Operation CameraSwarm: 14,500+ Dahua Devices Fell in a Single Month

·
Listen to this article~5 min
Operation CameraSwarm: 14,500+ Dahua Devices Fell in a Single Month

Hunt.io researchers exposed Operation CameraSwarm, a campaign that compromised over 14,530 Dahua devices in a month using credential attacks, auth bypasses, and P2P relay tricks.

It started with a single exposed folder on the internet. But that folder turned out to be the digital equivalent of a burglar's diary. Cybersecurity researchers at Hunt.io have published a detailed breakdown of a campaign that quietly compromised more than 14,530 Dahua devices in just over a month. That's not a typo. Between June 17 and July 22, 2026, attackers used a mix of old-school credential stuffing, two separate authentication-bypass flaws, and a peer-to-peer (P2P) relay technique to build what they've codenamed Operation CameraSwarm. If you're thinking this sounds like something out of a spy thriller, you're not wrong. But the scariest part is how mundane the initial attack vector was. The whole operation was reconstructed from a 407 MB working directory that was left exposed online. Inside, researchers found 2,616 files that essentially mapped out the entire attack playbook. It's like finding the blueprint to a bank heist taped to the bank's front door. ### The Anatomy of the Attack Let's break down how this actually went down. The attackers didn't rely on a single, flashy zero-day exploit. Instead, they layered several techniques to maximize their reach. - **Credential Attacks:** They started with brute-forcing and credential stuffing, trying common usernames and passwords against Dahua's remote management interfaces. You'd be surprised how many devices still have 'admin' and '12345' as the login. - **Authentication Bypass Flaws:** They exploited two distinct vulnerabilities that let them skip the login process entirely. These weren't brand-new bugs either, which raises questions about how many devices are still running outdated firmware. - **P2P Relay Technique:** This is where it gets clever. Instead of connecting directly to each camera (which would be easy to spot), they used Dahua's own peer-to-peer relay network to route their commands. This made the malicious traffic look like normal device-to-device communication. The combination of these methods meant that even if a device had a strong password, it could still fall to the auth bypass. And if it was patched against the bypass, the credential attacks might still get through. It's a shotgun approach, and unfortunately, it worked. ### Why This Matters for Your Security The implications here go beyond just Dahua customers. This campaign is a stark reminder that internet-connected devices are only as secure as their weakest link. And in many cases, that weakest link is the user who never changed the default password or the IT admin who forgot to update the firmware. Think about it this way: you can buy the most expensive deadbolt for your front door, but if you leave the key under the mat, it doesn't matter. The same logic applies to security cameras. They're not just recording video; they're nodes on your network. Once a camera is compromised, attackers can use it as a foothold to pivot into your entire internal infrastructure. > "The attackers didn't need to be geniuses. They just needed to find devices that were left unlocked, and they found thousands of them." — A lead researcher on the Hunt.io team. ### What You Can Do Today If you're running any Dahua equipment, or honestly any IP camera at all, now is the time to take action. Don't wait for a vendor advisory to land in your inbox. Here's a quick checklist to tighten your defenses: - **Change every default password immediately.** Use a unique, complex passphrase for each device. - **Update firmware religiously.** Check for patches at least once a month, and apply them as soon as they're available. - **Disable P2P if you don't absolutely need it.** Remote access convenience is not worth the risk of routing your traffic through an unknown relay. - **Segment your network.** Put cameras on a separate VLAN so that even if they're compromised, the attackers can't easily reach your computers or servers. - **Monitor for unusual login attempts.** Set up alerts for repeated failed logins or access from unexpected IP addresses. Operation CameraSwarm is a wake-up call. It shows that attackers are willing to put in the time to scan for vulnerable devices at massive scale. They're not targeting you personally; they're targeting everyone. And the only way to avoid being caught in the swarm is to make your devices harder to crack than the next guy's. It's not about being bulletproof. It's about not being the low-hanging fruit.