A 35-day cyber campaign named Operation CameraSwarm compromised over 14,500 Dahua surveillance devices worldwide, exposing critical vulnerabilities in public and private CCTV networks.

Operation CameraSwarm: 14,500+ Dahua Surveillance Cameras Compromised in Global Cyber Campaign

The420 Web Correspondent
6 Min Read

A massive cyber campaign codenamed Operation CameraSwarm has compromised more than 14,500 internet-connected surveillance devices globally, exposing severe vulnerabilities in widespread video security infrastructure. Uncovered by cybersecurity researchers at Hunt.io, the 35-day operation systematically breached Dahua cameras and network video recorders between June and July 2026. The incident underlines an escalating threat to physical and digital perimeter security, as hostile actors turn routine surveillance hardware into persistent intelligence-gathering endpoints.

The extensive campaign came to light after security analysts discovered a 407-megabyte exposed working directory hosted on an open web server belonging to the attacker. The recovered corpus contained over 2,600 files detailing automated scan logs, custom exploitation scripts, and target databases. While mass scanning swept global internet address spaces, confirmed compromises heavily concentrated within telecom netblocks across Eastern Europe, highlighting how edge devices are weaponised at scale.

For India, where municipal corporations, public transit systems, and commercial enterprises rely extensively on Chinese original equipment manufacturer hardware, the exposure serves as a stark warning. With Lakhs of connected cameras deployed across national Smart Cities projects and critical infrastructure sites, unpatched video equipment represents a vulnerable back door into enterprise networks.

Tripartite Exploitation and Persistent Backdoors

The threat actor executed a highly coordinated three-pronged attack strategy to maximize device takeover without raising immediate security alarms. The primary vector relied on automated brute-force credential engines, which successfully breached over 12,000 devices using default or weak passwords. This high-volume automated probing allowed the operator to establish initial footholds across thousands of enterprise and residential networks worldwide.

Concurrently, the attacker weaponised legacy authentication-bypass vulnerabilities, specifically CVE-2021-33044 and CVE-2021-33045, to compromise nearly 2,000 additional endpoints. Upon gaining administrative access through these flaws, the actor executed remote procedure calls to install a persistent backdoor account. Stored independently of standard administrator credentials, this hidden profile survives routine password changes and factory resets on most firmware versions, granting permanent unauthorized access.

The third and most technical vector exploited Dahua’s proprietary peer-to-peer cloud relay protocol, Easy4IP, to bypass firewalls and network address translation barriers. By querying cloud servers using device serial numbers alone, the attacker established direct communication tunnels to hundreds of cameras without requiring prior authentication. Security logs revealed that nearly nine out of ten targeted cloud relays granted full administrative access upon connection.

Systemic Risks Across Indian Infrastructure

The compromise of internet-of-things surveillance hardware introduces profound physical and economic risks for Indian institutions. Surveillance cameras operating within corporate headquarters, manufacturing plants, and financial institutions frequently process sensitive operational footage while remaining connected to internal local area networks. Once compromised, these edge devices can be repurposed as stealthy jump hosts to pivot deeper into protected corporate environments.

The Union Government has repeatedly cautioned administrative bodies and public sector undertakings against deploying unvetted foreign hardware across sensitive government installations. Despite regulatory guidelines issued by the Ministry of Electronics and Information Technology, legacy video hardware across local municipal offices and private housing societies often remains unpatched for years. The ability of hostile actors to silently view live feeds or recruit devices into massive distributed denial-of-service botnets poses an ongoing national security concern.

Furthermore, language artifacts recovered from the operator’s staging server indicate the involvement of Russian-speaking actors utilizing modular, assembled toolkits. The open accessibility of offline recovery codes within the attacker’s directory strongly suggests the infrastructure was designed to monetize or transfer physical access to third-party buyers, elevating the threat from routine vandalism to state-aligned espionage.

Defensive Protocols and Network Segmentation

In response to the disclosure, cybersecurity authorities and emergency response teams are urging infrastructure operators to audit all connected video surveillance assets immediately. Dahua’s product security incident response team has released updated firmware versions to patch legacy authentication vulnerabilities, advising administrators to apply software updates immediately.

To mitigate cloud-based relay exploitation, enterprise security teams are strongly advised to disable peer-to-peer functionality across all camera networks unless strictly necessary for remote operations. Disabling automated cloud lookup protocols prevents external actors from locating devices behind network firewalls using static serial numbers. Administrators must also audit internal user registries to identify and remove unauthorized backdoor accounts installed during automated compromise waves.

The Central Government’s national cybersecurity guidelines continue to advocate for strict physical and logical network segmentation. Isolating video surveillance systems on dedicated virtual local area networks prevents compromised cameras from communicating with sensitive internal servers. As edge hardware becomes a primary target for global cyber syndicates, continuous behavioral monitoring and hardware-level access controls remain essential safeguards for maintaining sovereign digital security.

Stay Connected