Researchers reconstructed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras, with the largest concentration of affected devices in Ukraine and Russia. The operation was pieced together from an exposed directory on 154.86.119.60 containing the operator’s tooling, logs, source code, and staging files. According to the report, the attackers used three parallel access paths: credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua’s P2P cloud relay to reach cameras by serial number. Researchers said the relay path relied on cloud-issued session tokens obtainable through fixed SDK credentials embedded in Dahua clients, enabling unauthenticated access through that channel.
The operators also installed a persistent backdoor account, p2pwn / p2password, on 1,923 cameras; the account reportedly survives password changes and, on most firmware, even factory resets, while offline-generated recovery codes could provide additional cloud-level administrative reset capability by serial number. Hunt.io said some CVE labels used in the tooling were incorrect, including a misreference to CVE-2024-39943 and an overbroad use of CVE-2025-31702, and it made no attribution claim for the campaign. The same host also staged a separate UPX-packed Windows payload believed to be SalatStealer and a PowerShell script for Microsoft Defender exclusions. Defenders were urged to treat exposed Dahua cameras as potentially compromised, remove the p2pwn account, rotate credentials, disable P2P where unnecessary, and apply firmware updates covered by Dahua SA-2021-0130.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
On 18 August 2026, Hunt.io published a technical analysis of Operation CameraSwarm, detailing how a single operator compromised more than 14,530 Dahua cameras between 17 June and 22 July 2026. The report publicly documented the brute-force, exploit-chain, and cloud-relay access paths, as well as tooling and infrastructure including host 154.86.119.60 and a second host at 185.132.53.56.
On August 10, 2026, Hunt.io notified national CERTs and Dahua's PSIRT about the CameraSwarm campaign. This was an official disclosure and coordination step following Hunt.io's reconstruction of the operation.
On 23 July 2026, Hunt.io AttackCapture crawled an exposed open HTTP directory on 154.86.119.60 used by the operator. The crawl recovered 2,616 files across 234 subdirectories totaling 407 MB, enabling reconstruction of the campaign.
On 18 June 2026, the campaign's largest early haul skewed toward Mexican and Vietnamese consumer ISP ranges before later focus shifted toward Russian and CIS telecom netblocks. The broader compromise set was later concentrated in Ukraine and Russia, with Ukraine holding the largest share.
Between 17 June and 22 July 2026, a single operator compromised more than 14,530 Dahua IP cameras over 35 days. The campaign used credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua's P2P relay by serial number.
Hunt.io reported that the CameraSwarm operator used Dahua's cloud relay to reach 283 cameras by serial number alone during the campaign. The recovered tooling logged that 89.4% of live serials exposed an open no-authentication channel, making serial-number knowledge the main barrier to access.
During the campaign, the operator installed a persistent backdoor account named p2pwn with password p2password on 1,923 cameras. The account was installed over RPC and survived password changes and, on most firmware, factory resets.
SSH fingerprint telemetry showed that server 154.86.119.60 had hosted multiple operating system generations since April 2025, indicating the infrastructure predated the camera-compromise campaign. Hunt.io assessed the host was repurposed rather than provisioned specifically for this operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityweek.com
Open sourcexakep.ru
Open sourcecyberveille.ch
Open sourcereddit.com
Open sourcehunt.io
Open sourcegithub.com
Open sourcelabs.itresit.es
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.