A large-scale campaign dubbed Operation CameraSwarm has compromised more than 14,000 Dahua IP cameras, with victims concentrated in Ukraine, Russia and neighboring CIS countries over a 35-day window this summer.[1][2][7][13][14] Researchers say a single operator gained persistent, remote access to at least 14,530 devices between June 17 and July 22, 2026, turning widely deployed surveillance systems into an extensive, distributed foothold across telecom, corporate and residential networks.[1][2][7][13][14] The operation was first detailed by analysts at Hunt.io and subsequently confirmed by multiple independent reports, which together paint one of the most significant mass compromises of commercial cameras in recent years.[1][2][7][13][14]
CameraSwarm combined several techniques to break into Dahua cameras at scale, beginning with credential attacks against devices exposed on the internet.[2][7][11][13] According to technical breakdowns, the operator ran an asyncio-based brute-forcer targeting Dahua’s proprietary TCP service on port 37777, exploiting weak or reused passwords to gain access on thousands of endpoints.[2][11][13][14] Where brute force failed, the campaign pivoted to two known authentication-bypass flaws in Dahua products, chaining misconfigurations with protocol quirks to sidestep normal login flows and plant persistent administrator accounts.[2][7][11][13] A third access path abused Dahua’s peer‑to‑peer cloud relay, using device serial numbers and SDK credentials to reach hundreds of cameras that were otherwise shielded behind NAT or firewalls.[2][7][11][13][14]
Two of the vulnerabilities abused in the operation are tracked as CVE-2021-33044 and CVE-2021-33045, critical authentication-bypass bugs affecting Dahua IP cameras and related video products.[5][8][9][10] Both issues allow remote attackers to bypass device identity checks during the login process by sending specially crafted data packets, including manipulation of the NetKeyboard type parameter and spoofed loopback addresses in authentication requests.[5][8][9][10] The flaws carry CVSS scores of 9.8 and have been highlighted in public advisories as impacting multiple Dahua firmware branches prior to mid‑2020 and June 2021, depending on model.[5][8][9] They remain listed in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, underscoring their continued use in real‑world attacks and the urgency of applying vendor mitigations or retiring affected devices.[5][8][9] Separate reporting has linked exploitation of CVE‑2021‑33045 to Russia’s GRU Unit 29155, but CameraSwarm itself has not yet been publicly attributed to a specific threat group.[10][1][13]
The compromise of so many internet‑connected cameras has significant operational and privacy implications for organizations and individuals alike.[1][2][7][14] Once an attacker gains administrative control of a Dahua camera, they can manipulate live and recorded video, disable or spoof motion detection, and potentially use the device as a pivot into internal networks.[1][3][6][12] Dahua equipment has previously been at the center of serious security findings, including ONVIF protocol flaws such as CVE-2022-30563 that enable credential replay, and more recent buffer‑overflow bugs CVE-2025-31700 and CVE-2025-31701 that allow remote code execution on several camera and PTZ series.[12][15] Taken together with CameraSwarm, these issues highlight how quickly unpatched or poorly configured video systems can be repurposed as both surveillance tools for adversaries and launchpads for wider compromise.
Defenders with Dahua deployments now face a dual challenge: identifying whether their cameras were touched during CameraSwarm and closing the underlying exposure that made the campaign possible.[1][2][7][13][14] Security guidance around CVE‑2021‑33044 and CVE‑2021‑33045 stresses upgrading to fixed firmware releases, disabling unused remote management features and cloud P2P relay, and enforcing strong, unique passwords on every device.[5][8][9] CISA’s advisories further recommend segmenting cameras on dedicated networks, restricting inbound access to known management systems, and continuously monitoring for anomalous logins or unexplained configuration changes indicative of prior compromise.[4][5][8] For organizations unable to apply patches or mitigations, regulators and incident responders increasingly advise replacing vulnerable cameras outright rather than accepting the risk of persistent, hard‑to‑detect access by unknown operators.[5][8]
While CameraSwarm appears to have concluded in late July, researchers warn that its success is likely to inspire copycat operations targeting the same weaknesses in Dahua and other IP camera ecosystems.[1][2][7][13][14] With Dahua devices deployed at scale across critical infrastructure, retail, transportation and residential settings worldwide, the campaign serves as a reminder that “perimeter” sensors are often among the least maintained yet most exposed assets in modern networks.[1][2][7][12] Organizations that treat cameras as part of their core attack surface—subject to regular patching, credential hygiene and network hardening—will be far better positioned to weather the next wave of CameraSwarm‑style attacks than those still assuming their video systems are benign appliances.[5][8][12]
References
- Over 14000 Dahua cameras compromised across Ukraine and Russia
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign
- Ip Camera CVEs and Security Vulnerabilities
- Dahua Technology Co., Ltd Digital Video Recorders and IP …
- CISA Warns of Exploited Vulnerabilities Impacting Dahua Products
- Dahuasecurity CVEs and Security Vulnerabilities – OpenCVE
- Hackers Compromised 14,500+ Dahua Devices Using Credential …
- U.S. CISA adds Dahua IP Camera, Linux Kernel and …
- CVE-2021-33044 – Dahua IP Camera Authentication Bypass …
- CVE-2021-33045 – Exploits & Severity
- r/netsec – Operation CameraSwarm: over 14000 Dahua cameras …
- A flaw in Dahua IP Cameras allows full take over of the …
- CyberHappenings — Sourced Cybersecurity Happenings and Timelines
- CameraSwarm Campaign: 14500 Dahua IP Cameras …
- Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and …
