HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Hackers Compromise 14,500 Dahua IP Cameras in 35‑Day Campaign Using Vulnerabilities, Brute‑Force, and Cloud Recovery Codes

A 35‑day campaign dubbed CameraSwarm compromised over 14,500 Dahua IP cameras across Ukraine and Russia by exploiting CVEs, brute‑forcing logins, and abusing serial‑number‑based recovery codes. The incident underscores the importance of continuous control mapping and audit‑ready evidence for SOC 2 compliance.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

Hackers Compromise 14,500 Dahua IP Cameras in 35‑Day Campaign Using Vulnerabilities, Brute‑Force, and Cloud Recovery Codes

What Happened — Over a 35‑day period (June 17 – July 22, 2026) threat researchers identified a coordinated campaign, dubbed CameraSwarm, that compromised more than 14,500 Dahua IP cameras in Ukraine, Russia, and surrounding regions. The attackers used three parallel methods: (1) brute‑forcing the default TCP 37777 login, (2) exploiting CVE‑2021‑33044 and CVE‑2021‑33045 to install a persistent back‑door account, and (3) leveraging serial‑number‑based cloud‑relay recovery codes to gain access without authentication.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how insecure default credentials and undocumented recovery mechanisms can bypass SOC 2 Access Control and System Operations criteria, leaving audit evidence gaps.
  • Highlights the need for continuous control mapping and automated evidence collection to prove that device‑level security controls (e.g., credential rotation, firmware patching) are consistently enforced.
  • Aligns with Verisq’s Control Mapping capability, which provides a real‑time view of configuration drift and evidences remediation for audit readiness.

Who Is Affected

  • Telecommunications & ISP operators deploying Dahua cameras.
  • Enterprises in critical infrastructure, retail, and public safety that rely on IP‑based video surveillance.

Recommended Actions

  • Inventory all Dahua (or similar) cameras and verify firmware versions against known patches for CVE‑2021‑33044/45.
  • Enforce strong, unique passwords and disable default accounts; rotate credentials regularly.
  • Audit and disable any “p2pwn” back‑door accounts; remove lingering recovery codes.
  • Implement continuous configuration monitoring to detect unauthorized changes and generate audit‑ready evidence.

Technical Notes – The campaign combined (a) brute‑force scans of TCP 37777, (b) exploitation of two 2021 CVEs that create a persistent back‑door surviving password changes and factory resets, and (c) a cloud‑relay attack that used serial numbers to generate valid recovery codes via Dahua’s password‑recovery API. Researchers recovered 407 MB of data, including source code, logs, credentials, and captured images. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-cameras-in-35-day-campaign/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →