🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
An operator's exposed working directory on an HTTP server allowed Hunt.io to reconstruct a campaign. This led to the discovery of three parallel exploitation paths targeting Dahua cameras. One path involved an asyncio credential brute-forcer. Another utilized an authentication bypass chain for CVE-2021-33044/33045. The third exploited P2P relay abuse, accessing cameras by serial number, a method that bypasses authentication entirely. This relay path relied on session tokens obtained with fixed SDK credentials. Two disclosed CVEs were found to be misattributed or too narrow for this unauthenticated relay abuse. The report details the PTCP tunnel breakdown, including specific packet structures and a bind-to-localhost technique. Neutral attribution is maintained, focusing on the operation's methods rather than its operators. Detailed mitigation and indicators of compromise are available on Hunt.io.