started · updated
Dahua security cameras targeted in massive CameraSwarm hack
Security researchers from Hunt.io have uncovered a large-scale cyberattack, dubbed ‘CameraSwarm’, targeting more than 14,500 Dahua security cameras. The campaign, which took place between mid-June and late July 2026, utilized multiple exploitation methods to gain unauthorized access and add attacker-controlled accounts to the devices.
The attackers employed three primary vectors: automated brute-force attacks on port 37777, exploitation of older vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a more sophisticated method involving Dahua’s own cloud-relay service. In the latter case, attackers were able to access 283 cameras using only their serial numbers, bypassing the need for public IP addresses or credentials. This P2P mechanism allowed access even to cameras protected behind routers.
While the highest concentration of compromised devices was identified in Ukraine and Russia, the vulnerability affects Dahua products sold globally, including in Slovakia. Researchers were able to reconstruct the operation after discovering an unsecured server belonging to the attackers that contained tools, credentials, and command histories.
Entities
Dahua · Hunt.io · ITRES Labs