$ techbeacon▋
Phishing

Operation CameraSwarm Hijacks Over 14,500 Dahua Surveillance Units in Just Over a Month

Operation CameraSwarm Hijacks Over 14,500 Dahua Surveillance Units in Just Over a Month

A coordinated intrusion known as Operation CameraSwarm succeeded in taking control of at least 14,530 Dahua IP cameras and associated surveillance hardware within a 35‑day window, security analysts reported. The campaign, which unfolded across multiple continents, demonstrates how quickly a large‑scale botnet can be assembled from everyday video‑monitoring equipment.

Researchers traced the attackers' methods to three primary weaknesses: outdated firmware that left known vulnerabilities unpatched, default or easily guessable administrator passwords, and the manufacturers' peer‑to‑peer (P2P) cloud service that enables remote access without a dedicated network configuration. When combined, these flaws gave threat actors the ability to log in, re‑program settings and enlist the devices in a larger malicious network.

Dahua Technology, a leading Chinese supplier of video‑surveillance solutions, counts its cameras on everything from retail storefronts to municipal traffic intersections. Many installations, especially those managed by small businesses or local governments, still operate on firmware versions released years ago, making them prime targets for exploitation. The sheer number of compromised units underscores how pervasive insecure IoT deployments remain.

Control of the cameras provides attackers with live video streams, the capacity to manipulate recordings, and a foothold for lateral movement inside corporate or municipal networks. While investigators have not yet uncovered evidence of systematic data exfiltration, the potential for privacy violations and for the devices to be repurposed in distributed‑denial‑of‑service (DDoS) attacks is significant.

In response, Dahua issued an emergency advisory urging owners to install the latest firmware patches and to replace factory‑default credentials with strong, unique passwords. Several security firms have also begun offering free scans to locate vulnerable units, and some internet service providers are throttling traffic from known compromised IP ranges.

The incident adds to a growing body of evidence that the Internet of Things sector still lacks robust security standards. Experts stress that manufacturers must embed automatic update mechanisms and enforce stronger authentication, while end users need to adopt regular maintenance routines to mitigate risk.

Law‑enforcement agencies are monitoring the botnet’s activity, and cybersecurity researchers plan to continue tracking its command‑and‑control infrastructure. Until comprehensive patches are deployed, officials recommend that organizations audit their camera inventories, disable unnecessary cloud features, and enforce strict password policies to prevent further exploitation.

Source: GBHackers
Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related