you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / security
02 September 2026 security 5 min read

CameraSwarm: one operator hijacked 14,530 Dahua cameras with a five-year-old bug

Between June 17 and July 22, 2026, a lone operator running under the banner researchers later dubbed CameraSwarm quietly took control of at least 14,530 Dahua IP cameras. Most confirmed victims sit in Ukraine and Russia, with Ukraine holding the largest share, though the scanning itself was global — masscan sweeps hit Russian address space first and then chewed through the entire IPv4 range before the operator settled on Russian and CIS telecom netblocks.

The campaign might still be running if its author had practiced basic operational security. Analysts at Hunt.io found a working directory on one of the operator's own HTTP servers left wide open, and pulled 407 MB of data from it: 2,616 files across 234 directories containing source code, logs, stolen credentials, captured camera snapshots, shell history and exploitation results. In effect, the attacker handed researchers a complete map of his own operation. For a scene that lectures everyone else about opsec, it is a familiar irony — the same loose metadata that dooms marketplace admins keeps dooming malware operators too.

Three attack paths running in parallel

What makes CameraSwarm notable is not a novel exploit but industrialized breadth. The recovered tooling shows three compromise methods running side by side. First, a brute-forcing system scanned TCP port 37777 — Dahua's proprietary service port — and cracked logins on 12,324 unique IP addresses, grabbing usable snapshots and shipping results to Telegram for export into Dahua's SMART PSS management platform. Second, the operator weaponized the legacy authentication bypass pair CVE-2021-33044 and CVE-2021-33045 to plant a persistent backdoor account named 'p2pwn' on 1,923 cameras. On most firmware versions this account survives password changes and even factory resets, meaning victims who noticed the intrusion and wiped their devices may have handed control right back to the attacker. Third, a cloud-relay technique targeted 283 cameras hidden behind NAT by abusing Dahua's P2P infrastructure: using device serial numbers and embedded SDK credentials, the toolkit generated offline password recovery codes and walked straight through the vendor's own cloud. Worryingly, Hunt.io notes those recovery codes remain usable until Dahua changes the derivation mechanism server-side — deleting the backdoor user alone does not lock the attacker out.

A five-year-old wound that never closed

The core vulnerabilities here should be ancient history. CVE-2021-33044 and CVE-2021-33045 were disclosed in 2021, shipped with vendor fixes at the time, and added to CISA's Known Exploited Vulnerabilities catalog in August 2024 after a multinational advisory tied them to Russian military Unit 29155 operations against IP cameras. Public proof-of-concept code has circulated for years. Yet in mid-2026, tens of thousands of fielded Dahua devices — many built before the fix existed — remain reachable, unpatched, and trivially exploitable. The CameraSwarm operator did not need a zero-day; he needed patience and a scanner. Hunt.io notified national CERTs and Dahua's PSIRT on August 10, holding publication until August 18 under TLP:AMBER. Full technical reporting is available directly from Hunt.io, with additional English-language coverage from BleepingComputer and The Hacker News. Polish and Russian readers can find detailed write-ups at Niebezpiecznik and Xakep respectively.

Where hijacked CCTV fleets end up

The Tor audience angle deserves blunt language. A hijacked camera fleet is not just a privacy scandal for the camera owners — it is inventory. Compromised devices on residential and telecom connections are exactly what proxy and botnet resale markets stock: eyeballs-on-the-street IPs that pass fraud checks, look domestic to geo-filters, and rent out by the thousand on underground forums. Camera snapshots harvested during compromise feed a separate surveillance-for-sale ecosystem, where access to private premises is packaged and sold to whoever pays. Every unpatched Dahua on a CIS telecom netblock is potential stock for those listings, and operations like CameraSwarm show how cheaply that stock can be manufactured by one person in five weeks. It also illustrates why reputation-based trust fails on both sides of the fence. Buyers in those markets assume they are renting clean residential exits; sellers assume their own infrastructure is private. CameraSwarm broke both assumptions at once, and the attacker lost his anonymity not to law enforcement but to a misconfigured directory listing.

If you operate Dahua hardware

Owners of any camera that answered on TCP port 37777 between June and July 2026 should treat it as potentially compromised. Check the user list for a 'p2pwn' account and remove it, disable P2P/Easy4ip unless genuinely needed, apply firmware addressing CVE-2021-33044 and CVE-2021-33045 or newer, and remember that removing the backdoor does not invalidate already-generated recovery codes — escalate to Dahua if serial-number-based recovery was possible on your devices. Segment cameras away from the rest of the network and never expose management ports to the internet. The broader lesson applies well beyond CCTV: infrastructure you depend on degrades silently while vendors and owners assume someone else patched it. Whether you run cameras or onion services, verify rather than assume — our onion status checker exists precisely because uptime claims and reality drift apart. CameraSwarm will not be the last campaign to prove it.

more notes

all news ›