Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Posted on August 20, 2026 By CWS

A recent cyber attack compromised over 14,000 Dahua IP cameras across Ukraine and Russia, according to reports by Hunt.io. The operation, known as Operation CameraSwarm, occurred from June 17 to July 22, beginning with global scans targeting Russian, Mexican, and Vietnamese ISP ranges before concentrating on Russian and CIS telecom netblocks.

Details of the CameraSwarm Operation

Hunt.io’s investigation revealed access to the hacker’s servers, which contained 2,616 files spread across 234 subdirectories, amounting to roughly 407 MB of data. This data exposure led to the discovery of 14,530 compromised devices over a 35-day period, with a brute-force engine targeting 12,324 unique addresses.

Furthermore, the attackers installed a persistent backdoor account on 1,923 cameras using Remote Procedure Call (RPC). The backdoor account, utilizing the credentials p2pwn/p2password, was independent of any administrative passwords and could endure password changes or factory resets on most firmware versions.

Technical Aspects of the Attack

The attackers employed a publicly available asyncio framework for brute-forcing credentials, alongside a compiled Go binary to bypass authentication. This binary exploited a series of vulnerabilities, including CVE-2021-33044 and CVE-2021-33045, to implement the backdoor account.

Notably, CVE-2021-33044 involves a flaw where the system unconditionally trusts clients identifying as NetKeyboard hardware controllers, ignoring the password field when clientType is NetKeyboard. Additionally, CVE-2021-33045 takes advantage of the firmware reading the source address from the request body rather than the TCP connection, allowing unauthorized administrative access.

Infrastructure and Motivation

The attackers occasionally exploited Dahua’s cloud relay to access cameras behind NATs using only their serial numbers. Hunt.io discovered that the campaign’s infrastructure had been established at least a year prior, integrating both custom and modified code from four other developers.

While the exact motivations of the threat actors remain unclear, Hunt.io assesses that the toolkit’s design suggests potential third-party access, though there is insufficient evidence to confirm a commercial operation. The broader implications of this breach, including potential surveillance or data theft, remain under scrutiny.

This incident underscores ongoing vulnerabilities in networked devices and the critical need for robust cybersecurity measures to protect sensitive infrastructure.

Security Week News Tags:Backdoor, camera hack, cloud relay, CVE-2021-33044, CVE-2021-33045, cyber attack, Cybersecurity, Dahua, Hunt.io, IP cameras, network security, Operation CameraSwarm, Russia, threat actor, Ukraine

Post navigation

Previous Post: Zombie Card Technique Revives Expired Visa Cards
Next Post: OpenAI Pauses AI Training Over Cybersecurity Concerns

Related Posts

Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws Microsoft Patches 173 Vulnerabilities, Including Exploited Windows Flaws Security Week News
UK Train Operator LNER Warns Customers of Data Breach UK Train Operator LNER Warns Customers of Data Breach Security Week News
CISA Warns of Spyware Targeting Messaging App Users CISA Warns of Spyware Targeting Messaging App Users Security Week News
WhatsApp Introduces Usernames for Enhanced Privacy WhatsApp Introduces Usernames for Enhanced Privacy Security Week News
April 2026 Sees 33 Major Cybersecurity M&A Deals April 2026 Sees 33 Major Cybersecurity M&A Deals Security Week News
IBM and Red Hat Invest  Billion to Enhance Open Source Security IBM and Red Hat Invest $5 Billion to Enhance Open Source Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark