Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
A threat actor known for Operation CameraSwarm has compromised over 14,000 Dahua IP cameras across Ukraine and Russia between mid-June and late July. The attacker leveraged a brute-force engine alongside authentication bypass techniques involving CVE-2021-33044, CVE-2021-33045, and CVE-20244-39943 to gain unauthorized administrative access. This exploit chain allowed the deployment of a persistent backdoor account using the credentials p2pwn/p2password via RPC, which remains effective even after password changes or factory resets on many firmware versions.
Hunt.io discovered that the operator had prepared this infrastructure long in advance and utilized a toolkit combining proprietary code with modified scripts from other developers. While the specific motivation behind the mass compromise is unclear, the presence of enterprise-format export tools suggests the data may have been intended for transfer to a third party.