Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Posted on August 20, 2026 By CWS

A recent cyber attack compromised over 14,000 Dahua IP cameras across Ukraine and Russia, according to reports by Hunt.io. The operation, known as Operation CameraSwarm, occurred from June 17 to July 22, beginning with global scans targeting Russian, Mexican, and Vietnamese ISP ranges before concentrating on Russian and CIS telecom netblocks.

Details of the CameraSwarm Operation

Hunt.io’s investigation revealed access to the hacker’s servers, which contained 2,616 files spread across 234 subdirectories, amounting to roughly 407 MB of data. This data exposure led to the discovery of 14,530 compromised devices over a 35-day period, with a brute-force engine targeting 12,324 unique addresses.

Furthermore, the attackers installed a persistent backdoor account on 1,923 cameras using Remote Procedure Call (RPC). The backdoor account, utilizing the credentials p2pwn/p2password, was independent of any administrative passwords and could endure password changes or factory resets on most firmware versions.

Technical Aspects of the Attack

The attackers employed a publicly available asyncio framework for brute-forcing credentials, alongside a compiled Go binary to bypass authentication. This binary exploited a series of vulnerabilities, including CVE-2021-33044 and CVE-2021-33045, to implement the backdoor account.

Notably, CVE-2021-33044 involves a flaw where the system unconditionally trusts clients identifying as NetKeyboard hardware controllers, ignoring the password field when clientType is NetKeyboard. Additionally, CVE-2021-33045 takes advantage of the firmware reading the source address from the request body rather than the TCP connection, allowing unauthorized administrative access.

Infrastructure and Motivation

The attackers occasionally exploited Dahua’s cloud relay to access cameras behind NATs using only their serial numbers. Hunt.io discovered that the campaign’s infrastructure had been established at least a year prior, integrating both custom and modified code from four other developers.

While the exact motivations of the threat actors remain unclear, Hunt.io assesses that the toolkit’s design suggests potential third-party access, though there is insufficient evidence to confirm a commercial operation. The broader implications of this breach, including potential surveillance or data theft, remain under scrutiny.

This incident underscores ongoing vulnerabilities in networked devices and the critical need for robust cybersecurity measures to protect sensitive infrastructure.

Security Week News Tags:Backdoor, camera hack, cloud relay, CVE-2021-33044, CVE-2021-33045, cyber attack, Cybersecurity, Dahua, Hunt.io, IP cameras, network security, Operation CameraSwarm, Russia, threat actor, Ukraine

Post navigation

Previous Post: Zombie Card Technique Revives Expired Visa Cards
Next Post: OpenAI Pauses AI Training Over Cybersecurity Concerns

Related Posts

OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity OpenAI Launches GPT-5.6-Cyber for Advanced Cybersecurity Security Week News
What Can Businesses Do About Ethical Dilemmas Posed by AI? What Can Businesses Do About Ethical Dilemmas Posed by AI? Security Week News
Axonius Acquires Medical Device Security Firm Cynerio in 0 Million Deal Axonius Acquires Medical Device Security Firm Cynerio in $100 Million Deal Security Week News
Telnyx Python SDK Faces Supply Chain Attack Telnyx Python SDK Faces Supply Chain Attack Security Week News
Urgent Patch Needed for Critical Citrix NetScaler Vulnerability Urgent Patch Needed for Critical Citrix NetScaler Vulnerability Security Week News
Samsung Announces Security Improvements for Galaxy Smartphones Samsung Announces Security Improvements for Galaxy Smartphones Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Red Hat Kubernetes Vulnerability Risks Internal Services
  • Atlassian and Splunk Address Critical Software Vulnerabilities
  • Critical Isolated-vm Flaw Threatens JavaScript Security
  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Red Hat Kubernetes Vulnerability Risks Internal Services
  • Atlassian and Splunk Address Critical Software Vulnerabilities
  • Critical Isolated-vm Flaw Threatens JavaScript Security
  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark