Exploits

Operation CameraSwarm Compromises 14,530 Dahua Devices

Published  ·  5 min read

Dahua Devices

The security researchers have uncovered that there has been a huge hacking attack on Dahua cameras and recorders. From June 17 through July 22, 2026, attackers broke into more than 14,530 devices. They used a mix of stolen passwords, old security holes, and a clever relay trick to get in.

The campaign is called Operation CameraSwarm. Hunt.io, the security firm that found it, was able to piece together what happened because the attackers left their working files exposed. The folder contained 407 MB of data; logs, tools, and campaign records that showed the whole operation. Most of the compromised devices were in Ukraine and Russia.

If you have a Dahua camera or NVR sitting on your network, this is something you need to pay attention to.

What Actually Happened?

The attackers used three primary methods to break into Dahua’s devices:

1. Guessing Passwords

To try and gain access, they used either weak or compromised credentials. This was effective for 12,324 unique IP addresses.

2. Exploitation of Exploits for Old Security Vulnerabilities

There were two old security vulnerabilities exploited, CVE-2021-33044 and CVE-2021-33045, that allowed an attacker to exploit vulnerable devices in order to authenticate themselves in 1,923 camera devices. The security vulnerability was discovered in 2021, yet remains unpatched on many devices.

3. P2P Relay Trick

This is the clever one. The attackers used a peer-to-peer relay to reach 283 devices, even when those devices were hidden behind firewalls.

The Two Vulnerabilities They Exploited

Both of the flaws the attackers used are old but still effective.

CVE-2021-33044:

This one lets attackers bypass authentication by sending a specially crafted packet. Imagine that you have the key to open all locks.

CVE-2021-33045

It causes the camera to think the request is coming from the inside of the network. It uses a loopback address -127.0.0.1- to fool the device.

What Dahua Said:
"Attackers can bypass device identity authentication by constructing malicious data packets."

What CISA Says:
Both vulnerabilities are on CISA's Known Exploited Vulnerabilities list. That means the U.S. government considers them a serious risk.

The P2P Relay Trick

This is the part that's really interesting. The P2P relay is a separate technique from the two authentication bypasses.

Here's how it works:

  • Attacker obtains a legitimate Dahua serial number
  • It is then used to establish the relay via Easy4IPCloud
  • Targeted device is now accessible via the vendor's network infrastructure

Why It Works:

The relaying pathway is created prior to the device authenticating. That means that even if the device is locked down, the attack can still be successful.

The p2pwn Tool:

There's a public tool called p2pwn that does exactly this. It accepts a Dahua serial number and checks for the two vulnerabilities.

What ITRES Labs Found:

Researchers at ITRES Labs discovered this technique earlier. They found that the P2P relay worked on firmware released before mid-2024. Newer firmware seems to have fixed the issue.

The Scale of the Operation

Operation CameraSwarm was a big operation:

Metric

Number

Total compromised devices

14,530+

IPs hit with credential attacks

12,324

Cameras bypassed with CVEs

1,923

Devices reached via P2P

283

Persistent accounts created

1,923


The Geography:

Most of the compromised devices were in Ukraine and Russia.

The Operator:

The researchers believe the operator is Russian-speaking, based on language artifacts found in the exposed files. They haven't attributed the campaign to any specific group or government.

What the Exposed Data Revealed

The attackers made a big mistake. They left their working directory exposed. Hunt.io found:

  • 407 MB of data
  • 2,616 files across 234 subdirectories
  • Tooling, logs, shell history, and campaign records

The 89.4% Figure:

The operator's code recorded that 89.4% of live serial numbers returned an open channel without authentication. That's a campaign-specific claim and hasn't been independently verified.

What You Should Do

If you have Dahua devices on your network, here's what you need to do:

1. Update the Firmware

Visit the website of the vendor and get the latest firmware. Install it now.

2. Turn Off P2P

If you don't need P2P, turn it off. It's a potential backdoor.

3. Password Change

Don’t use weak or default passwords. Get yourself a unique one.

4. Check for Unauthorized Accounts

Look for accounts you didn't create. The attackers created persistent accounts on 1,923 devices.

5. Isolate Surveillance Systems

Put your cameras and NVRs on a separate network segment. Don't leave them exposed to the internet.

Wrapping It Up

Operation CameraSwarm is a serious reminder that IoT devices are often the weakest link in network security. Attackers are actively scanning for vulnerable cameras.

Remember the following points:

  • There have been 14,530+ Dahua exploits
  • The exploit uses credential attacks, authentication bypasses, and P2P relay
  • The victims are mostly from Ukraine and Russia
  • Ensure you update the firmware and disable P2P

If you own a Dahua device, don't wait. Patch it now. Check for unauthorized accounts. And think twice about leaving your cameras exposed to the internet.

FAQ Section

What is Operation CameraSwarm?

This is a campaign where more than 14,530 Dahua devices were affected between June 17 and July 22, 2026.

What were the exploited vulnerabilities?

There were two exploited vulnerabilities. CVE-2021-33044 and CVE-2021-33045. They're authentication-bypass flaws.

What is P2P Relay Attack?

It involves using a valid Dahua serial number for creating a relay path to allow communication through NAT.

How many devices were compromised?

More than 14,530. 1,923 devices using cameras had persisting accounts. 283 were accessed through the use of P2P.

What should the Dahua device users do?

Firmware update, disabling P2P, strong passwords, deleting unnecessary accounts, and segmentation of surveillance networks.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067