Hackers Compromise Over 14,500 Dahua Devices Using P2P and Auth Bypasses
Quick Summary
- Massive IoT Breach:A massive cyberattack campaign, dubbed Operation CameraSwarm, has successfully compromised over 14,530 Dahua security cameras and devices.
- Attack Timeline:The exploitation activity took place between June 17 and July 22, 2026.
- Triple Threat Tactics: Hackers utilized a combination of credential attacks, two authentication-bypass vulnerabilities, and a peer-to-peer (P2P) relay technique to gain control.
- Primary Targets:While initial scanning efforts targeted global IPv4 address ranges, the confirmed compromises were heavily concentrated in Ukraine and Russia.
- Sloppy Tradecraft:Cybersecurity researchers at Hunt.io uncovered the entire campaign because the operator accidentally exposed their own 407 MB working directory containing hacking tools and logs.
Full Story
Cybersecurity researchers at Hunt.io have uncovered a massive, highly coordinated cyberespionage and botnet campaign targeting Dahua IP cameras. Codenamed "Operation CameraSwarm," the attack compromised more than 14,530 Dahua devices worldwide over a five-week period stretching from mid-June to late July 2026. The threat actor achieved this unprecedented scale by launching three parallel exploitation paths: aggressive credential attacks, leveraging two existing authentication-bypass flaws, and exploiting a peer-to-peer (P2P) relay mechanism.
The extensive operation was brought to light not through complex reverse engineering, but due to a critical operational security failure by the attacker. On July 23, 2026, Hunt.io researchers crawled an exposed open HTTP directory operated by the hackers. This massive 407 MB trove contained 2,616 files spread across 234 subdirectories, providing investigators with complete access to the attacker's tooling, shell history, and campaign records. Analysis of this data revealed that the operator conducted global sweeps, with initial masscan activities targeting Russian address space before expanding to global IPv4 ranges. Despite the global scan, the successful compromises heavily concentrated on networks within Ukraine and Russia. As a result of the breaches, the attacker established persistent backdoor access by configuring secondary accounts on 1,923 of the compromised cameras.
Why it Matters
This incident underscores the severe, ongoing vulnerability of critical Internet of Things (IoT) infrastructure. Security cameras are frequently deployed on the perimeters of sensitive government, military, and commercial networks. When an authentication bypass flaw allows remote attackers to circumvent device identity authentication and seize complete control, the cameras can be weaponized for unauthorized surveillance or lateral network infiltration. Furthermore, the discovery that parts of the attacker's toolkit may have been designed to transfer camera access to a third party raises serious concerns about the commercialization of compromised intelligence.
Conclusion
Operation CameraSwarm is a stark reminder that unpatched IoT devices remain prime targets for sophisticated cyber threat actors. While language artifacts recovered from the working directory suggest the operator is Russian-speaking, no specific threat group has been formally attributed to the campaign. Security experts and ITRES Labs urgently recommend that users of Dahua equipment update their firmware immediately and disable P2P functionality unless absolutely required.


0 Comments