14K+ Dahua cameras across Ukraine and Russia compromised; Slovakia found backdoor in traffic speed cameras

 

14K+ Dahua cameras across Ukraine and Russia compromised; Slovakia found backdoor in traffic speed cameras

More than 14,000 Dahua IP cameras were compromised between June 17 and July 22, 2026, in a multi-stage cyber campaign that mainly affected networks in Ukraine and Russia.

According to researchers at Hunt.io, who discovered and analyzed the campaign, the operator used masscan to scan large parts of the internet, first targeting Russian address space and later expanding scans across the full IPv4 range. The brute-force component reached 12,324 unique IP addresses. Researchers also found that some scans produced large numbers of potential targets in Mexico and Vietnam before the operation focused on Russian and CIS telecom networks.

The attacks leveraged several techniques, including automated password guessing against exposed cameras; vulnerabilities or authentication bypasses that allowed the attacker to access device functions without the normal login process; and Dahua's P2P relay service, which can provide remote access through the manufacturer's cloud infrastructure.

Attacks involved a persistent backdoor account named p2pwn, paired with the password p2password. Researchers found the account on 1,923 cameras. It was installed through RPC after one of the authentication bypasses and was stored separately from the main administrator credentials. This meant changing the admin password did not remove the backdoor. On most affected firmware versions, it could also survive a factory reset.

The operator also abused Dahua's cloud-based access system. At least 283 cameras were accessed using their serial numbers rather than network addresses. In many cases, no camera credentials were required. The operator's records indicated that nearly 90% of live serial numbers tested could be accessed without authentication.

Researchers also recovered offline cloud recovery codes, which could provide administrative access to a camera by a serial number. This feature suggests the toolkit may have been designed to provide camera access to third parties.

Hunt.io found the operator's exposed server directory containing 2,616 files across 234 directories, totaling about 407 MB. The files included scanning and exploitation tools, target lists, credentials, serial numbers and scripts used during the operation.

The same server contained a separate Windows malware component. Researchers identified a UPX-packed binary as SalatStealer and found a script containing five different methods for bypassing Microsoft Defender protections.

The toolkit appears to have been assembled from existing tools rather than developed by one operator. Its components were linked to at least six upstream developers, so it's hard to tell who originally created them.

More detailed analysis, as well as Indicators of Compromise (IoCs), can be found in Hunt.io’s technical write-up.

In an unrelated incident, Slovakia’s national security service (NBU) has warned about a potential backdoor in NERO R-ONE traffic cameras, which could allow malicious code to be sent via SMS from Russian phone numbers.

The cameras, reportedly rebranded Russian CORDON PRO.M devices, were purchased as part of a €30 million EU-funded traffic monitoring project. The NBU also found serious security flaws, including disabled SecureBoot, vulnerable web software, and unprotected live video streams.

The Interior Ministry has paused deployment of the 279 cameras and plans to have the findings independently assessed.


Back to the list