```html ```
top of page

Everyone Will Write About the Clever Trick That Took 283 Cameras. The Default Password Took 12,324. Operation CameraSwarm Is a Lesson in Reading Your Own Numbers.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 3 minutes ago
  • 4 min read

Hunt.io published research on Operation CameraSwarm: 14,530 Dahua devices compromised between 17 June and 22 July 2026, concentrated in Ukraine and Russia.


The campaign used three methods, and the write-ups — reasonably — lead with the most interesting one, a peer-to-peer relay abuse that turns the vendor's own infrastructure into a route past your firewall.


Here is how the 14,530 actually breaks down:



Method

Devices

Share

Credential attacks

12,324

84.8%

Authentication bypass (CVE-2021-33044 / -33045)

1,923

13.2%

P2P relay abuse (Easy4IP)

283

1.9%


The numbers reconcile exactly to the stated total. The clever part accounts for fewer than two devices in a hundred. Guessed, reused and factory-default passwords account for eighty-five.





The interesting finding, given its actual weight


It deserves its paragraph, so here it is properly.


On Dahua firmware before mid-2024, a valid serial number was enough to establish an Easy4IP relay path to a device — and the relay was established before the device performed its own credential check.


Read that ordering again, because it is the whole thing. A camera sitting behind NAT, with no port forwarded, unreachable from the internet by design, becomes reachable through the vendor's own relay infrastructure on the strength of a serial number. The customer's network boundary did not fail. It was routed around by a convenience feature that exists precisely to route around it, and which asked for identity in the wrong order.


That is a real seam and it is the kind we keep naming: the control held, the handoff was unassigned. The customer owns the firewall. The vendor owns the relay. Nobody owns the question of which one authenticates first.


It got 283 devices.



The finding that actually did the damage


Credentials. 12,324 of them.


No exploit. No CVE. No firmware dependency. Nothing to patch, no advisory to read, no vendor to wait on. Somebody guessed, reused or simply used the factory default on more than twelve thousand cameras.


This gets one line in most coverage because there is nothing clever to explain. It is six times the CVE number and forty-four times the P2P number.


We have a standing rule about this, and it exists because we have got it wrong before: rank by share of the total, not by how much it looks like tradecraft. The interesting thing and the important thing are frequently different things, and the interesting one is much easier to write about. If you are defending a camera estate tonight, the exotic path is a rounding error and the boring path is nearly the whole event.



The part that should genuinely bother you


CVE-2021-33044 and CVE-2021-33045 are both CVSS 9.8. Both were added to the CISA Known Exploited Vulnerabilities catalogue on 21 August 2024. Dahua shipped firmware fixes.


The campaign started on 17 June 2026665 days after the KEV listing — and still took 1,923 devices through those two CVEs.


A patch that exists is not a patch that is applied. On a camera that was installed by a contractor, mounted eleven feet up, and never logged into again by anybody, it is never going to be applied. That is not a patching-discipline failure in the way the phrase is usually meant. It is a structural property of a device class that has no operator — nobody whose job includes it, nobody who would notice, nobody who gets the advisory.


This is what the 665 days is really measuring. Not slowness. Absence.



What to do, in the order the numbers justify


First, credentials. Every camera, every NVR, every recorder. Unique passwords, not one shared across the estate. This addresses 85% of what actually happened.


Second, firmware. Get onto a build that carries the 33044/33045 fixes. That is another 13%.


Third, disable P2P where it is not essential. Easy4IP is a convenience feature; if you are not using remote viewing through the vendor cloud, turn it off. That closes the remaining 2% and the most architecturally interesting hole.


Fourth, and this is the one people skip: work out who owns your cameras. If the honest answer is "the installer, four years ago," then you do not have a patching problem, you have an ownership vacancy, and every future advisory will land in the same empty inbox.



A footnote on how this was found at all


Hunt.io reconstructed the campaign from a 407 MB working directory the operator left exposed — 2,616 files across 234 subdirectories, containing tooling, logs, shell history and campaign records.


That is the second campaign this week undone by its own operator's housekeeping. We wrote on Monday about StopAndProtect, a global ransomware operation unmasked because one of its operators infected their own desktop and the stolen files uploaded to their own collection server.


Both crews ran competent technical operations and both were exposed by ordinary carelessness with their own infrastructure. It is worth resisting the urge to find that comforting — the defensive version of the same mistake is what half our own audit findings are about, and the only difference is consequence.



Sources


Operation CameraSwarm: Hunt.io research, reported 19–26 August 2026. 14,530 Dahua devices compromised 17 June – 22 July 2026, concentrated in Ukraine and Russia; 12,324 via credential attacks, 1,923 via authentication bypass, 283 via P2P relay; reconstructed from a 407 MB exposed working directory of 2,616 files across 234 subdirectories.


CVE-2021-33044 and CVE-2021-33045 (both CVSS 9.8, Dahua IP camera authentication bypass) and their 21 August 2024 KEV listing dates are from our own cisa_kev index. The 665-day figure is our arithmetic.


Capped at 95 percent: the campaign figures are Hunt.io's and we have not independently verified them; we hold no first-party observation of this campaign and no CameraSwarm-attributed indicators in our feed. The percentage breakdown is ours, computed from their numbers, and it reconciles exactly to their stated total.




If you own cameras, the useful question is not "are we patched." It is "who would receive the advisory." Go and find out whether that person exists, because on this device class the answer is very often no. Rate this post below.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=everyone-will-write-about-the-clever-trick-that-took-283-cameras-the-default-password-took-12-324



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page