Russian intelligence operatives have been systematically hacking into internet-connected security cameras across Europe and Ukraine. These intrusions are being used to monitor military logistics, track weapons shipments to Kyiv, and observe the positions of Ukrainian forces. This revelation comes from a cybersecurity advisory published on July 10 by the Netherlands’ intelligence agencies, AIVD and MIVD, highlighting the ongoing nature of this operation.
Targeting Ukrainian Military
In Ukraine, the situation escalates beyond mere surveillance. The compromised camera feeds have been used in attempts to target and neutralize Ukrainian military personnel, according to the Dutch services. By exploiting exposed roadside or business cameras, the attackers have turned civilian technology into military targeting tools.
Beyond Ukraine, similar tactics are employed across EU and NATO states. Here, the focus extends to gathering military intelligence unrelated to the current conflict, demonstrating the broad scope of this espionage effort.
Methods of Camera Compromise
The method of gaining access to these cameras is alarmingly simple. Attackers scan the internet for devices with default settings, such as unchanged passwords or outdated firmware. Once access is gained, image-recognition software automatically scans the video feeds for military vehicles and cargo, eliminating the need for sophisticated zero-day exploits.
Despite public concern, not all exposed cameras are hacked. As Martijn Grooten from Censys, an internet-scanning firm, notes, being publicly accessible does not inherently make a camera vulnerable to hacking. Nevertheless, Censys identified over 87,000 vulnerable cameras across the EU, NATO, and Ukraine, with over 4,000 located in Ukraine alone.
Understanding the Vulnerability Landscape
Censys reports that many cameras in the Netherlands are potentially vulnerable due to known exploits. Specifically, 45,386 cameras are publicly reachable, with 1,992 running services with exploitable vulnerabilities. Narrowing down to software-specific issues reduces the number to 541.
These vulnerabilities include CVE-2016-7407, affecting the Dropbear SSH server, and CVE-2021-39275, a low-rated Apache vulnerability. Despite their identification, neither vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog. The Dutch services have confirmed only a few cameras have been used in direct espionage activities along military logistics routes.
Defensive Measures for Camera Security
To mitigate these threats, experts recommend several security measures. Identifying and securing publicly reachable cameras, particularly those overlooking sensitive areas, is crucial. Disabling public internet access, using VPNs, and employing multi-factor authentication are key steps in protecting these devices.
Maintaining up-to-date firmware and carefully positioning cameras to avoid capturing sensitive sites are additional recommended practices. The Dutch services have not observed any camera-derived intelligence being used for attacks outside Ukraine, yet the potential remains due to the simplicity of these espionage tactics.
The broader lesson is clear: preventing unauthorized access is not solely about updating devices but also about removing them from public visibility and controlling what they monitor. A compromised camera can provide adversaries with real-time insights into military operations, emphasizing the need for vigilant cybersecurity practices.
