Operation CameraSwarm Compromised More Than 14,500 Dahua Cameras, Hunt.io Finds

· Original article ↗

Summary

Hunt.io says an operator compromised more than 14,530 Dahua devices in 35 days using credential brute force, authentication bypasses and serial-based P2P relay access, leaving 1,923 cameras with a persistent backdoor.

Key points

  • Hunt.io traced more than 14,530 compromised devices to a 35-day campaign; confirmed compromises were concentrated in Ukraine and Russia, although scanning was global.
  • The operator combined credential brute force against TCP/37777, unauthenticated CVE-2021-33044 and CVE-2021-33045 bypasses, and Dahua’s P2P relay, which can reach cameras by serial number; 283 cameras were reached through the relay.
  • The p2pwn tool installed the p2pwn / p2password account on 1,923 cameras. The account can survive password changes and, on most firmware, factory resets.
  • The toolkit generated offline Dahua recovery codes that could enable administrative password resets. Hunt.io says updating firmware prevents new codes and eventually invalidates previously issued ones.
  • A separate UPX-packed Windows binary, assessed as likely SalatStealer, and a script designed to add Microsoft Defender exclusions were found on the operator’s host; the report treats this as a distinct capability.
  • Hunt.io recommends auditing cameras for the backdoor account, removing it and rotating stored credentials, disabling P2P if unneeded, applying Dahua’s security fixes and keeping firmware updated. It also advises preventing external access to port 37777.

Article Details

Attack Vectors
  • The operator scanned TCP/37777, then used a high-concurrency credential-guessing engine against Dahua's Easy4IP management protocol.
  • p2pwn used CVE-2021-33044 and CVE-2021-33045 authentication bypasses to obtain administrator sessions without a working password, then installed a persistent local account over RPC.
  • Serial-number harvesting and Dahua's cloud relay gave the operator a path to cameras behind NAT. The relay path did not itself guarantee device control; the toolkit also used credentials or authentication bypasses.
  • A separate tool generated device recovery codes offline from verified live serial numbers, creating an administrative-reset risk independent of device credentials.
  • A Windows binary tagged by a sandbox as SalatStealer was staged alongside a PowerShell script designed to create Defender exclusions. The malware-family assessment was not independently confirmed.
Defensive Notes
  • Audit Dahua camera accounts for p2pwn, remove it, and rotate stored credentials that may have been drained.
  • Disable camera P2P where it is not needed; blocking individual relay addresses is not a reliable control.
  • Apply Dahua SA-2021-0130, update camera firmware, and prevent external access to TCP/37777. Dahua states that updated firmware prevents generation of valid new recovery codes and that previously issued codes are eventually invalidated.
  • Investigate login requests containing clientType NetKeyboard or loginType Loopback with ipAddr 127.0.0.1.
  • On Windows systems, monitor for volume-wide Defender exclusions, CIM calls against MSFT_MpPreference, and unexpected policy refreshes. Do not treat the cloned rbc.ru certificate as evidence that RBC or Qrator was compromised.

Indicators of compromise

TypeIndicatorContext
IPV4154[.]86[.]119[.]60Operator server used for scanning and payload staging; its open directory exposed the working environment.
IPV4185[.]132[.]53[.]56Second host where the identical staged Windows payload was observed; the report assesses a brief takeover with moderate confidence.
SHA256083c9ee06ed2ee1bc0051358b3eeb3242f474eacea4c88b3b10b06d15389b753Hash of the operator's partially rewritten serial brute-forcer script.
SHA2564a4a346df72c839272ea835e4717cd88f843333b3563e745e657895347ea3dbeHash of the active launcher for parallel serial-number probing.
SHA2565f60e5b45ecd67a987bdb1173d6a8063aa20a7946377da4698aaba3ebe72d088Hash of the fully Russified serial brute-forcer script recovered from the operator server.
SHA256694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8Hash of the operator's compiled p2pwn Go ELF.
SHA2567a963211a052a78899a8881d36b42b55690c02e95c1485f5d78d3cfdb3d2842aHash of the original serial brute-forcer script recovered from the operator server.
SHA256be2738c8a2beb55ac484d71c329381f3caabac80664283ad9a24dbab82b5b590Hash of the operator's p2pwn source archive.
SHA256cba28f2b4f12cd3f0a222a3885bef70518872c0ca62798dc810b8caa3035cca7SSH host-key fingerprint observed on the operator server during its Debian 13 period, beginning in the campaign.
SHA256de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090cHash of the staged 1.exe / xeno.exe Windows binary, tagged as SalatStealer by a sandbox.

MITRE ATT&CK

CVE

Malware

Vendors

Products

Tools

Countries

Related Articles