CameraSwarm: hackers hijack 14,500 Dahua cameras in month-long spree

A 35-day campaign quietly took over Dahua security cameras across Ukraine and Russia, planting a hidden backdoor account that even factory resets can't remove.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Hunt.io researchers found a campaign, dubbed CameraSwarm, that broke into 14,530 Dahua internet-connected security cameras between June 17 and July 22.
  • The attackers used three methods at once: guessing passwords, exploiting known software flaws, and abusing a recovery code trick tied to the camera's serial number.
  • On 1,923 cameras the hackers installed a hidden account called 'p2pwn' that survives password changes and most factory resets.
  • Most victim cameras sit inside Russian and CIS telecom networks, though the initial scanning was global.
  • Hunt.io notified national response teams and Dahua's product security team on August 10.

A hacking crew spent five weeks quietly taking control of internet-connected security cameras, ending up with 14,530 devices under their thumb. The campaign, named CameraSwarm by the researchers who uncovered it, ran from June 17 to July 22 and mostly hit cameras in Ukraine and Russia.

The cameras are made by Dahua, a large Chinese manufacturer whose gear turns up in shops, offices, apartment blocks and small businesses worldwide. First reported by BleepingComputer, the operation was pieced together by threat intelligence firm Hunt.io after the attackers left a working folder exposed on a public web server.

Hunt.io downloaded 407 MB of the crew's own files: source code, logs, stolen passwords, captured camera stills, and command history. That gave researchers a rare look inside a live operation.

How did they break in?

The hackers ran three attacks in parallel rather than picking one. That is what made the reach so large.

The first was straightforward password guessing against TCP port 37777, the port Dahua cameras use for their own management protocol. That alone gave the crew access to 12,324 cameras. Once inside, the tool grabbed a snapshot from each camera and pushed the results into a Telegram channel.

The second method used two older Dahua flaws, CVE-2021-33044 and CVE-2021-33045, which let an attacker skip the login screen entirely. A custom tool the crew called p2pwn used these to plant a hidden admin account, username p2pwn and password p2password, on 1,923 cameras. On most firmware versions that account survives a factory reset, meaning the usual advice of "turn it off and on again with default settings" does not clear it out.

The third method is the clever one. Dahua cameras can be reached through the company's cloud relay service using only their serial number and credentials baked into Dahua's own apps. The attackers' toolkit generates password-recovery codes from the serial number, then feeds them through Dahua's standard recovery process. No knowledge of the current password needed. Hunt.io reports that 89.4% of live serials tested exposed an access channel without authentication.

Who got hit?

Mostly camera owners in Russia and other former Soviet states, though the scanning itself was worldwide.

Hunt.io says the crew first swept Russian address space, then the entire internet, before settling their attention on Russian and CIS telecom networks. Researchers also found Russian-language comments inside modified code, so the operator's own language appears to be Russian even though the targets were largely Russian too.

Attack method Cameras hit What it did
Password brute force on port 37777 12,324 Login guessing, snapshots sent to Telegram
p2pwn exploit (CVE-2021-33044, CVE-2021-33045) 1,923 Installed hidden backdoor account
Cloud recovery code abuse 283 Reached cameras behind home routers

What should camera owners do now?

Any Dahua camera reachable on port 37777 during June or July should be treated as possibly hacked. Check the account list for a user named p2pwn and remove it.

Removing the account is not the end of it. Hunt.io warns that the recovery codes the attackers generated remain valid until Dahua changes how those codes are derived on its servers. Owners should also turn off the P2P cloud feature if they do not use it, and install the firmware fix Dahua published as SA-2021-0130 or a later version.

For ordinary people with a Dahua camera watching the front door or the shop till, the practical worry is that a stranger may have been watching too, and could still have a way back in.

© 2026 Threat Vectr