Hackers took over more than 14,500 Dahua internet-connected cameras in a month-long campaign, with most confirmed victims in Ukraine and Russia. Hunt.io says the attackers combined brute-force attacks on port 37777, exploitation of Dahua flaws CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua's password-recovery flow using serial numbers and embedded SDK credentials to reach even some cameras behind network address translation (NAT). The toolkit planted a persistent backdoor account named p2pwn that can survive password changes and often factory resets.
Why it matters: This is a large active compromise of surveillance devices that could let attackers watch camera feeds and keep access even after basic cleanup. Organizations and consumers using Dahua cameras should urgently check for the p2pwn account, disable peer-to-peer access if not needed, and apply Dahua firmware from advisory SA-2021-0130 or later.
Ionut Arghire
2026.08.20
98% relevant
This is the same underlying CameraSwarm event and adds reporting details on timeline, targeting focus on Russian and CIS telecom netblocks, the p2pwn/p2password persistent backdoor account, brute-force and cloud-relay abuse, and the chained Dahua flaws used for unauthenticated admin access.
Bill Toulas
2026.08.19
100% relevant
This article appears to be the first concrete report establishing the CameraSwarm operation, including scope, attack methods, affected vendor, and mitigation guidance.
← Back to all stories