Particle.news

Operation CameraSwarm Compromised Over 14,000 Dahua Cameras

Researchers say attackers abused older authentication bypasses via the vendor's cloud relay to reach many devices without normal logins.

Overview

  • Hunt.io reconstructed a 35-day campaign that it says reached 14,530 Dahua devices between June 17 and July 22, 2026, using three parallel paths: credential brute force, two 2021 authentication-bypass flaws, and a serial-number P2P relay.
  • The firm recovered a 407 MB exposed operator directory with 2,616 files that contained the attacker’s scanning and exploit code, logs, captured images, credentials, and tooling that let researchers map the operation.
  • The P2P relay used device serial numbers and fixed SDK credentials to build tunnels to cameras behind NAT, and the operator’s logs claim 89.4% of probed serials returned an open channel without authentication though that probe rate is currently Hunt.io’s claim and not independently reproduced.
  • Researchers say the campaign installed persistent backdoor accounts on 1,923 cameras that on most firmware survive password changes and factory resets, and the toolkit also includes an offline recovery-code method that can redeem account recovery using only a device serial number.
  • Dahua and CISA list the two 2021 authentication-bypass CVEs and provide firmware updates, while experts advise disabling P2P where possible, updating firmware from vendor sites, rotating and removing credentials, and urging vendors to change recovery-code and relay authentication logic.