Operation CameraSwarm Compromised More Than 14,500 Dahua Cameras, Hunt.io Finds

Summary
Hunt.io says an operator compromised more than 14,530 Dahua devices in 35 days using credential brute force, authentication bypasses and serial-based P2P relay access, leaving 1,923 cameras with a persistent backdoor.
Key points
- Hunt.io traced more than 14,530 compromised devices to a 35-day campaign; confirmed compromises were concentrated in Ukraine and Russia, although scanning was global.
- The operator combined credential brute force against TCP/37777, unauthenticated CVE-2021-33044 and CVE-2021-33045 bypasses, and Dahua’s P2P relay, which can reach cameras by serial number; 283 cameras were reached through the relay.
- The p2pwn tool installed the p2pwn / p2password account on 1,923 cameras. The account can survive password changes and, on most firmware, factory resets.
- The toolkit generated offline Dahua recovery codes that could enable administrative password resets. Hunt.io says updating firmware prevents new codes and eventually invalidates previously issued ones.
- A separate UPX-packed Windows binary, assessed as likely SalatStealer, and a script designed to add Microsoft Defender exclusions were found on the operator’s host; the report treats this as a distinct capability.
- Hunt.io recommends auditing cameras for the backdoor account, removing it and rotating stored credentials, disabling P2P if unneeded, applying Dahua’s security fixes and keeping firmware updated. It also advises preventing external access to port 37777.
Article Details
- Attack Vectors
- The operator scanned TCP/37777, then used a high-concurrency credential-guessing engine against Dahua's Easy4IP management protocol.
- p2pwn used CVE-2021-33044 and CVE-2021-33045 authentication bypasses to obtain administrator sessions without a working password, then installed a persistent local account over RPC.
- Serial-number harvesting and Dahua's cloud relay gave the operator a path to cameras behind NAT. The relay path did not itself guarantee device control; the toolkit also used credentials or authentication bypasses.
- A separate tool generated device recovery codes offline from verified live serial numbers, creating an administrative-reset risk independent of device credentials.
- A Windows binary tagged by a sandbox as SalatStealer was staged alongside a PowerShell script designed to create Defender exclusions. The malware-family assessment was not independently confirmed.
- Defensive Notes
- Audit Dahua camera accounts for p2pwn, remove it, and rotate stored credentials that may have been drained.
- Disable camera P2P where it is not needed; blocking individual relay addresses is not a reliable control.
- Apply Dahua SA-2021-0130, update camera firmware, and prevent external access to TCP/37777. Dahua states that updated firmware prevents generation of valid new recovery codes and that previously issued codes are eventually invalidated.
- Investigate login requests containing clientType NetKeyboard or loginType Loopback with ipAddr 127.0.0.1.
- On Windows systems, monitor for volume-wide Defender exclusions, CIM calls against MSFT_MpPreference, and unexpected policy refreshes. Do not treat the cloned rbc.ru certificate as evidence that RBC or Qrator was compromised.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 154[.]86[.]119[.]60 | Operator server used for scanning and payload staging; its open directory exposed the working environment. |
| IPV4 | 185[.]132[.]53[.]56 | Second host where the identical staged Windows payload was observed; the report assesses a brief takeover with moderate confidence. |
| SHA256 | 083c9ee06ed2ee1bc0051358b3eeb3242f474eacea4c88b3b10b06d15389b753 | Hash of the operator's partially rewritten serial brute-forcer script. |
| SHA256 | 4a4a346df72c839272ea835e4717cd88f843333b3563e745e657895347ea3dbe | Hash of the active launcher for parallel serial-number probing. |
| SHA256 | 5f60e5b45ecd67a987bdb1173d6a8063aa20a7946377da4698aaba3ebe72d088 | Hash of the fully Russified serial brute-forcer script recovered from the operator server. |
| SHA256 | 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8 | Hash of the operator's compiled p2pwn Go ELF. |
| SHA256 | 7a963211a052a78899a8881d36b42b55690c02e95c1485f5d78d3cfdb3d2842a | Hash of the original serial brute-forcer script recovered from the operator server. |
| SHA256 | be2738c8a2beb55ac484d71c329381f3caabac80664283ad9a24dbab82b5b590 | Hash of the operator's p2pwn source archive. |
| SHA256 | cba28f2b4f12cd3f0a222a3885bef70518872c0ca62798dc810b8caa3035cca7 | SSH host-key fingerprint observed on the operator server during its Debian 13 period, beginning in the campaign. |
| SHA256 | de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c | Hash of the staged 1.exe / xeno.exe Windows binary, tagged as SalatStealer by a sandbox. |
MITRE ATT&CK
T1027.002 · Software PackingThe separately staged Windows executable was UPX-packed.T1110.003 · Password SprayingThe asyncio engine tried credential pairs against large numbers of cameras on TCP/37777.T1113 · Screen CaptureThe camera-scanning engine captured snapshots and filtered out dark, featureless frames.T1136.001 · Local Accountp2pwn installed a persistent local camera account named p2pwn through RPC.T1190 · Exploit Public-Facing ApplicationThe operator used CVE-2021-33044 and CVE-2021-33045 to bypass authentication on exposed cameras.T1562.001 · Disable or Modify ToolsA staged PowerShell script used five methods to establish Defender exclusions, including a Group Policy registry key.T1567.004 · Exfiltration Over WebhookThe brute-force engine posted credential hits and captured images to a Telegram channel through a bot.T1595.001 · Scanning IP Blocksmasscan swept Russian address blocks and then the global IPv4 range for TCP/37777.T1596.005 · Scan DatabasesThe serial-harvesting module queried Shodan for Dahua banners and serial numbers.
