Researchers Say 14,500 Dahua Cameras Fell to a Six-Week Hijack Campaign

Hunt.io traced Operation CameraSwarm through an exposed 407 MB working directory, revealing password guessing, two authentication-bypass flaws, and a peer-to-peer relay trick.

ThreatVectr Newsdesk· 4 min read
Dim editorial photograph of a developer workstation at night, screen showing a code editor with a redacted extension manifest, faint overlay of blockchain trans
Share

Key points

  • Researchers at Hunt.io say attackers broke into more than 14,530 Dahua internet-connected cameras between June 17 and July 22, 2026.
  • The campaign, named Operation CameraSwarm, mixed password guessing with two authentication-bypass flaws in Dahua firmware.
  • Attackers also used a peer-to-peer relay feature to reach cameras that sit behind home and office routers.
  • Hunt.io reconstructed the operation from a 407 MB working directory left exposed online, holding 2,616 files.
  • Owners of Dahua-branded cameras and rebadged models should change default passwords and install the latest firmware.

Security researchers at Hunt.io have published details of a six-week hijack campaign against Dahua-made surveillance cameras, one of the largest consumer and small-business camera brands in the world.

The researchers say attackers took control of more than 14,530 devices between June 17 and July 22, 2026. They have named the operation CameraSwarm. The write-up was picked up by The Hacker News.

Hunt.io reconstructed the campaign from an unusual source: the attackers' own working folder, which sat exposed on the open internet. That folder held 407 MB of material across 2,616 files, including scripts, target lists, and logs of successful break-ins.

How did the attackers get in?

They used three techniques together. First, credential attacks, meaning automated guessing of usernames and passwords, often trying factory defaults that owners never changed. Second, two authentication-bypass flaws in Dahua's firmware, which let a request skip the login step entirely. Third, a peer-to-peer, or P2P, relay technique.

The P2P point matters for ordinary readers. Most home cameras sit behind a router and are not directly reachable from the internet. Dahua devices ship with a built-in relay service so owners can view their feed from a phone anywhere. The attackers rode that same relay to reach cameras that their owners assumed were tucked safely behind the router.

What could the hackers do with a hijacked camera?

At minimum, watch the video feed. In practice, a compromised camera can also be used as a foothold on the same home or office network, or added to a botnet, a network of hijacked devices rented out to launch attacks on other targets. Hunt.io's files suggest the operators were cataloguing devices at scale rather than picking individual victims.

Operation CameraSwarm at a glance

Detail Figure
Devices compromised 14,530+
Campaign window 17 Jun to 22 Jul 2026
Exposed directory size 407 MB
Files recovered 2,616
Techniques used Credential attacks, 2 auth-bypass flaws, P2P relay

Who should be paying attention?

Anyone with a Dahua camera, and anyone with a camera that looks generic but was actually built on Dahua hardware. Dahua supplies the internals for a long list of rebranded products sold under other names in shops and online marketplaces. If you bought a cheap IP camera in the last few years, there is a real chance the guts are Dahua.

Owners should log in to the camera's app or web panel, change any password that is still set to the default or to something short, and check for a firmware update. If the camera is more than a few years old and no longer receives updates from the maker, treat it as untrusted and consider replacing it or putting it on a separate guest network.

Hunt.io has not publicly attributed Operation CameraSwarm to a named group. The researchers note the operators showed reasonable technical skill but poor operational security, which is how their working directory ended up exposed in the first place.

Common questions

How do I know if my camera is Dahua-made?

Check the app you use to view the feed. If it is DMSS, gDMSS, iDMSS or Dahua's own portal, the device is Dahua. Rebadged models often show the same app name in the setup instructions.

Should I unplug the camera?

Not necessarily. Change the password, apply the latest firmware, and turn off remote P2P viewing if you do not use it. That closes the main doors this campaign walked through.

© 2026 Threat Vectr