Large-scale intrusion targets Dahua cameras via credential attacks and P2P exploits

A new campaign dubbed CameraSwarm has compromised over 14,500 Dahua surveillance devices using brute-force, known vulnerabilities, and peer-to-peer relay abuse, highlighting emerging risks in remote device management.

Hunt.io has detailed a large-scale intrusion campaign against Dahua surveillance equipment that, over 35 days, appears to have compromised at least 14,530 IP cameras and related devices. The operation, which the company dubbed CameraSwarm, combined brute-force attacks, exploitation of known authentication-bypass flaws and abuse of Dahua’s own peer-to-peer relay infrastructure, according to the research. The activity ran from 17 June to 22 July 2026, with the strongest concentration of victim devices in Ukraine and Russia. According to Hunt.io, the campaign shows how quickly internet-exposed video-security systems can become a remote attack surface when passwords are weak and firmware is not kept current. Hunt.io said it reconstructed the operation after finding an unsecured HTTP directory tied to the suspected operator, which exposed a large collection of logs, tooling, credentials and camera data.

The largest part of the intrusion effort targeted devices listening on Dahua’s proprietary management port. Hunt.io said the operator tried credentials against 12,324 unique IP addresses and then collected accessible snapshots and exported results for use with Dahua’s SMART PSS management software. That approach is consistent with the long-standing problem of reused and default administrator passwords on surveillance equipment. The researchers also identified exploitation of CVE-2021-33044 and CVE-2021-33045, two authentication-bypass vulnerabilities first disclosed in 2021. Those flaws have remained serious enough to stay on the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities list, which is intended to help defenders prioritise issues already seen in real-world attacks.

A third access path involved Dahua’s peer-to-peer cloud relay feature, which can expose devices even when they sit behind network address translation. Hunt.io said the operator used device serial numbers and embedded SDK credentials from Dahua applications to reach 283 cameras that were not directly visible on the public internet. The firm linked the activity to a tool called p2pwn, which created a persistent account on 1,923 devices and could survive password changes, and in many firmware versions even factory resets. That persistence matters: it means an administrator may believe a device has been cleaned when attacker access still remains. Hunt.io also said its recovered material suggested a very high proportion of live serial numbers tested by the operator returned an unauthenticated open channel, although the company stressed that this was a campaign-specific finding rather than an independently reproduced benchmark.

Dahua has issued repair software and updated firmware for affected products. In a statement reflected in Hunt.io’s report, the vendor said the methods involved were mainly password cracking and the two previously disclosed vulnerabilities, and recommended strong unique passwords, prompt firmware updates, monitoring of its security advisories and a full factory reset where appropriate. For organisations running Dahua cameras or OEM-rebranded devices, the practical response is to inventory anything exposed on port 37777, check for unauthorised accounts, look specifically for p2pwn access, rotate administrator credentials and review camera and NVR logs for abnormal sessions. Security teams should also disable peer-to-peer connectivity where it is not required and segment surveillance networks from corporate systems, because, as Hunt.io’s analysis makes clear, cloud-assisted device management can defeat the assumption that NAT alone provides protection.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.