Hackers Compromise 14,500 Dahua IP Cameras in 35‑Day Campaign Using Vulnerabilities, Brute‑Force, and Cloud Recovery Codes
What Happened — Over a 35‑day period (June 17 – July 22, 2026) threat researchers identified a coordinated campaign, dubbed CameraSwarm, that compromised more than 14,500 Dahua IP cameras in Ukraine, Russia, and surrounding regions. The attackers used three parallel methods: (1) brute‑forcing the default TCP 37777 login, (2) exploiting CVE‑2021‑33044 and CVE‑2021‑33045 to install a persistent back‑door account, and (3) leveraging serial‑number‑based cloud‑relay recovery codes to gain access without authentication.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how insecure default credentials and undocumented recovery mechanisms can bypass SOC 2 Access Control and System Operations criteria, leaving audit evidence gaps.
- Highlights the need for continuous control mapping and automated evidence collection to prove that device‑level security controls (e.g., credential rotation, firmware patching) are consistently enforced.
- Aligns with Verisq’s Control Mapping capability, which provides a real‑time view of configuration drift and evidences remediation for audit readiness.
Who Is Affected
- Telecommunications & ISP operators deploying Dahua cameras.
- Enterprises in critical infrastructure, retail, and public safety that rely on IP‑based video surveillance.
Recommended Actions
- Inventory all Dahua (or similar) cameras and verify firmware versions against known patches for CVE‑2021‑33044/45.
- Enforce strong, unique passwords and disable default accounts; rotate credentials regularly.
- Audit and disable any “p2pwn” back‑door accounts; remove lingering recovery codes.
- Implement continuous configuration monitoring to detect unauthorized changes and generate audit‑ready evidence.
Technical Notes – The campaign combined (a) brute‑force scans of TCP 37777, (b) exploitation of two 2021 CVEs that create a persistent back‑door surviving password changes and factory resets, and (c) a cloud‑relay attack that used serial numbers to generate valid recovery codes via Dahua’s password‑recovery API. Researchers recovered 407 MB of data, including source code, logs, credentials, and captured images. Source: BleepingComputer