Researchers at Hunt.io uncovered two exposed directories that revealed parallel intrusion operations targeting internet-exposed infrastructure in Ukraine, particularly IP cameras and routers. One server at 89.208.97[.]165 contained evidence that a Ukrainian OpenCart-based e-commerce site had been compromised through SQL injection and repurposed as a proxy and staging node for Tor-routed intrusion attempts against Ukrainian government and military websites. The same server hosted a custom camera exploitation platform, camview, whose recovered data showed 58 compromised Ukrainian cameras, logs of live viewing sessions, and use of the open-source Ingram scanner against Dahua, Hikvision, D-Link, and Reolink devices.
A second exposed directory at 213.165.63[.]49 showed a separate but similar operation using Russian-language tooling, Ingram, and custom scripts to scan and exploit routers and cameras across 15 European countries, with camera targeting concentrated on Ukraine. The toolkit focused on converting compromised TP-Link, MikroTik, and camera devices into SOCKS5 proxies and reverse tunnels over port 4444, relying on stolen access, weak credentials, and known vulnerabilities, including CVE-2021-33044. Hunt.io said the activity was not attributed to a named threat actor or state entity, but the exposed infrastructure pointed to a low-cost, repeatable campaign aimed at Ukrainian targets using publicly available tools and long-patched flaws.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Hunt.io published research describing two exposed directories that revealed separate but similar operations targeting Ukrainian cameras, routers, and websites using stolen access, weak credentials, and known vulnerabilities. The report documented a compromised Ukrainian OpenCart site used as a proxy and staging point, plus camview data showing 58 compromised Ukrainian cameras and live viewing logs.
Hunt.io notified CERT-UA about its findings on two exposed directories linked to operations targeting Ukrainian internet-exposed infrastructure. The company then held publication for a seven-day disclosure window.
A second open directory was discovered on 213.165.63.49:8080, exposing 1,704 files tied to attacks on TP-Link Archer routers, MikroTik devices, and IP cameras across 15 European countries including Ukraine. Hunt.io later linked this infrastructure to a related russophone operation using exploits, brute force, SOCKS5 proxy setup, and Chisel reverse tunnels.
Attack Capture identified 89.208.97[.]165 as a malicious open directory. Hunt.io later tied that exposed server to tooling, logs, and files from an operation targeting Ukrainian websites and cameras.
Hunt.io reported that the camview toolkit used by the operator tested CVE-2021-33044 among several known camera vulnerabilities against internet-exposed devices in Ukraine. The reference does not anchor when the operator began using this CVE, only that it was part of the recovered tooling.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcereddit.com
Open sourcehunt.io
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.