Research details toolkits targeting Ukrainian IP cameras and routers

Summary
Hunt.io analyzed two exposed directories documenting credential theft, SQL injection, camera and router exploitation, and proxy tooling. One cataloged 58 compromised Ukrainian cameras; government and military attacks and exploitation by the second operation were unして
Key points
- An exposed server contained evidence of a Ukrainian e-commerce site compromise through credential theft and SQL injection; a captured admin session confirmed access to its backend.
- The operator used the compromised site as a proxy and recorded attempts against Ukrainian government and military websites, but the recovered files do not confirm those attempts succeeded.
- A camera toolkit cataloged 58 compromised Ukrainian cameras and logs showed live viewing sessions. It used known Dahua and Hikvision vulnerabilities and weak-credential checks.
- A second, separately operated server contained scripts targeting cameras and routers across 15 European countries, including tools to turn compromised devices into SOCKS5 proxies; successful exploitation was not confirmed.
- The investigation found no evidence tying either operation to a state actor or named group, and no evidence of extracted e-commerce database records.
- Hunt.io recommends strong unique passwords, current firmware, restricting internet exposure of cameras and routers, and monitoring for scanning and suspicious outbound tunnels.
Article Details
- Attack Vectors
- The first operator used credential theft and SQL injection against a Ukrainian OpenCart site, then used administrative access and a captured session cookie to reach its backend.
- A Python HTTP proxy routed the first operator's traffic through the compromised e-commerce server. Recovered shell history shows the relay was used for further scanning and attempted exploitation.
- Tor-routed attempts against Ukrainian council sites included credential guessing, SQL injection, and attempted WordPress web-shell deployment. The recovered files do not confirm success.
- The first operator scanned exposed Ukrainian cameras, tested weak credentials and known vulnerabilities, and maintained a catalog of 58 compromised cameras.
- The second operator's scripts attempted to compromise exposed cameras and routers, enable SOCKS5 proxies, and connect them to a chisel reverse-tunnel listener. Researchers found no signs of successful exploitation in the second directory.
- Defensive Notes
- Replace default or weak camera and router credentials with strong, unique passwords.
- Apply current firmware to Hikvision and Dahua cameras and patch TP-Link Archer and MikroTik devices; disable remote administration where unnecessary.
- Keep cameras and routers off the public internet, using a VPN or isolated VLANs instead of exposed ports or UPnP.
- Disable ONVIF and unauthenticated RTSP when not required.
- Monitor network-boundary traffic for repeated camera-port connections, sequential ONVIF or RTSP discovery, and credential-guessing attempts.
- Alert on unexpected outbound tunnels from edge devices, including connections to port 4444.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 213[.]165[.]63[.]49 | Separately operated server exposing router and camera scanning and exploitation files on port 8080. |
| IPV4 | 89[.]208[.]97[.]165 | First operator's server, which exposed an open directory of intrusion scripts, shell history, and the camview archive on port 8888. |
MITRE ATT&CK
T1005 · Data from Local SystemThe first operator's files included a catalog of compromised camera details and a saved still from a camera.T1090 · ProxyThe first operator proxied traffic through a compromised e-commerce server; the second operator's scripts attempted to turn edge devices into SOCKS5 proxies.T1110 · Brute ForceThe tooling guessed camera and router credentials, including against the MikroTik router API.T1110.003 · Password SprayingThe first operator used per-target credential lists in password-spray attempts against Ukrainian government and military sites.T1125 · Video CaptureThe first operator opened live feeds from compromised cameras and logged viewing-session lengths, frame counts, and frame rates.T1133 · External Remote ServicesThe second operator targeted reachable router management interfaces, including the MikroTik API, for remote access.T1190 · Exploit Public-Facing ApplicationThe first operator used SQL injection against an OpenCart endpoint; both directories also contained tooling to test vulnerabilities in internet-exposed cameras or routers.T1550.004 · Web Session CookieRecovered HTML files set a captured OpenCart OCSESSID cookie so the first operator could return to the compromised administrative backend.T1571 · Non-Standard PortThe second operator's proxy tooling reported to a chisel reverse-tunnel listener on port 4444.T1572 · Protocol TunnelingThe second operator's scripts attempted to establish chisel reverse tunnels from compromised edge devices to the operator's server.T1595.002 · Vulnerability ScanningIngram and custom scripts scanned IP ranges for exposed cameras and routers and tested known vulnerabilities.
