Threat Actor hacks 14,000 IP cameras in Ukraine and Russia

A threat actor has conducted a massive hacking campaign against Dahua IP cameras, compromising over 14,000 of them in Ukraine and Russia, Hunt.io reports.

The activity called Operation CameraSwarmoccurred between June 17 and July 22. It initially included a global scan across ranges of Russian, Mexican, and Vietnamese ISPs, but later focused on telecommunications network blocks of Russia and the CIS.

Hunt.io says it gained access to the threat’s servers, where it found 2,616 files in 234 subdirectories, or roughly 407MB of data, left in an open HTTP directory that the hackers themselves disclosed.

Data analysis revealed over 14,530 devices were compromised within the 35-day campaign. A brute force engine was used to target 12,324 unique addresses.

The threat actor has deployed a persistent backend account on 1923 cameras via Remote Procedure Call (RPC). The account uses the username and password pair p2pwn/p2password.

“It is stored independently of the administrator password and survives a password change and, on most firmwares, a factory reset,” says Hunt.io.

Advertising. Scroll to continue reading.

To brute force credentials, the threat used a publicly available asynchronous framework. They also relied on a compiled Go binary to bypass authentication, linking three vulnerabilities including the CVE-2021-33044 and CVE-2021-33045 and CVE-20244-39943 backdoor implementation bypasses.

“CVE-2021-33044 exploits unconditional trust in clients identifying themselves as NetKeyboard hardware controllers: when clientType is NetKeyboard, the password field is never evaluated. CVE-2021-33045 exploits firmware that reads the requested source address from the request body, not from the TCP connection,” says Hunt.io.

The bypasses return a full admin session, unauthorized, and the binary removes the p2pwn / p2password account via RPC.

In some cases, attackers abuse Dahua Cloud Relay to reach cameras behind NAT using only their serial numbers.

Hunt.io discovered that the threat had created the infrastructure used in the campaign at least a year before the attacks, and that its toolkit contained both their own code and modified code from at least four other developers.

“We estimate with moderate confidence that the toolkit was designed to provide third-party access, based on a transferable recovery code design and export pipeline in an enterprise format. This is narrower than a confirmed commercial operation, which the evidence does not support,” Hunt.io said.

The report did not establish the operator’s ultimate motivation or intended use of the compromised cameras.

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Cl0p Ransomware Group names over 40 victims of PTC Windchill campaign

Related: Fortune 500 companies fall victim to Azure data theft campaign

Related: Hidden ‘City-Forum’ attacks target Salesforce and ServiceNow with custom toolset

Leave a Reply

Your email address will not be published. Required fields are marked *