CVE Tools
Back to feed
Exploited in the wild Dahua IP Cameras ics-ot-iot Dahua malware

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Threat intelligence firm Hunt.io has identified a 35-day attack campaign dubbed CameraSwarm that compromised over 14,500 Dahua IP cameras, primarily in Ukraine and Russia. The operation utilized a combination of brute-force attacks against TCP port 37777, exploitation of CVE-2021-33044 and CVE-2021-33045 to install persistent backdoors, and unauthorized cloud-relay access via serial numbers. Researchers recovered extensive operational data, including source code and credentials, from an unprotected server directory left open by the attackers. Administrators are advised to check devices for the malicious 'p2pwn' account, apply firmware updates per Dahua SA-2021-0130, and disable P2P services when not in use.