top of page

CameraSwarm campaign warning: Over 14,500 security cameras compromised

Surveillance cameras were originally designed to protect assets, but what happens when they turn into a gateway for malicious actors to infiltrate internal systems? Recently, a sophisticated cyberattack campaign named CameraSwarm was uncovered, revealing that tens of thousands of Dahua smart cameras (IP cameras) were compromised in a short period of time. This incident serves as a stark wake-up call for all businesses regarding fatal vulnerabilities in technology device management.

How dangerous is the CameraSwarm campaign?

According to a report by the security research firm Hunt.io, the CameraSwarm campaign took place from mid-June to late July 2026. Rather than relying on a single tactic, the hacker group launched a series of automated attacks to manipulate more than 14,500 cameras. Initially, they primarily targeted telecommunications networks in Russia before rapidly expanding their scans to systems worldwide.

cameraswarm-campaign-overview
Overview of the CameraSwarm campaign (Source: Hunt.io)

Experts gathered approximately 407 MB of data from the perpetrators' systems, including malicious source code, activity logs, and stolen login credentials. Most concerningly, after gaining control of the devices, the hackers were able to view live surveillance feeds and covertly exfiltrate this sensitive data via the Telegram messaging app.

Three main methods used to knock out tens of thousands of cameras

To easily gain control of the systems, the attackers targeted three core vulnerabilities commonly found in enterprise camera infrastructure:

First, the habit of using weak passwords. By deploying automated password-guessing (brute-force) software to scan common connection ports on Dahua devices (TCP port 37777), attackers easily gained access because many organizations still use default or overly predictable login credentials.

Second, exploiting software vulnerabilities to plant a backdoor. By leveraging long-standing vulnerabilities, attackers created a hidden account named "p2pwn." This account exhibits extraordinary persistence, taking deep root in the system to the extent that even if administrators change passwords or perform a factory reset, it can still persist, allowing attackers to regain access at any time.

Third, manipulating cloud features. Even if an enterprise's cameras are not directly exposed to the internet and are protected behind an internal network layer (NAT), attackers can still reach them. They exploit device serial numbers and cloud connectivity features to generate entirely new password recovery tokens without needing to know the current password.

series-of-attack
A series of attacks took down the camera system (Source: Hunt.io)

Solutions to protect enterprise surveillance camera systems

Given the sophisticated methods employed in the CameraSwarm campaign, resolving the issue is not as simple as merely changing a password. To safeguard data, enterprises must immediately implement more comprehensive measures:

  • Audit and purge systems: Administrators must thoroughly audit the active user account list on camera systems. If the "p2pwn" account is discovered, it must be disabled immediately. However, Hunt.io warns that this alone may not fully eliminate the threat, as previously generated recovery tokens may still remain valid.

  • Disable unnecessary features: Immediately turn off peer-to-peer (P2P) connection features if the enterprise does not genuinely require them. Additionally, minimize direct internet exposure for surveillance devices as much as possible.

  • Update operating systems (firmware): This is a mandatory step. Businesses must promptly install updates from the manufacturer (such as patch SA-2021-0130) to seal software vulnerabilities currently being exploited by hackers.

In summary, a surveillance camera is not merely an isolated video recording device; it must be treated as a critical link in the overall information technology security architecture. Do not let a device designed to protect security become the fatal vulnerability that exposes enterprise data to cyberspace.

Refer to: Tạp chí An toàn thông tin (Information Security Magazine)

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page