Researchers at Hunt.io uncovered two exposed directories that revealed parallel intrusion operations targeting internet-exposed infrastructure in Ukraine, particularly IP cameras and routers. One server at 89.208.97[.]165 contained evidence that a Ukrainian OpenCart-based e-commerce site had been compromised through SQL injection and repurposed as a proxy and staging node for Tor-routed intrusion attempts against Ukrainian government and military websites. The same server hosted a custom camera exploitation platform, camview, whose recovered data showed 58 compromised Ukrainian cameras, logs of live viewing sessions, and use of the open-source Ingram scanner against Dahua, Hikvision, D-Link, and Reolink devices.
A second exposed directory at 213.165.63[.]49 showed a separate but similar operation using Russian-language tooling, Ingram, and custom scripts to scan and exploit routers and cameras across 15 European countries, with camera targeting concentrated on Ukraine. The toolkit focused on converting compromised TP-Link, MikroTik, and camera devices into SOCKS5 proxies and reverse tunnels over port 4444, relying on stolen access, weak credentials, and known vulnerabilities, including CVE-2021-33044. Hunt.io said the activity was not attributed to a named threat actor or state entity, but the exposed infrastructure pointed to a low-cost, repeatable campaign aimed at Ukrainian targets using publicly available tools and long-patched flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Hunt.io published research describing two exposed directories that revealed separate but similar operations targeting Ukrainian cameras, routers, and websites using stolen access, weak credentials, and known vulnerabilities. The report documented a compromised Ukrainian OpenCart site used as a proxy and staging point, plus camview data showing 58 compromised Ukrainian cameras and live viewing logs.
Hunt.io notified CERT-UA about its findings on two exposed directories linked to operations targeting Ukrainian internet-exposed infrastructure. The company then held publication for a seven-day disclosure window.
Attack Capture identified 89.208.97[.]165 as a malicious open directory. Hunt.io later tied that exposed server to tooling, logs, and files from an operation targeting Ukrainian websites and cameras.
Hunt.io reported that the camview toolkit used by the operator tested CVE-2021-33044 among several known camera vulnerabilities against internet-exposed devices in Ukraine. The reference does not anchor when the operator began using this CVE, only that it was part of the recovered tooling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcehunt.io
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.