Code Defence Cyber security

Operation CameraSwarm hacks 14000 IP cameras via chained authentication bypasses and RPC flaws

Threat research writeups have detailed a multi-month mass hacking campaign targeting edge IP cameras across enterprise and telecommunication subnets. The threat actor utilized automated scanning toolkits to chain legacy authentication bypasses with remote procedure call flaws, dropping persistent backdoor accounts across thousands of devices.

The activity, designated Operation CameraSwarm, compromised over 14,500 Dahua IP cameras across global ISP ranges. The threat actor deployed a compiled Go binary that chained legacy authentication bypasses CVE-2021-33044 and CVE-2021-33045 to obtain unauthenticated administrator sessions. Once administrative access was achieved, the binary executed Remote Procedure Call commands to create a persistent backdoor user account. In multiple instances, the attackers abused vendor cloud relay services to breach devices operating behind internal NAT boundaries.

Subverting edge surveillance infrastructure creates unmonitored persistence channels across enterprise perimeters. Because compromised IP camera hardware maintains active local network access, persistent backdoor accounts allow threat actors to capture internal video streams, conduct local subnet reconnaissance, and pivot into adjacent corporate network segments.

– Apply current firmware updates provided by camera hardware vendors across all IP surveillance deployments.

– Isolate physical security hardware and camera management networks on dedicated, non-routable surveillance VLANs.

– Audit device administrative user registries for unauthorized account additions, specifically inspecting RPC configuration logs.

– Disable cloud relay mechanisms and UPnP auto-forwarding options on edge video recording equipment.

IoT edge infrastructure security depends on strict network microsegmentation and continuous device account auditing to ensure smart perimeter hardware cannot be subverted into persistent backdoor entry points. #CodeDefence #OperationCameraSwarm #IoTSecurity #CameraHacking #AuthBypass #NetworkSecurity #AppSec
/

Scroll to Top