Dahua IP Cameras in Ukraine and Russia Compromised via Chained CVEs and Persistent RPC Backdoor
A 35-day operation compromised 14,530 Dahua cameras in Ukraine and Russia using publicly available tools and known authentication bypasses. Evidence points to pre-positioned infrastructure and a backdoor designed for transfer rather than immediate use. The activity underscores ongoing exposure of critical infrastructure sensors to commodity exploits with unclear ultimate operators.
{"Hunt.io gained access to the operators' exposed HTTP directory containing 2,616 files and mapped the full campaign infrastructure. The toolkit combined custom Go binaries with modified public asyncio brute-force code and exploited Dahua RPC to install the p2pwn/p2password account, which persists across password changes and most factory resets. Scanning initially targeted global ISP ranges before narrowing to Russian and CIS netblocks, with cloud relay abuse used to reach NATed devices by serial number alone.","Technical evidence shows the backdoor was deployed on 1,923 cameras after successful bypass sessions. The operators had pre-positioned servers at least twelve months earlier and built a recovery-code export pipeline consistent with third-party handoff rather than direct operational use. No attribution data links the activity to a specific state, though the geographic focus on Ukraine and Russia overlaps known critical-infrastructure targeting patterns without independent confirmation of espionage payload deployment.","The campaign reveals a recurring pattern of long-dwell infrastructure preparation followed by rapid, automated exploitation of commodity camera firmware. Similar Dahua bypass chains have appeared in prior botnet and surveillance operations, yet procurement records for these devices in both countries continue to favor lowest-cost vendors without mandatory firmware attestation. The transferable recovery mechanism suggests the operators may be selling or leasing access rather than consuming it directly.","Unpatched devices remain reachable via the same RPC path; administrators who have not rotated credentials or isolated cameras from the internet should assume persistence. Next observable indicators will likely appear in open directories or new serial-number relay traffic within the next 45 days if the same infrastructure is reused."}
Hunt.io: Reuse of the p2pwn account on additional devices will exceed 3,000 new infections in CIS networks within 45 days absent widespread patching.
Sources (3)
- [1]Hunt.io Operation CameraSwarm Report(https://hunt.io/research/operation-cameraswarm)
- [2]NVD CVE-2021-33044(https://nvd.nist.gov/vuln/detail/CVE-2021-33044)
- [3]Dahua Firmware Authentication Bypass Analysis(https://www.rapid7.com/blog/post/2021/09/02/dahua-authentication-bypass/)