A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports.
The activity, referred to as Operation CameraSwarm, occurred between June 17 and July 22. It initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges, but later focused on Russian and CIS telecom netblocks.
Hunt.io says it gained access to the threat actor’s servers, where it found 2,616 files across 234 subdirectories, or approximately 407 MB of data, left in an open HTTP directory that the hackers exposed themselves.
Analysis of the data revealed the compromise of over 14,530 devices within the 35-day-long campaign. A brute-force engine was used to target 12,324 unique addresses.
The threat actor deployed a persistent backdoor account on 1,923 cameras over Remote Procedure Call (RPC). The account uses the p2pwn/p2password username and password pair.







