
Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised in Ukraine and Russia
CybersecurityHackingIoTVulnerabilities
An exposed working directory on an open HTTP server revealed details of a campaign targeting Dahua cameras. The operation used three exploitation methods: an asyncio credential brute-forcer, a CVE-2021-33044/33045 authentication-bypass chain, and P2P relay abuse via serial numbers without proper authentication. Two referenced CVEs (2024-39943 and 2025-31702) were mislabeled or unrelated to the unauthenticated relay abuse. The corpus provided technical details, including PTCP tunnel techniques, but did not attribute the attack to any specific actor.