CameraSwarm: 14,500 cameras taken over, most of them in Ukraine
Over thirty-five days one operator compromised more than fourteen thousand Dahua surveillance cameras, door intercoms and video recorders, installed permanent backdoor accounts and sent the captured images out through Telegram.
The largest concentration of hijacked devices was in Ukraine, with Russia and other former Soviet networks next. The firm that found it assesses, at moderate confidence, that the access was being built to hand to somebody else.
↓ Download one-page brief (PDF)Scanning, then a decision about where to work
The operator scans broadly, touching Mexican and Vietnamese provider ranges, before concentrating the effort on Russian and other former Soviet networks. The geography of the campaign is a choice made early and then held.
Four ways in, used together
Brute-forcing from more than twelve thousand source addresses accounts for most of it. Two authentication-bypass vulnerabilities published in 2021 account for 1,923 cameras. The manufacturer's own cloud relay, which needs only a serial number, accounts for 283 more.
The access is made permanent
Backdoor accounts are installed on the devices so that access survives a password change, and management at scale is attempted through the manufacturer's own administration platform. This is the step that turns a compromise into infrastructure.
The pictures go to Telegram
Captured snapshots are exfiltrated through Telegram, which requires no attacker-controlled server and looks like ordinary traffic on most networks.
Disclosure, and an unanswered question
National response teams and the manufacturer are notified on 10 August and the research is published on 18 August. Who the access was being assembled for is not established, and on Hunt.io's own assessment that question is the significant one.
Installed once and forgotten
Surveillance cameras are fitted by an installer, connected to the internet for remote viewing and then left. They are rarely patched, frequently keep their default credentials, and almost never appear on an asset register maintained by anyone with security responsibility.
The vulnerabilities used here
Two authentication-bypass flaws in this manufacturer's devices were published in 2021 and accounted for 1,923 of the compromised cameras in 2026. Five years is a long time for a known flaw to remain exploitable at that scale.
A cloud service that trusts a serial number
The manufacturer's peer-to-peer cloud feature, intended to let owners view cameras without network configuration, was abused to reach 283 devices using only their serial numbers. Convenience features that bypass the firewall are attack surface by design.
Telegram as exfiltration
Sending stolen images out through a widely used messaging service removes the need for attacker-owned infrastructure and produces traffic that is unremarkable on most networks.
The uncomfortable feature of this case is how little of it required skill. Twelve thousand source addresses brute-forcing default passwords, two flaws that have been public since 2021, and a cloud feature that trusts a serial number. The capability assembled is significant; nothing used to assemble it was.
The concentration in Ukraine is the fact to sit with, and it is not evidence of purpose
The largest share of hijacked devices is in an active war zone, which invites an obvious reading. Hunt.io states that no military or battlefield reconnaissance purpose appears in the recovered material, and assesses at moderate confidence only that the access was built for handover. The geography is suggestive and the intent is not established, and this report does not close that gap.
Access built for resale is a different problem from access built for use
If the assessment is right, the operator was assembling an asset rather than running an operation, and the end user has not appeared. That matters because the capability outlives the campaign: the backdoors remain, the devices remain, and whoever eventually acquires the access inherits it without having done any of the work.
Persistent accounts defeat the remedy most owners will apply
A device owner told their camera was compromised will change the password. The backdoor accounts installed here survive that. Effective remediation requires a firmware reset and an audit of accounts on each device, which is a materially larger task and will not happen at scale across fourteen thousand consumer-installed cameras.
Five-year-old vulnerabilities are still working, which is a patching problem not a research one
Nearly two thousand cameras fell to flaws published in 2021. There is no defensive research gap here and no unknown technique to counter. The exposure is an installed base that nobody owns operationally, and that is a procurement and estate-management failure rather than a security one.
Camera fleets will keep being taken and the region will keep being the focus
Internet-exposed cameras with weak credentials are abundant, the economics of access brokerage reward assembling them, and the region offers both density and interest. It is highly likely that further large-scale camera compromises occur, and likely that some are assembled for sale rather than for the assembler's own use.
Set this beside Minnesota, where control systems at water utilities were reached because they were exposed to the internet with weak authentication. The device class differs and the failure does not: equipment installed by a contractor, connected for convenience, and thereafter owned by nobody.
- Put cameras and intercoms on the asset register. Most organisations cannot say how many internet-connected cameras they have, who installed them or when the firmware was last updated. That inventory is the first control and it does not exist in most estates.
- Change default credentials and verify it was done. Brute-forcing accounted for the large majority of this campaign. The installer may have set a password; it may also be the same one across every site they have fitted.
- Turn off cloud relay features unless you need them. A service that lets a camera be reached from outside using only a serial number bypasses the firewall by design. If remote viewing is required, it should go through a controlled route.
- Assume a password change is not remediation. Backdoor accounts persist. Any device suspected of compromise needs a firmware reset and an account audit, and that should be in the plan before it is needed.
- Consider what your cameras see. Door intercoms face the people entering a building and internal cameras face working areas. A compromised camera estate is a personnel surveillance capability, not a property one.
- Watch for outbound traffic to consumer messaging services from devices that should never use them. A camera talking to a messaging platform is anomalous by definition and is one of the few signals available on an estate that generates little other telemetry.
- https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised
- https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
- https://securityaffairs.com/197527/iot/inside-operation-cameraswarm-how-one-actor-took-over-14000-dahua-cameras.html
Compiled from open-source reporting for professional security discussion. This is a single threat intelligence firm's research finding. The identification of a Russian-speaking operator rests on Cyrillic comments in the tooling and on infrastructure analysis; no state connection and no commercial operator has been established, and the assessment that the access was built for onward handover is stated at moderate confidence. No military or battlefield reconnaissance purpose appears in the recovered material. The device owners have not been identified and the manufacturer was notified before publication. Technical indicators are not reproduced here. Details may be revised. This is a protective-security lessons-learned assessment, not an operational account.