CVE
CVE-2017-7921T1190Exploit Public-Facing ApplicationCamera CVEs (CVE-2017-7921, CVE-2021-36260, CVE-2021-33044/33045) and TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) staged for exploitationCVE-2020-25078CVE-2020-25169CVE-2021-33044CVE-2021-33044 / 33045DahuaAuthentication bypass (passwordless login)CVE-2021-33045CVE-2021-36260T1190Exploit Public-Facing ApplicationCamera CVEs (CVE-2017-7921, CVE-2021-36260, CVE-2021-33044/33045) and TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) staged for exploitationCVE-2024-53375CVE-2024-53375 - Authenticated command injection (RCE)CVE-2024-57049CVE-2024-57049 - Chained with 2024-53375 in a script titled archerpwn.py
Vendors
Aeza Group LLCThe server at 89.208.97[.]165 exposed 120 files across 31 subdirectories on port 8888, hosted by Aeza Group LLC (AS210644). Attack Capture flagged it as a malicious open directory on May 30, 2026. In addition to theAsuslocate exposed devices and write the results to a text file. The code queried the service for TP-Link and Asus routers across 15 European countries:D-Linkcameras and tests them against a set of known CVE's and weak credential checks across Hikvision, Dahua, D-Link, and other vendors.DahuaThe same server hosted a Docker project named "camview" in its archive, used to scan, exploit, and maintain a list of internet-exposed cameras using known Dahua and Hikvision vulnerabilities.HikvisionThe same server hosted a Docker project named "camview" in its archive, used to scan, exploit, and maintain a list of internet-exposed cameras using known Dahua and Hikvision vulnerabilities.MikroTikat 213.165.63[.]49. That server ran a similar style of scanning and exploitation against TP-Link and MikroTik routers and cameras across 15 European countries, with a focus on Odessa, Burshtyn, and Kherson.ReolinksistemaltdAttack Capture discovered an open directory on 213.165.63[.]49 hosted on sistemaltd (AS215540) in Latvia, on July 21, 2026. The exposed server consisted of 1,704 files across 505 subdirectories, totaling 761 MB. TheTP-Linkrun directory at 213.165.63[.]49. That server ran a similar style of scanning and exploitation against TP-Link and MikroTik routers and cameras across 15 European countries, with a focus on Odessa, Burshtyn, and
Products
OpenCartpaths against the site using the AutoPwn suite, then directed error and UNION-based SQL injection at the OpenCart product search endpoint. The code simultaneously also checked for exposed .env and configuration files.SmartPSSA file titled 'kramatorsk_snaps.html' appears to be a test run against SmartPSS (Smart Professional Surveillance System) run-devices. The IP addresses above each feed geo-locate to Russia and Kazakhstan, not Ukraine,TP-Link ArcherThe directory contained numerous scripts targeting cameras, MikroTik devices, TP-Link Archer routers and generic router brands. A pattern repeated itself across the codebases: compromise the device, enable a SOCKS5WordPressdomains, the websites of local Ukrainian settlement and village councils, the majority running WordPress. The attempted attacks targeted the WordPress XML-RPC interface and REST API, with a desired end goal of
Tools
archerpwn.pyCVE-2024-57049 - Chained with 2024-53375 in a script titled archerpwn.pyAutoPwnOne of the main scripts enumerated common administrative paths against the site using the AutoPwn suite, then directed error and UNION-based SQL injection at the OpenCart product search endpoint. The code simultaneouslycamviewThe same server hosted a Docker project named "camview" in its archive, used to scan, exploit, and maintain a list of internet-exposed cameras using known Dahua and Hikvision vulnerabilities.camworm.pyFilenames like camworm.py and routerworm.py found on the server follow the same exploitation > proxy attempt described above, and contain no worm functionality.Chiselacross the codebases: compromise the device, enable a SOCKS5 proxy on it, and report the result back to a chisel reverse-tunnel listener on the server's port at 4444. The operator's objective is a pool of SOCKS5IngramIngram: The Open-Source Scanner Behind camviewmasscanFastAPI and served