14,500 Dahua cameras hacked — backdoor survives factory reset on most firmware versions

A 35-day hacking campaign dubbed CameraSwarm compromised over 14,500 Dahua IP cameras, primarily located in Ukraine and Russia. The operation ran from June 17 to July 22, according to researchers at threat intelligence firm Hunt.io, who discovered the campaign after the operator left a working directory on an HTTP server unprotected.
Hunt.io recovered 407 MB of data comprising 2,616 files across 234 directories. The recovered files included source code, logs, credentials, captured camera snapshots, shell history, and exploitation results. This data allowed the researchers to reconstruct the full scope of the attack.
The attackers used three parallel methods to compromise the devices. The first method was brute-forcing TCP port 37777, which compromised 12,324 devices at unique IP addresses. The brute-forcing system captured usable camera snapshots, sent the results to Telegram, and exported them for Dahua's SMART PSS platform.
The second method exploited vulnerabilities CVE-2021-33044 and CVE-2021-33045 using a tool called p2pwn. This tool installed a persistent backdoor account (p2pwn / p2password) on 1,923 cameras. Critically, this backdoor account survives password changes and, on most firmware versions, even factory resets. This means that simply resetting the camera to its default settings will not remove the attacker's access.
The third method was a cloud-relay attack that reached 283 cameras behind NAT. The attackers used only serial numbers and SDK credentials embedded in Dahua applications. According to the data, 89.4% of live serial numbers exposed an access channel without requiring any authentication. This method allowed the hackers to target devices that were not directly exposed to the internet but were still registered with Dahua's cloud services.
The data recovered by Hunt.io also included shell command history and exploitation results, which helped the researchers map the operation's infrastructure. The campaign's scale and the use of a backdoor that survives factory resets pose a significant security concern for Dahua camera owners, especially those in the affected regions.


