CameraSwarm Campaign Compromises 14,530 Dahua IP Cameras
Cybersecurity researchers have uncovered a large-scale hacking campaign, dubbed CameraSwarm, that compromised more than 14,500 Dahua IP cameras, primarily in Ukraine and Russia.
The campaign lasted at least 35 days, from June 17 through July 22. Attackers gained access to Dahua cameras through a combination of software vulnerabilities, brute-force attacks, and offline recovery codes generated from camera serial numbers registered with Dahua’s cloud services.
Threat intelligence firm Hunt.io discovered the operation after finding unprotected working directories on HTTP servers used by the attackers.
Hunt.io researchers analyzed 407 MB of data containing 2,616 files across 234 directories. The material included source code, attack logs, credentials, captured camera images, shell history, and exploit results, providing insight into the scale and methods of the operation.

Source: Hunt.io
According to Hunt.io, the 35-day CameraSwarm operation compromised 14,530 Dahua IP cameras using three attack methods running in parallel:
- Brute-force attacks: An automated system scanned TCP port 37777 and compromised devices at 12,324 unique IP addresses. The attackers captured snapshots from accessible cameras, sent the images to Telegram, and exported camera data for use with Dahua’s SMART PSS platform.
- Exploitation of Dahua vulnerabilities: The attackers used the CVE-2021-33044 and CVE-2021-33045 vulnerabilities through a tool called p2pwn. The tool created persistent backdoor accounts named p2pwn and p2password on 1,923 cameras. These accounts can survive password changes and, on most firmware versions, remain active after a factory reset.
- Cloud relay attacks: This technique accessed 283 cameras behind network address translation (NAT) using only serial numbers and SDK credentials embedded in the Dahua application. Hunt.io found that 89.4% of active serial numbers exposed access channels without authentication.
The attack toolkit also included a recovery-code generation mechanism based on a camera’s serial number. This allowed the CameraSwarm operators to request new codes through Dahua’s standard password recovery process without knowing the camera’s current administrator password.
Researchers identified two additional vulnerability references in the toolkit—CVE-2024-39943 and CVE-2025-31702—but found no evidence that either vulnerability was used in the observed attacks.

Source: Hunt.io
Hunt.io’s analysis showed that the scanning activity was global. The attackers initially focused on Russian address space before expanding their scans across the entire IPv4 range. Researchers said the operators appeared to concentrate on telecommunications and communications network blocks in Russia and other Commonwealth of Independent States (CIS) countries.
The modified code also contained Russian-language comments, although the attackers appeared to have reused publicly available tools as part of their operation.
On August 10, Hunt.io notified national computer emergency response teams (CERTs) and Dahua’s Product Security Incident Response Team (PSIRT) about the CameraSwarm campaign.
Dahua cameras exposed to the internet through TCP port 37777 between June and July should be considered potentially compromised. Device owners should check for unauthorized p2pwn accounts and remove them immediately.
However, Hunt.io warns that deleting the backdoor account does not invalidate recovery codes generated by the attack toolkit. Those codes may remain usable until Dahua makes changes to the server-side recovery-code system.
Organizations should also disable Dahua’s P2P functionality when it is not required and install the firmware update listed in Dahua SA-2021-0130, which addresses CVE-2021-33044 and CVE-2021-33045. Updating to a later supported firmware version is also recommended.
Traditional prevention scores may not show what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of security defenses can drop significantly.
Blue Report 2026 measures defense techniques by technology across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




