In a significant cybersecurity incident, researchers from Hunt.io have revealed a breach affecting over 14,530 Dahua devices. The breach occurred between June 17 and July 22, 2026, employing credential attacks, authentication-bypass exploits, and a peer-to-peer (P2P) relay method.
Details of Operation CameraSwarm
The breach, dubbed Operation CameraSwarm, was uncovered through a 407 MB exposed working directory. This directory contained 2,616 files spread across 234 subdirectories, including essential tools, logs, and records of the campaign. The compromised devices were predominantly located in Ukraine and Russia.
During the campaign, researchers noted that 1,923 cameras were set up with persistent accounts, while 283 devices were accessed through a P2P relay. Users of affected Dahua devices are encouraged to update their firmware or apply the recommended security patches. ITRES Labs emphasizes disabling P2P features unless necessary and verifying firmware versions against the manufacturer’s site.
Understanding the Breach Mechanisms
Hunt.io attributes the breach to three main attack vectors. Credential attacks accounted for 12,324 unique IP addresses over 13,229 records. Authentication bypasses involved CVE-2021-33044 and CVE-2021-33045, affecting 1,923 cameras configured with persistent accounts. The P2P relay identified 283 cameras, even those behind network address translation (NAT).
The flaws CVE-2021-33044 and CVE-2021-33045 are critical vulnerabilities in Dahua products. Dahua rates these vulnerabilities with a CVSS score of 8.1, while the U.S. National Vulnerability Database assigns a score of 9.8. These exploits enable attackers to bypass device authentication by crafting malicious data packets.
Recommendations and Future Implications
Security experts advise disabling unnecessary P2P features and updating device firmware from official sources. ITRES Labs found that older firmware versions before mid-2024 were particularly vulnerable to these attacks. The Easy4IP relay could be exploited using valid serial numbers, making devices accessible despite being behind NAT.
Hunt.io’s findings indicate that 89.4% of live serial numbers could establish an open channel without authentication. However, this claim remains specific to the operation and has not been independently verified by ITRES Labs or Dahua. ITRES Labs recommends strong, unique credentials and segmenting surveillance systems to mitigate risks.
While the operators behind the breach are believed to be Russian-speaking, there is no confirmed attribution to any specific threat actor or government entity. The incident underscores the importance of robust security measures and continuous monitoring to protect networked devices.
