TechNewsReel
Live

Operation CameraSwarm: 14,530 Dahua IP Cameras Hijacked in 35-Day Campaign

A threat actor exploited legacy vulnerabilities and poor password hygiene to compromise thousands of devices across Russia and Ukraine.

TechNewsReel Newsroom · August 19, 2026

A single threat actor compromised 14,530 Dahua IP cameras during a concentrated 35-day campaign between June 17 and July 22, 2026. Dubbed "Operation CameraSwarm," the operation primarily targeted devices in Russia and Ukraine, raising urgent concerns over regional security and surveillance.

Researchers at Hunt.io discovered the breach after recovering an operator's toolkit from an open directory, which enabled them to map the full scale of the compromise. The attacker employed three parallel vectors to gain access: password brute-forcing, the use of a P2P relay, and the exploitation of two known vulnerabilities, CVE-2021-33044 and CVE-2021-33045. National CERTs were notified of the activity on August 10, 2026, and the full findings were published on August 18, 2026.

The Persistence of Legacy Risks

The reliance on CVE-2021-33044 and CVE-2021-33045 underscores a systemic failure in IoT lifecycle management. These vulnerabilities date back to 2021, yet they remained viable entry points for the CameraSwarm actor five years later. This gap suggests a significant portion of the installed Dahua fleet remains unpatched, leaving devices exposed to well-documented exploits that are easily integrated into automated attack toolkits.

Furthermore, the success of password brute-forcing indicates that many users and organizations continue to deploy IP cameras with default or weak credentials. In the context of IoT security, the combination of unpatched firmware and poor credential hygiene creates a low-barrier environment for threat actors to build massive botnets with minimal effort.

Implications for Privacy and Security

The scale of this compromise is particularly alarming given the geographic concentration in Russia and Ukraine. The hijacking of thousands of cameras in a conflict-sensitive region provides a potent tool for espionage, allowing an external actor to monitor physical movements and infrastructure in real-time. Beyond simple surveillance, such a botnet can serve as a strategic launchpad for deeper network intrusions, enabling attackers to pivot from a compromised camera into more sensitive corporate or government networks.

Future Outlook

Industry analysts are now monitoring whether the CameraSwarm toolkit has been leaked or adopted by other threat actors, which could trigger a second wave of compromises. While the initial campaign has been mapped, the long-term persistence of these backdoors remains a critical concern. Security professionals are urged to audit all Dahua deployments, enforce strong password policies, and ensure all firmware is updated to versions that mitigate the 2021 CVEs.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.