LIVE · cybersecurity feed
Live wire
security

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

In a large-scale campaign that researchers dubbed CameraSwarm, hackers compromised more than 14,500 Dahua IP cameras mostly in Ukraine and Russia. [...]

zeroday.news ·

A campaign dubbed "CameraSwarm" compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia, over a 35-day period between June 17 and July 22. Threat intelligence company Hunt.io discovered the operation after finding an unprotected HTTP server containing 407 MB of data, including source code, logs, credentials, and captured camera images.

The attackers employed three distinct methods to compromise devices. The most prevalent method involved a brute-forcing system that scanned TCP port 37777, leading to the compromise of cameras at 12,324 unique IP addresses. This system captured snapshots, sent results to Telegram, and exported them for Dahua's SMART PSS platform.

Another method exploited CVE-2021-33044 and CVE-2021-33045 using a tool called "p2pwn." This resulted in the installation of a persistent backdoor account, also named "p2pwn" with the password "p2password," on 1,923 cameras. This backdoor account is designed to survive password changes and, on most firmware versions, factory resets.

The third attack vector was a cloud-relay attack, which targeted 283 cameras located behind NAT. This method leveraged only serial numbers and SDK credentials embedded in Dahua applications. Data indicated that 89.4% of live serial numbers exposed an access channel without requiring authentication. The attack toolkit's recovery code generation mechanism utilized the camera's serial number, enabling the operator to obtain new codes through Dahua's standard password recovery process without needing the current administrator password.

Hunt.io's analysis revealed that the scanning operations were global, initially focusing on the Russian address space before expanding to the entire IPv4 range. The operator's primary focus, however, appeared to be on Russian and CIS telecom netblocks. Researchers also noted the presence of Russian comments within modified code sections of repurposed public tools.

On August 10, Hunt.io informed national CERTs and Dahua's PSIRT about the CameraSwarm campaign. Dahua cameras accessible via port 37777 during the June-July period should be considered potentially compromised. Owners are advised to check for the "p2pwn" account and remove it.

However, Hunt.io warns that simply removing the backdoor account will not invalidate recovery codes generated by the toolkit, as these codes remain usable until Dahua modifies the derivation process on its servers. Users are also recommended to disable P2P functionality when it is not needed and to apply Dahua SA-2021-0130 firmware updates, or a later version, to address CVE-2021-33044 and CVE-2021-33045. The researchers also found two unexploited CVE references, CVE-2024-39943 and CVE-2025-31702, in the toolkit.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

security

ICE boss to agents: Leave the Meta spy glasses at home

'Personally owned body-worn cameras are prohibited,' ICE tells The Reg. Because the last thing DHS needs is more proof of misconduct

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments.

security

41 deceptive download sites show a real link, then send you somewhere else

A legitimate-looking link or valid digital signature can offer false reassurance. Here’s why familiar download safety checks aren’t always enough.

vulnerabilitycritical

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of known vulnerabilities.

phishing

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.