by Uvicorn, it is packaged as a container running Python 3.11 with FFmpeg, Nmap, and masscan built into the image. FFmpeg transcodes the camera's RTSP feed to MJPEG for display, while Nmap andNmapBuilt with FastAPI and served by Uvicorn, it is packaged as a container running Python 3.11 with FFmpeg, Nmap, and masscan built into the image. FFmpeg transcodes the camera's RTSP feed to MJPEG for display, while Nmapproxy_access.pyFigure 02: Redacted code snippet from proxy_access.py, using the compromised network to further attacks.The script also included fallback logic in case the session expired, giving the operator persistent access. Therouterworm.pyFilenames like camworm.py and routerworm.py found on the server follow the same exploitation > proxy attempt described above, and contain no worm functionality.Seleniumsnippet showing Tor-routed reconnaissance against a Ukrainian government domain, including a Selenium headless-browser.The table below summarizes the government and military targeting recorded in thesqlmapoperator cycled through a broad range of SQL injection techniques against the endpoint before turning to sqlmap. The small number of commands against the panel points to manual, hands-on iteration rather than ansysrfxcontained multiple OSINT scripts built on identifying Ukrainian personal data. Internally versioned as sysrfx v4.2.1, the code contains a header comment reading: ÐÐÐÐ ÐÐÐРУÐÐ ÐÐÐÐ - ÐСÐÐÐÐÐÐTorThe same server's bash history records Tor-routed intrusion attempts against Ukrainian government and military sites, built with per-target credential lists, though the recovered files do not confirm whether any attemptvps_mon.shA bash script designed to run on the server, vps_mon.sh parses incoming web traffic for four parameters: role, user_id, view_mode, and active_drone_type. The role values are then mapped to categories of drone operators:
Countries
AustriaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.BulgariaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.CzechiaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.FranceUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.GermanyUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.HungaryUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.ItalyUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.KazakhstanSurveillance System) run-devices. The IP addresses above each feed geo-locate to Russia and Kazakhstan, not Ukraine, which reads as a test run against whatever devices were reachable rather than liveLatviaAttack Capture discovered an open directory on 213.165.63[.]49 hosted on sistemaltd (AS215540) in Latvia, on July 21, 2026. The exposed server consisted of 1,704 files across 505 subdirectories, totaling 761 MB. TheMoldovaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.NetherlandsUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.PolandUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.RomaniaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.RussiaAeza Group is a Russia-based bulletproof host sanctioned by OFAC in July 2025, with AS210644 named in that designation.SlovakiaUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.SpainUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.Ukrainerecent AIVD and MIVD advisory on Russian actors compromising IP cameras across the EU, NATO states, and Ukraine. Neither directory is linked to a state actor or any named group, but the recovered files offer aUnited KingdomUkraine, Poland, Romania, Moldova, Hungary, Czechia, Slovakia, Bulgaria, Germany, France, Netherlands, Italy, Spain, United Kingdom, and Austria.
Industries
E-commerceThe affected e-commerce operator was notified via CERT-UA.Governmentproxy server, and then used password spray attacks and attempted web shell deployment against Ukrainian government and military sites. During our investigation, we identified a custom platform built to find, exploit,Militaryand then used password spray attacks and attempted web shell deployment against Ukrainian government and military sites. During our investigation, we identified a custom platform built to find, exploit, and catalog