A threat actor carried out Operation CameraSwarm, compromising more than 14,000 Dahua IP cameras across Ukraine and Russia by combining brute-force attacks with authentication bypasses and a persistent RPC backdoor. Hunt.io found exposed attacker infrastructure and evidence that the toolkit was prepared for reuse or handoff, but the operator’s final motive remains unclear. #Dahua #OperationCameraSwarm #CVE-2021-33044 #CVE-2021-33045 #CVE-2024-39943 #Hunt.io
Keypoints
- Operation CameraSwarm targeted Dahua IP cameras between June 17 and July 22.
- More than 14,530 devices were compromised across Ukraine, Russia, and other ISP ranges.
- The attackers used brute force and an asyncio-based framework to attack 12,324 unique addresses.
- A persistent p2pwn/p2password backdoor account was deployed on 1,923 cameras via RPC.
- The campaign used authentication bypasses tied to CVE-2021-33044, CVE-2021-33045, and CVE-2024-39943.
Read More: https://www.securityweek.com/threat-actor-hacks-14000-ip-cameras-in-ukraine-and-russia/