Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Incidents: Mass exploitation of Dahua IP cameras via brute-forcing and CVEs leaves 14,000 devices with persistent backdoors.
Deep Analysis and Expert Commentary
The attack chain reveals a multi-phase operation: initial global scanning narrowed to Russian/CIS telecom blocks, followed by credential brute-forcing (12,324 targets) using a public asyncio framework. Critical vulnerabilities (CVE-2021-33044, CVE-2021-33045, CVE-20244-39943) were chained to bypass authentication, granting admin sessions and deploying a resilient backdoor via RPC. Notably, the backdoor persists through firmware resets, indicating deep firmware-level compromise. Attackers also abused Dahua’s cloud relay to bypass NATs using serial numbers alone. The toolkit’s modular design—incorporating both custom and third-party code—points to a scalable, reusable framework likely intended for access brokering. Defenders should prioritize firmware updates, disable cloud relay features where unnecessary, and monitor for RPC connections using the p2pwn credentials.
Action Items
- Patch Dahua cameras immediately to address CVE-2021-33044, CVE-2021-33045, and related vulnerabilities.
- Audit RPC configurations and disable unused remote access protocols.
- Monitor network traffic for anomalous connections to cloud relay services or serial-number-based requests.
Original Article Brief Intro
SecurityWeek · 2026-08-20 · Incidents: Mass exploitation of Dahua IP cameras via brute-forcing and CVEs leaves 14,000 devices with persistent backdoors.
Related Terms and Notes
CVE IDs
- CVE-2021-33044 — Dahua authentication bypass exploiting trust in NetKeyboard clients, ignoring password validation.
Malware Families
- Backdoor
- Operation CameraSwarm
- Persistent Backdoor
- RPC — Remote Procedure Call, a protocol allowing remote execution of commands, abused here for backdoor deployment.
Techniques / TTPs
- Brute-Force
Context Notes
- CVE
- Dahua
- IoT
- RPC
- RPC Exploitation