Dahua Devices Compromised

Overview

Cybersecurity researchers at Hunt.io have revealed details of Operation CameraSwarm, a campaign that compromised more than 14,530 Dahua devices between June 17 and July 22, 2026. Attackers leveraged credential attacks, two authentication‑bypass flaws, and a peer‑to‑peer (P2P) relay technique to gain access, with confirmed compromises concentrated in Ukraine and Russia.

Attack Vectors

  • Credential attacks:
    • 12,324 unique IP addresses across 13,229 campaign records.
  • Authentication bypass:
    • 1,923 cameras exploited using CVE‑2021‑33044 and CVE‑2021‑33045.
    • These flaws allow attackers to bypass device identity authentication with malicious packets.
  • P2P relay:
    • 283 cameras identified by serial number, including devices behind NAT.
    • Exploits Dahua’s Easy4IP relay infrastructure to establish tunnels without prior authentication.

Vulnerability Details

  • CVE‑2021‑33044: Triggered by a NetKeyboard client type during authentication.
  • CVE‑2021‑33045: Exploited via a loopback login request using 127.0.0.1.
  • Both flaws remain in CISA’s Known Exploited Vulnerabilities catalog with CVSS scores up to 9.8.
  • Dahua’s advisory confirms patched firmware is available, urging customers to update immediately.

Campaign Findings

  • Persistent accounts: 1,923 cameras configured with accounts that survived factory resets.
  • P2P exposure: Hunt.io claims 89.4% of live serial numbers returned open channels without authentication.
  • Recovered toolkit: Language artifacts suggest a Russian‑speaking operator, though attribution to a specific threat group remains unconfirmed.
  • Potential resale: Researchers assessed with moderate confidence that compromised access may have been prepared for third‑party transfer.

Defensive Guidance

Security teams should:

  • Disable P2P unless required.
  • Update firmware from Dahua’s official site.
  • Use strong credentials and remove unused accounts.
  • Segment surveillance systems to limit exposure.
  • Restrict Easy4IP connectivity where appropriate.
  • Monitor for suspicious activity including unexpected relay paths or persistent accounts.

Expert in the Cloud Insight

Operation CameraSwarm underscores how legacy vulnerabilities and insecure protocols can be weaponized at scale. Dahua’s P2P relay, designed for convenience, became a backdoor for attackers when combined with credential brute‑forcing and authentication bypasses. For defenders, the lesson is clear: disable unnecessary features, patch relentlessly, and treat IoT devices as critical infrastructure.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.