Executive Summary
Between June 17 and July 22, 2026, cybersecurity researchers at Hunt.io identified a campaign, dubbed Operation CameraSwarm, that compromised over 14,530 Dahua devices. Attackers employed credential attacks, exploited authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and utilized a peer-to-peer (P2P) relay technique to gain unauthorized access. The breaches were predominantly concentrated in Ukraine and Russia, with 1,923 cameras configured with persistent accounts and 283 accessed via the P2P method.
This incident underscores the critical need for organizations to promptly apply security patches, disable unnecessary P2P features, and regularly update device firmware to mitigate potential vulnerabilities. (labs.itresit.es)
Why This Matters Now
The exploitation of known vulnerabilities in Dahua devices highlights the urgency for organizations to proactively manage and secure IoT devices, as similar attack vectors may be leveraged in future campaigns.
Attack Path Analysis
Attackers initiated the campaign by exploiting weak credentials and authentication bypass vulnerabilities in Dahua devices, gaining unauthorized access. They then established persistent accounts on compromised devices to maintain control. Utilizing the P2P relay feature, attackers accessed devices behind NAT without prior authentication. Compromised devices were used to establish command and control channels, allowing remote management. Attackers exfiltrated sensitive data from the devices. The operation resulted in unauthorized surveillance and potential privacy violations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited weak credentials and authentication bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045) to gain unauthorized access to Dahua devices.
Related CVEs
CVE-2021-33044
CVSS 9.8An authentication bypass vulnerability in some Dahua products allows attackers to bypass device identity authentication by constructing malicious data packets.
Affected Products:
Dahua Technology IP Camera – IPC-HX3XXX, IPC-HX5XXX
Dahua Technology PTZ Dome Camera – SD1A1, SD22, SD49, SD50, SD52C, SD6AL
Dahua Technology Thermal Camera – TPC-BF1241, TPC-BF2221, TPC-SD2221
Dahua Technology Video Intercom – VTO2101E, VTOX221E
Dahua Technology Access Control – ASC2204C
Dahua Technology NVR – NVR4XXX, NVR5XXX
Dahua Technology XVR – XVR4XXX, XVR5XXX
Dahua Technology HCVR – HCVR7XXX, HCVR8XXX
Exploit Status:
exploited in the wildCVE-2021-33045
CVSS 9.8An authentication bypass vulnerability in some Dahua products allows attackers to bypass device identity authentication by constructing malicious data packets.
Affected Products:
Dahua Technology IP Camera – IPC-HX3XXX, IPC-HX5XXX
Dahua Technology PTZ Dome Camera – SD1A1, SD22, SD49, SD50, SD52C, SD6AL
Dahua Technology Thermal Camera – TPC-BF1241, TPC-BF2221, TPC-SD2221
Dahua Technology Video Intercom – VTO2101E, VTOX221E
Dahua Technology Access Control – ASC2204C
Dahua Technology NVR – NVR4XXX, NVR5XXX
Dahua Technology XVR – XVR4XXX, XVR5XXX
Dahua Technology HCVR – HCVR7XXX, HCVR8XXX
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Brute Force
Valid Accounts
External Remote Services
Exploit Public-Facing Application
Account Manipulation
Non-Standard Port
Remote Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
IoT device compromises via credential attacks and authentication bypasses directly impact security infrastructure, requiring enhanced egress filtering and zero trust segmentation capabilities.
Public Safety
Video surveillance system vulnerabilities expose critical security infrastructure through P2P relay attacks, compromising incident response capabilities and requiring immediate firmware updates.
Government Administration
Dahua camera compromises threaten government facility security monitoring, enabling lateral movement and data exfiltration through unencrypted traffic and authentication bypass vulnerabilities.
Banking/Mortgage
Financial institutions face compliance violations and surveillance system breaches, requiring encrypted traffic controls and threat detection capabilities to prevent unauthorized access.
Sources
- Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2Phttps://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.htmlVerified
- Dahua Security Advisory - Identity Authentication Bypass Vulnerability Found in Some Dahua Productshttps://www.dahuasecurity.com/support/cybersecurity/details/957Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-33044Verified
- NVD - CVE-2021-33044https://nvd.nist.gov/vuln/detail/CVE-2021-33044Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial unauthorized access due to credential weaknesses, it could limit the attacker's ability to exploit compromised devices to access other network segments.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by enforcing strict access controls, thereby reducing the scope of unauthorized activities.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic patterns.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to establish command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies.
Aviatrix Zero Trust CNSF could reduce the scope of unauthorized surveillance by limiting the attacker's access to sensitive data and systems.
Impact at a Glance
Affected Business Functions
- Surveillance Monitoring
- Security Operations
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of surveillance footage and unauthorized access to security systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement strong, unique credentials and disable default accounts to prevent unauthorized access.
- • Apply firmware updates promptly to patch known vulnerabilities like CVE-2021-33044 and CVE-2021-33045.
- • Disable P2P features if not required to reduce exposure to unauthorized access.
- • Deploy network segmentation to limit lateral movement within the network.
- • Monitor device logs and network traffic for anomalies indicating potential compromise.



