In a sophisticated and prolonged cyber operation, threat actors successfully compromised more than 14,500 Dahua IP cameras over a 35-day period, a campaign researchers have designated "CameraSwarm." The majority of these compromised devices were located in Ukraine and Russia, highlighting a significant regional concentration of the attack. The campaign, which ran from June 17 to July 22, employed a multi-pronged approach to gain unauthorized access, utilizing a combination of exploiting known vulnerabilities, brute-forcing login credentials, and a particularly concerning method involving the exploitation of offline recovery codes derived from camera serial numbers for cloud-registered devices.
The discovery of this widespread breach was made by researchers at the threat intelligence company Hunt.io. Their investigation was triggered by the serendipitous finding of an unprotected working directory on an HTTP server, which appeared to be operated by the perpetrators of the campaign. This unsecured server provided Hunt.io with a critical window into the operation, leading to the recovery of a substantial trove of data.
Uncovering the Scope of the Attack
The recovered data, totaling 407 megabytes and comprising 2,616 files spread across 234 directories, offered a comprehensive view of the CameraSwarm operation. This data included sensitive information such as source code for the attack tools, operational logs, captured credentials, photographic evidence from compromised cameras, shell history detailing command execution, and the results of their exploitation efforts. This wealth of information allowed Hunt.io to meticulously map the campaign’s impressive scale and technical sophistication.

The analysis revealed that the 35-day CameraSwarm campaign systematically targeted and compromised 14,530 Dahua IP cameras. The attackers employed three distinct methods in parallel to achieve their objectives, demonstrating a well-resourced and strategic approach.
The Technical Arsenal of CameraSwarm
One of the most alarming techniques identified in the CameraSwarm toolkit was the exploitation of Dahua’s password recovery mechanism. This method ingeniously leveraged the camera’s serial number to generate new recovery codes. By doing so, the CameraSwarm operator could bypass the need for the current administrative password and effectively redeem new credentials through Dahua’s legitimate password-recovery process. This approach highlights a critical vulnerability in how cloud-registered devices handle recovery processes, potentially leaving many users exposed if their serial numbers become known.
While the campaign utilized several attack vectors, researchers noted the presence of two misleading vulnerability references within the toolkit: CVE-2024-39943 and CVE-2025-31702. Importantly, Hunt.io’s analysis confirmed that these specific CVEs were not exploited in the observed attacks, suggesting they may have been included for misdirection or as part of a broader, unexecuted exploitation strategy.
The observed attack chain, as detailed by Hunt.io, illustrates a methodical progression from initial reconnaissance to full system compromise. This chain likely involved initial scanning to identify vulnerable devices, followed by attempts to exploit weak credentials or recovery mechanisms, and finally, the establishment of persistent access through backdoor accounts.

Geographic Focus and Operational Footprint
Hunt.io’s extensive analysis revealed that the scanning efforts for the CameraSwarm campaign were global in scope. The initial phase involved a concentrated effort to scan the Russian address space, followed by a broader sweep of the entire IPv4 range. However, the researchers observed a clear strategic focus on Russian and CIS (Commonwealth of Independent States) telecom network blocks. This geographic concentration suggests a potential motive tied to surveillance or intelligence gathering within these regions.
Further evidence supporting this regional focus was found in modified code snippets within repurposed public tools used by the attackers. These code modifications contained Russian comments, strongly indicating the nationality or primary operational language of the threat actors.
Timeline of the CameraSwarm Campaign
- June 17, 2024: The CameraSwarm campaign commences, initiating its multi-faceted attack on Dahua IP cameras.
- June 17 – July 22, 2024: Over a period of 35 days, the campaign actively compromises an estimated 14,530 Dahua IP cameras through various exploitation techniques.
- Undisclosed Date (Post-July 22): Hunt.io researchers discover an unprotected working directory on an HTTP server, leading to the identification of the CameraSwarm operation.
- Undisclosed Date (Post-Discovery): Hunt.io recovers a significant volume of data, including source code, logs, and credentials, enabling a detailed analysis of the campaign.
- August 10, 2024: Hunt.io formally notifies national Computer Emergency Response Teams (CERTs) and Dahua’s Product Security Incident Response Team (PSIRT) about the CameraSwarm campaign, sharing their findings and urging immediate action.
Official Responses and Mitigation Strategies
Following the discovery and analysis by Hunt.io, the threat intelligence firm took proactive steps to inform relevant authorities. On August 10, 2024, Hunt.io officially notified national CERTs and Dahua’s PSIRT about the CameraSwarm campaign. This crucial step aims to facilitate coordinated responses and the dissemination of critical security advisories to affected parties.
Dahua cameras that were accessible via port 37777 between June and July of 2024 should be considered potentially compromised. Owners of such devices are strongly advised to conduct immediate security audits. A key indicator of compromise is the presence of a "p2pwn" account, which attackers are believed to have created to maintain persistent access. The removal of this backdoor account is a critical first step in securing affected devices.

However, Hunt.io offers a significant warning: simply removing the backdoor account does not negate the threat posed by the generated recovery codes. These codes, once created through the exploit, can remain usable until Dahua makes server-side modifications to their recovery code derivation process. This underscores the ongoing risk even after immediate remediation steps are taken.
In light of these findings, Dahua users are strongly encouraged to implement several security best practices:
- Disable P2P Functionality: When not essential for operation, the Peer-to-Peer (P2P) connectivity feature on Dahua cameras should be disabled. This reduces the attack surface and limits potential avenues for exploitation.
- Apply Firmware Updates: Users should ensure their Dahua cameras are running the latest firmware. Specifically, applying the Dahua SA-2021-0130 firmware update, which addresses vulnerabilities CVE-2021-33044 and CVE-2021-33045, or any subsequent firmware versions, is critical. These updates are designed to patch known weaknesses exploited by threat actors.
Broader Implications and Future Concerns
The CameraSwarm operation serves as a stark reminder of the persistent threats facing the Internet of Things (IoT) ecosystem, particularly in the realm of surveillance and security devices. Dahua, as a major global manufacturer of video surveillance products, is a significant target for cybercriminals. The sophisticated methods employed in this campaign, including the exploitation of recovery codes, highlight the need for continuous vigilance and proactive security measures from both manufacturers and end-users.
The fact that the campaign was able to compromise such a large number of devices suggests potential systemic issues in the security posture of connected cameras, including weak default credentials, unpatched vulnerabilities, and insecure recovery mechanisms. The concentration of attacks in Ukraine and Russia could indicate a nation-state actor or a group with specific geopolitical interests in those regions, although this remains speculative without further intelligence.

The long duration of the campaign (35 days) and the parallel use of multiple attack vectors indicate a well-planned and executed operation. The recovery of source code and logs provides invaluable intelligence for cybersecurity professionals, allowing for a deeper understanding of attacker methodologies and the development of more effective defense strategies.
The ongoing reliance on serial numbers for recovery processes, especially when coupled with the potential for brute-force attacks or leaked serial number databases, presents a persistent vulnerability. Manufacturers must prioritize robust security features, including multi-factor authentication, secure default configurations, and resilient recovery mechanisms that are not easily exploitable.
For end-users, the lesson is clear: maintaining updated firmware, employing strong, unique passwords, and understanding the security settings of their devices are paramount. The compromise of security cameras can lead to severe privacy violations, potential espionage, and the use of these devices as pivot points for larger network intrusions. The CameraSwarm incident underscores the critical need for ongoing security research, rapid vendor response, and heightened user awareness in the ever-evolving landscape of cyber threats.








