An Unsecured Server Exposed a 35-Day Campaign That Hijacked 14,530 Dahua Cameras
Cybersecurity

An Unsecured Server Exposed a 35-Day Campaign That Hijacked 14,530 Dahua Cameras

Researchers at Hunt.io found an unsecured operator server that laid bare Operation CameraSwarm, a 35-day campaign between June and July 2026 that compromised more than 14,530 Dahua surveillance cameras using decade-old vulnerabilities and brute-force credential attacks.

PublishedSeptember 7, 2026
Read time5 min read
Share

Fourteen Thousand Cameras, Three Ways In

Between June 17 and July 22, 2026, an operator ran a 35-day campaign that Hunt.io researchers dubbed Operation CameraSwarm, compromising at least 14,530 Dahua IP cameras and surveillance devices. The campaign did not rely on a single clever exploit. It ran three concurrent attack methods against the same target population: brute-force credential attacks against 12,324 unique IP addresses exposing TCP port 37777, exploitation of two authentication-bypass vulnerabilities from 2021, CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua's own peer-to-peer cloud relay feature to reach 283 additional cameras sitting behind network address translation.

That third method is the one worth pausing on. Dahua's peer-to-peer relay exists as a convenience feature, letting users view camera feeds remotely without configuring port forwarding or a VPN. The operator turned that same convenience feature into a way past the network isolation NAT normally provides, reaching cameras that their owners likely assumed were protected simply by not being directly internet-facing. Convenience features that bypass network topology for legitimate users bypass it for attackers too.

Old Vulnerabilities, Fully Functional in 2026

CVE-2021-33044 and CVE-2021-33045 are not new. They are five-year-old authentication-bypass flaws, patched by Dahua years ago, and their continued usefulness to attackers in mid-2026 is a direct measurement of how slowly IP camera fleets get patched in the field. Unlike a server or a laptop, an IP camera bolted to a warehouse ceiling or a store entrance rarely gets touched again after installation unless it physically fails. Firmware updates require someone to remember the device exists, find its management interface, and push an update that risks temporary downtime for a device nobody wants to be the one who broke.

Hunt.io's researchers noted that 89.4% of live serial numbers they tested returned an open channel without authentication, a figure the researchers themselves caveat as specific to this campaign's dataset rather than a verified industry-wide statistic. Even treated as directional rather than definitive, it points to a fleet-wide pattern of default or absent credentials that brute-force attacks and five-year-old CVEs can still exploit at scale, which is exactly what made a 14,530-camera campaign possible with unsophisticated, publicly known techniques.

What the Attacker's Own Mistake Revealed

The campaign came to light because the operator made the same mistake so many of their victims did: they left their own infrastructure unsecured. Hunt.io found an exposed operator server containing attack tooling, operation logs, stolen credentials, shell history, captured camera images, and detailed campaign records. That level of operational exposure handed researchers a rare, comprehensive look at exactly how the campaign worked rather than having to reconstruct it from victim-side forensics alone.

The operator installed persistent backdoor access on 1,923 of the compromised devices using a hardcoded username, p2pwn, paired with a password, and automatically posted each newly compromised device's credentials to a Telegram channel as it was captured. That automation suggests either a botnet-building operation renting out access to compromised camera feeds, or reconnaissance infrastructure being assembled for a later purpose Hunt.io's researchers could not fully determine from the exposed server alone.

Why IoT Fleets Keep Failing the Same Way

IP cameras share a set of structural weaknesses that make campaigns like this predictable rather than surprising. They ship with default credentials that installers often never change, they run firmware that manufacturers stop updating years before the hardware is retired, and they are frequently deployed by contractors who hand over a working system and never touch it again. None of that is unique to Dahua. It describes the IP camera, badge reader, and building-automation device market broadly, which is why campaigns targeting these device classes keep succeeding with techniques that are years old rather than requiring anything novel.

What makes Operation CameraSwarm notable is the scale it reached using only public, patched vulnerabilities and brute-force credential guessing, methods any competent attacker could reproduce without discovering anything new. That should be more alarming to defenders than a campaign built on a fresh zero-day, because it means the barrier to running a similar operation against any other under-patched camera fleet is close to zero. The real vulnerability here is organizational: nobody owns the job of keeping these devices current long after a contractor finishes the installation.

The Patch Cadence Decision for Physical Security Infrastructure

Retail, warehouse, and facilities operations teams tend to treat IP cameras as physical security equipment rather than networked computers, which means they often sit outside the vulnerability management program that covers servers, laptops, and cloud infrastructure. Operation CameraSwarm is proof that this separation is a mistake. A compromised camera is a foothold on the internal network, a source of surveillance footage an attacker can review for operational intelligence, and in aggregate, infrastructure for a botnet, all from a device most IT teams never think to patch.

The roadmap decision is straightforward even if the execution is not: bring every internet-connected camera, badge reader, and physical security device into the same asset inventory and patch cadence as everything else on the network, and audit whether any of them still run default or weak credentials five years after the vulnerabilities exploiting them were disclosed. If your organization cannot currently produce a list of every IP camera on its network and its firmware version, Operation CameraSwarm is the reason to build that list this quarter, not after your own cameras show up in a Telegram channel.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#dahua#iot-security#camera-swarm#hunt-io#physical-security-devices