logo

Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras

ID: a40054d4-d015-54ff-ae4c-27475afd1bb8

STIX ID: report--a40054d4-d015-54ff-ae4c-27475afd1bb8

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-08-19

Date Updated: 2026-08-19

Author: Pierluigi Paganini

...
...

A researcher found an exposed operator directory that revealed "Operation CameraSwarm," in which an actor compromised over 14,000 Dahua and OEM cameras (mostly in Ukraine and Russia) between June and July 2026 using brute force, a 2021 auth-bypass that created persistent backdoor accounts, and abuse of Dahua’s cloud-relay serial-number channel (most devices accepted no authentication); the same infrastructure also hosted a UPX-packed Windows stealer and credential-exfiltration tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.