14,530+ devices compromised
Researchers at Hunt.io have uncovered a large-scale hacking campaign, named "Operation CameraSwarm," that compromised at least 14,530 Dahua-manufactured surveillance devices between June and July 2026. The campaign, discovered via an operational security failure by the attacker, utilized a multi-pronged strategy involving brute-force attacks, exploitation of known vulnerabilities, and abuse of Dahua's P2P cloud architecture. The compromised devices, mostly IP cameras and Network Video Recorders (NVRs), were concentrated in Ukraine and Russia. The attack highlights the persistent risks associated with internet-exposed IoT devices, especially those with weak credentials or unpatched firmware.
The threat actor behind Operation CameraSwarm systematically targeted Dahua devices using three distinct methods. The campaign's details were exposed when the attacker left a working directory containing exploit scripts, logs, and compromised device lists on an open HTTP server. The compromised devices can be leveraged for various malicious purposes, including serving as a proxy network, launching DDoS attacks, or as a pivot point for deeper intrusions into connected corporate networks.
Attack Vectors:
37777.p2pwn to exploit two critical authentication-bypass flaws, CVE-2021-33044 and CVE-2021-33045. This method compromised 1,923 cameras and installed a persistent backdoor account.The attacker's toolkit, found on the exposed server at 154.86.119.60, provided clear insight into their TTPs.
masscan to perform broad scans for open TCP port 37777, the default port for Dahua devices. This is an example of T1595.002 - Vulnerability Scanning.T1110.001 - Password Guessing technique against an exposed service.p2pwn tool exploited CVE-2021-33044 and CVE-2021-33045. These vulnerabilities allow an attacker to bypass authentication and create a new admin-level user account. This is a direct application of T1190 - Exploit Public-Facing Application.p2pwn tool created a backdoor user account named p2pwn with the password p2password. On many firmware versions, this account would persist even after a factory reset, demonstrating T1098 - Account Manipulation.T1105 - Ingress Tool Transfer and abuse of a legitimate protocol for C2.T1110 - Brute ForceT1190 - Exploit Public-Facing ApplicationT1078 - Valid AccountsT1098 - Account ManipulationT1595.002 - Vulnerability ScanningThe compromise of over 14,500 cameras creates a significant botnet that can be used for malicious activities. For the owners of these devices, the immediate impact is a loss of privacy and the potential for espionage. For the broader internet community, these devices can be used to launch large-scale DDoS attacks, act as proxies to anonymize other criminal activities, and serve as initial access points into more secure corporate or home networks. The persistence of the backdoor account makes remediation difficult for non-technical users.
154.86.119.60p2pwnp2passwordp2pwn account.Organizations using Dahua devices should hunt for the following indicators:
37777p2pwnp2pwn user.p2pwn. This aligns with D3-LAM: Local Account Monitoring.37777 from the internet. If the port must be exposed, restrict access to a small set of known-good IP addresses.Update device firmware to patch the exploited authentication bypass vulnerabilities.
Enforce strong, unique passwords for all device accounts and disable default credentials.
Prevent direct internet access to device management interfaces. Use a segmented network and VPN for remote access.
Regularly audit for and remove any unauthorized or suspicious user accounts.
Operation CameraSwarm campaign begins.
Operation CameraSwarm campaign ends after 35 days.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.