recovered 407 MB of data from an unprotected HTTP server.
  • Brute-forcing system scanned TCP port 37777.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A threat actor compromised over 14,000 Dahua IP cameras in Ukraine and Russia between June 17 and July 22, deploying a persistent backdoor account. This campaign highlights the vulnerability of IoT devices to brute-force attacks and the exploitation of known firmware flaws, posing significant privacy and security risks for affected users.

A 35-day campaign, dubbed CameraSwarm, compromised more than 14,500 Dahua IP cameras, primarily in Ukraine and Russia, using a combination of brute-forcing, vulnerability exploits, and cloud-relay attacks. This incident highlights significant security vulnerabilities in widely used surveillance equipment and the potential for widespread unauthorized access to camera feeds and device control.

Cybersecurity researchers at Hunt.io uncovered "Operation CameraSwarm," which compromised over 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws (CVE-2021-33044 and CVE-2021-33045), and a P2P relay technique. This compromise highlights the ongoing risk posed by unpatched vulnerabilities and weak credentials in IoT devices, particularly in critical infrastructure or surveillance contexts.