Over 14,500 Dahua cameras hacked in a month — attackers used three methods including P2P relay

Over 14,500 Dahua cameras hacked in a month — attackers used three methods including P2P relay

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that compromised more than 14,530 Dahua devices between June 17 and July 22, 2026. The operation, codenamed Operation CameraSwarm, was reconstructed from an exposed working directory of 407 MB containing 2,616 files across 234 subdirectories, including tooling, logs, shell history, and campaign records.

The researchers identified three primary attack vectors. The first was credential attacks, which accounted for 12,324 unique IP addresses across 13,229 campaign records. The second exploited two authentication-bypass vulnerabilities — CVE-2021-33044 and CVE-2021-33045 — allowing attackers to reach 1,923 cameras. The third method used a peer-to-peer (P2P) relay technique, which compromised 283 cameras identified by serial number, including devices located behind network address translation (NAT).

According to Hunt.io, the confirmed compromises were concentrated in Ukraine and Russia. During the operation, 1,923 cameras were configured with a persistent account, and 283 were reached through the P2P path. The relay establishes the route without prior authentication, leaving login checks to the device's web application, ITRES Labs noted in an analysis published in October 2025.

The two 2021 flaws are authentication-bypass vulnerabilities that allow remote attackers to bypass authentication to access sensitive information or initiate a connection with a target device. Hunt.io stated that the attackers used these vulnerabilities in combination with credential attacks and P2P relay to maximize their reach.

Users of affected Dahua products are advised to install the corresponding fix software or newer firmware. ITRES Labs recommends disabling P2P where it is not required and checking firmware against the vendor's download site. The scale of the campaign highlights the persistent risk posed by unpatched IoT devices and the evolving tactics of attackers who combine multiple techniques to compromise large numbers of connected devices.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate