Ethical Hacking News
Operation CameraSwarm, a highly sophisticated cyberattack, compromised over 14,000 Dahua cameras across Ukraine and Russia, exposing them without authentication. The attack highlights the vulnerability of IoT devices to cyberattacks and underscores the need for robust security measures and vendor responsibility in addressing vulnerabilities.
Over 14,000 Dahua cameras compromised in a cyberattack known as Operation CameraSwarm.A brute-force engine identified vulnerabilities in the cameras, exploiting them without authentication.An authentication-bypass chain was used to plant a persistent backdoor account on 1,923 cameras.A third path reached 283 cameras by serial number, without IP address checks.A recovery-code generator unlocked Dahua's cloud account-recovery flow without credentials.The attack highlights the vulnerability of IoT devices to cyberattacks and the need for regular patching and secure credentials.
A recent discovery has shed light on the devastating consequences of a highly sophisticated cyberattack known as Operation CameraSwarm. The operation, which took place between June 17 and July 22, 2026, saw one actor successfully compromise over 14,000 Dahua cameras across Ukraine and Russia. The attack, which was made possible by a combination of brute-force engines, authentication-bypass chains, and the exploitation of a cloud-based relay service, exposed the cameras without requiring any authentication.
At the heart of the operation was a brute-force engine that utilized a scanning process to identify and exploit vulnerabilities in the Dahua cameras. The engine alone reached over 12,300 unique addresses, with the majority of these being Dahua cameras that were exposed online without authentication. The brute-force engine's success was largely due to its ability to operate at scale, with the attacker's own code logs indicating that 89.4% of live serials returned an open, no-authentication channel.
In addition to the brute-force engine, the attacker also employed an authentication-bypass chain that utilized two 2021 Dahua vulnerabilities to plant a persistent backdoor account on 1,923 cameras. The backdoor account, which was stored independently of the admin password, survived both a password change and, on most firmware, a factory reset. The authentication-bypass chain's success was due to its ability to bypass the authentication process, allowing the attacker to gain access to the cameras without needing valid credentials.
The third path of the operation, which skipped IP addresses entirely, reached 283 cameras purely by serial number, through Dahua's own cloud relay. This path was particularly concerning, as most of the cameras were exposed online without authentication, and the attacker's own code logs indicated that 9 out of 10 cameras were reachable by anyone who could guess or harvest a serial number.
The attacker's toolkit, which was assembled from public repositories and credited to at least six other developers, also included a recovery-code generator that could unlock Dahua's cloud-level account-recovery flow without needing any current credentials. This recovery-code generator, which derived its decryption key entirely from values the attacker already held, device class prefix, and serial number, was arguably the most consequential piece of the toolkit.
The operation's implications are far-reaching, with the compromise of 14,000 Dahua cameras highlighting the vulnerability of IoT devices to cyberattacks. The attack also highlights the need for organizations to regularly patch their firmware, disable P2P on devices where it's not needed, and rotate credentials that cameras ever held. Ultimately, the success of Operation CameraSwarm serves as a reminder of the importance of robust security measures and the need for vendors to take responsibility for addressing vulnerabilities in their products.
Related Information:
https://www.ethicalhackingnews.com/articles/Operation-CameraSwarm-A-Masterclass-in-Exploiting-14000-Dahua-Cameras-ehn.shtml
https://securityaffairs.com/197527/iot/inside-operation-cameraswarm-how-one-actor-took-over-14000-dahua-cameras.html
Published: Wed Aug 19 13:53:52 2026 by llama3.2 3B Q4_K_M