CVE
CVE-2021-33044CVE-2021-33044 / CVE-2021-33045 bypass chain1,923 cameras, each backdooredCVE-2021-33045CVE-2021-33044 / CVE-2021-33045 bypass chain1,923 cameras, each backdooredCVE-2024-39943CVE-2024-39943 is the label p2pwn attaches to its persistent-backdoor technique. That identifier belongs to an unrelated command-injection flaw in Rejetto HTTP File Server, a different vendor and product family. TheCVE-2025-31702CVE-2025-31702 is inherited from the upstream researchers whose proof-of-concept underlies the relay component. Dahua's advisory for that identifier describes something far narrower: a post-authentication privilege
Malware
SalatStealerA second, unrelated capability was staged on the same host: a UPX-packed Windows binary classified as SalatStealer, with a five-method Defender bypass script.XenoRATThe pre-rename filename implies XenoRAT. The only sandbox classification attached to the file, on both hosts, is SalatStealer. In our indexed reporting these are materially different families: every XenoRAT sighting
Vendors
Products
Dahua IP camerasBetween 17 June and 22 July 2026, a single operator compromised over 14,000 Dahua IP cameras. The scanning behind it was global: masscan sweeps ran against Russian address space first, then across the full IPv4 range,DefenderA second, unrelated capability was staged on the same host: a UPX-packed Windows binary classified as SalatStealer, with a five-method Defender bypass script.SMART PSSA separate module batches credential hits into SMART PSS-compatible XML, Dahua's own enterprise camera-management platform.
Tools
add-defender-exclusions.ps1Figure 19. add-defender-exclusions.ps1: five independent Defender exclusion methods, including Group Policy persistence.The five methods are deliberately redundant: user-context PowerShell, a full-list override, CIM/WMIasleep_scannerThe engine is a purpose-built asyncio framework, publicly available as asleep_scanner under the handle d34db33f-1007; the operator's copy links to that repository from its bundled README. Russian developer comments runCCTV-ScannerCCTV-Scanner-main/, publicly attributed to github.com/ipxobd/CCTV-Scanner, contains no exploitation code. It fingerprints Dahua and Hikvision devices over HTTP by page title and probes RTSP, port 37777, and Hikvision'sIngram DahuaConsoleattempts the bypasses over HTTP; on success it shells out to a locally-held copy of the public Ingram DahuaConsole toolkit; only if both fail does it drop to a sixteen-pair default-credential brute. Its keyspacemasscan2026, a single operator compromised over 14,000 Dahua IP cameras. The scanning behind it was global: masscan sweeps ran against Russian address space first, then across the full IPv4 range, and the largest singlescannerdahuaThe scannerdahua ToolkitShodansn/_pipeline_runner.py, hard-codes TARGET_HITS = 5 and MAX_ROUNDS = 20, importing the prefix-ranking and Shodan-harvest modules directly. Each round widens the candidate window by 2,000 from a base offset of 8,000
Countries
MexicoRussiaand CIS telecom netblocks. Where the confirmed, geolocated compromises concentrated was Ukraine and Russia, with Ukraine holding the largest share.Ukraineon Russian and CIS telecom netblocks. Where the confirmed, geolocated compromises concentrated was Ukraine and Russia, with Ukraine holding the largest share.Vietnam