A significant security breach has affected more than 14,000 Dahua internet-connected cameras, showcasing the vulnerability of surveillance equipment as a conduit for unauthorized access to video feeds and device settings. This large-scale operation spanned 35 days, targeting devices globally, with notable breaches in Ukraine and Russia. The incident highlights the potential for unattended devices to offer enduring, clandestine access to intruders.
Global Impact of Dahua Camera Breach
The breach involved scanning for exposed camera management services, exploiting weak credentials, and leveraging two known authentication-bypass vulnerabilities in unpatched devices. A cloud relay method was employed, allowing access to cameras obscured by network address translation by using serial numbers, making even non-public devices susceptible to attack.
Hunt.io analysts uncovered this activity after discovering an openly accessible directory containing 2,616 files and campaign tools. According to a Hunt.io report shared with Cyber Security News, the findings revealed multiple attack vectors, persistent access tools, and an unrelated Windows payload.
Persistent Backdoor Access
One of the most alarming discoveries was the persistence of access. After obtaining administrator rights through the vulnerabilities CVE-2021-33044 and CVE-2021-33045, attackers created an additional account via the camera’s remote management interface. This account is independent of the main administrator password, meaning a password change does not eliminate it. In most affected firmware, even a factory reset fails to remove this hidden access. Hunt.io identified 1,923 cameras with this unauthorized account.
This revelation transforms a routine password update into a full-fledged compromise investigation, particularly for organizations utilizing cameras in sensitive areas. Despite available patches, exposed and unpatched cameras remain attractive targets, emphasizing the importance of understanding the risks of direct exposure.
Recommendations for Enhanced Security
The campaign also exploited a cloud relay feature to locate and contact cameras using serial numbers. Logs indicate that 89.4% of tested serials connected to channels that bypassed authentication. Attackers generated recovery codes offline, enabling password recovery without current device credentials. This renders the threat more persistent, as eliminating the unauthorized account may not end access.
Organizations are advised to audit all camera accounts, eliminate unauthorized accounts, and frequently change camera and connected recorder credentials. Additionally, administrators should deactivate unneeded P2P features, restrict management services to trusted networks, and apply vendor updates to remedy the bypass vulnerabilities.
Implementing firmware updates is critical as they prevent the generation of new recovery codes and eventually invalidate previous ones. Network and Windows teams should monitor for abnormal login patterns and scrutinize broad security-tool exclusions. For further insights into the risks posed by exposed video equipment, refer to the FBI’s warnings on webcam and DVR attacks and analyses of automated camera exploitation tools.
By staying informed and proactive, organizations can mitigate the risks associated with surveillance equipment vulnerabilities and enhance their overall security posture.
