Researchers Say 14,500 Dahua Cameras Fell to a Six-Week Hijack Campaign

Hunt.io traced Operation CameraSwarm through an exposed 407 MB working directory, revealing password guessing, two authentication-bypass flaws, and a peer-to-peer relay trick.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A cybersecurity researcher's desk with investigation files spread out, a security camera image displayed on monitor, directory structure and authentication logs
Share

Key points

  • Researchers at Hunt.io say attackers broke into more than 14,530 Dahua internet-connected cameras between June 17 and July 22, 2026.
  • The campaign, named Operation CameraSwarm, mixed password guessing with two authentication-bypass flaws in Dahua firmware.
  • Attackers used a peer-to-peer relay feature to reach cameras sitting behind home and office routers.
  • Hunt.io reconstructed the operation from a 407 MB working directory left exposed online, holding 2,616 files.
  • Owners of Dahua-branded cameras and rebadged models should change default passwords and install the latest firmware.

Security researchers at Hunt.io have published details of a six-week hijack campaign against Dahua-made surveillance cameras, one of the largest consumer and small-business camera brands in the world.

The researchers say attackers took control of more than 14,530 devices between June 17 and July 22, 2026. The write-up was reported by The Hacker News. Hunt.io reconstructed the campaign from the attackers' own working folder, left sitting exposed on the open internet: 407 MB of material across 2,616 files, including scripts, logs of successful break-ins, and target lists.

How did the attackers get in?

Three techniques, used together. Credential attacks: automated guessing of usernames and passwords, often trying factory defaults that owners never changed. Two authentication-bypass flaws in Dahua's firmware, letting a request skip the login step entirely. And a peer-to-peer relay, or P2P relay, technique worth explaining.

Most home cameras sit behind a router and aren't directly reachable from the internet. Dahua devices ship with a built-in relay service so owners can view their feed from a phone anywhere. The attackers rode that same relay to reach cameras that owners assumed were tucked safely out of reach.

What could the hackers do with a hijacked camera?

At minimum, watch the video feed. A compromised camera can also serve as a foothold on the home or office network, or get folded into a botnet, a network of hijacked devices rented out to attack other targets. We covered a similar cataloguing operation on 11 June, when Lumen's Black Lotus Labs tied the JDY botnet to nation-state reconnaissance. Hunt.io's files suggest CameraSwarm's operators were doing much the same: building inventory at scale, not picking individual victims.

Operation CameraSwarm at a glance

Detail Figure
Devices compromised 14,530+
Campaign window 17 Jun to 22 Jul 2026
Exposed directory size 407 MB
Files recovered 2,616
Techniques used Credential attacks, 2 auth-bypass flaws, P2P relay

Who should be paying attention?

Anyone with a Dahua camera, and anyone whose camera looks generic but runs Dahua hardware underneath. Dahua supplies internals for a long list of rebranded products sold under other names. If you bought a cheap IP camera in the last few years, there's a real chance the guts are Dahua.

Log in to the camera's app or web panel, change any password that's still at the default, and check for a firmware update. If the device is old enough that the maker no longer pushes updates, treat it as untrusted: put it on a separate guest network or replace it.

Hunt.io hasn't publicly attributed Operation CameraSwarm to a named group. The researchers note the operators showed reasonable technical skill but poor operational security, which is how their working directory ended up exposed in the first place. That gap matters: it's the only reason we know the scale of this at all.

Common questions

How do I know if my camera is Dahua-made?

Check the app you use to view the feed. If it's DMSS, gDMSS or Dahua's own portal, the device is Dahua. Rebadged models often show the same app name in the setup instructions.

Should I unplug the camera?

Not necessarily. Change the password, apply the latest firmware, and turn off remote P2P viewing if you don't use it. Those steps close the main doors this campaign walked through.

© 2026 Threat Vectr