14,530 Dahua cameras breached in Ukraine and Russia

Attackers breached 14,530 Dahua IP cameras from June 17 to July 22, installing persistent backdoor accounts via brute-force and chained exploits.

Hunt.io reported a mass-hacking campaign that compromised 14,530 Dahua IP cameras across Ukraine and Russia between June 17 and July 22. The intruders used brute-force credential attacks and chained software exploits to install persistent backdoor accounts that often survive password changes and many factory resets.

Investigators gained access to the attackers’ servers and found an exposed HTTP directory containing about 2,616 files in 234 subdirectories, totaling roughly 407 MB. Early scans covered broad network ranges, including Russian, Mexican and Vietnamese ISP blocks, then shifted focus to Russian and other Commonwealth of Independent States telecom netblocks. Hunt.io determined some of the infrastructure had been in place for at least a year before the active campaign.

The threat actor used a brute-force engine against 12,324 unique IP addresses and deployed a compiled Go binary that chained multiple vulnerabilities to bypass authentication and create a persistent account over Remote Procedure Call. Hunt.io found the account using the username and password pair p2pwn/p2password on 1,923 cameras, and noted the account is stored separately from the administrator password and survives password changes and, on most firmware, factory resets.

Credential stuffing relied on a publicly available asyncio framework. The Go binary exploited three known flaws, including CVE-2021-33044 and CVE-2021-33045 plus CVE-20244-39943, to obtain administrator sessions without authentication and then drop the backdoor account. Hunt.io described one flaw as an unconditional trust in clients that identify as NetKeyboard hardware controllers, which bypasses the password check, and another as firmware reading the claimed source address from the request body rather than the TCP connection. Those bypasses returned full administrator sessions to the attacker.

In some cases, the attackers connected to cameras behind network address translation by abusing Dahua’s cloud relay service using only device serial numbers. The seized toolkit combined original code and modified components from at least four other developers. Hunt.io assessed with moderate confidence that the toolkit was built to pass access to a third party based on a transferable recovery-code design and an enterprise-format export pipeline, but the report did not find conclusive evidence that the operation was a commercial service.

The report does not identify the attackers’ motivation or how the compromised cameras were used after the intrusion.

Articles by this author