A large campaign has compromised more than 14,000 internet-connected Dahua cameras, exposing how vulnerable surveillance equipment can become a gateway to video feeds and device settings.
The operation ran for 35 days, and hit devices worldwide, with confirmed compromises centered in Ukraine and Russia. It shows how unattended devices can create durable, long-lasting hidden access for intruders.
The operator scanned for exposed camera management services, tried weak credentials, and used two known authentication-bypass flaws against unpatched devices.
It also used a cloud relay path that can reach cameras behind network address translation by serial number, so even non-public devices could be targeted.
Analysts at Hunt.io identified the activity after finding an openly exposed operator directory containing 2,616 files and campaign tooling.
Hunt.io said in a report shared with Cyber Security News (CSN) the recovered material revealed parallel attack paths, persistent access, and an unrelated Windows payload.
The impact goes beyond unauthorized viewing. The toolkit collected credentials, captured camera snapshots, and exported device records in a format designed for large-scale administration.

Researchers also found offline recovery-code generation, creating a route to administrative resets that can remain useful even after a device owner changes a password.
Dahua Camera Backdoor Survives Password Changes
The most serious finding is persistence. After gaining administrator access through CVE-2021-33044 or CVE-2021-33045, the tool adds a separate account through the camera’s remote management interface.
That account is stored independently from the main administrator password, so changing the password does not remove it. On most affected firmware, a factory reset also fails to erase the hidden access. Hunt.io counted 1,923 cameras carrying the account.
That changes the response from a routine password reset into a compromise investigation, especially for organizations using cameras at sensitive sites.
The two flaws used for initial entry have patches available, yet exposed and unpatched cameras remain attractive targets. Readers can see why direct exposure matters in this coverage of threat actors targeting IP cameras, which also tracks authentication weaknesses affecting surveillance devices.

One exploit path impersonates a trusted hardware controller, while the other claims the request came from the camera itself. Both can provide administrator access without a valid password.
Researchers cautioned that a label used in the toolkit for the persistent-account technique points to an unrelated vulnerability, so defenders should focus on the observed behavior rather than that incorrect identifier.
Recovery Codes Expand Risk
The campaign also abused a cloud relay capability to find and contact cameras using serial numbers. According to the recovered logs, 89.4 percent of live serials tested returned a channel that did not require authentication.
That route can bypass the protection normally offered by placing a camera behind a home or business router. Attackers then generated recovery codes offline for live devices.
These codes can support password recovery without knowing the current device credentials. This makes the threat more durable: removing the unauthorized account may not end access.
Organizations should audit every camera account, remove the unauthorized account when found, rotate camera and linked recorder credentials, and review whether footage or passwords were accessed.

Administrators should also disable P2P features when they are not needed, restrict the management service to trusted internal networks, and apply the vendor update that fixes the two bypasses.
Unpatched-camera abuse also appeared in Iranian operations targeting US networks, underlining that camera security is now an operational concern, not a minor maintenance task.
Firmware updates are essential because they prevent new recovery codes from being generated and cause earlier codes to be refreshed and eventually invalidated.
Network teams should alert on suspicious controller or loopback login patterns, while Windows teams should investigate broad security-tool exclusions.
For broader context on the risks posed by exposed video equipment, see the FBI warning on webcam and DVR attacks and the analysis of automated camera exploitation toolkit.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IPv4 | 154.86[.]119.60 |
Operator server that exposed the open directory and staged payloads |
| IPv4 | 185.132[.]53.56 |
Second host where the identical Windows payload was identified |
| Domain:Port | easy4ipcloud[.]com:8800 |
Dahua P2P relay endpoint abused in the campaign; legitimate infrastructure, not inherently malicious |
| URL | vk[.]com/wall-163997495 |
VKontakte link hardcoded into the operator’s Telegram notification template |
| Domains | dahuaddns[.]com, quickddns[.]com |
Dahua DDNS services used for serial-number enumeration; legitimate infrastructure abused by the operator |
| Port | 37777/TCP |
Dahua Easy4IP binary management protocol targeted by the campaign |
| TLS Subject | rbc[.]ru |
Certificate subject presented by the primary host; identified as a widely reused proxy-tool certificate, not a bank-specific compromise indicator |
| Discord | discord[.]gg/cctv |
Community handle included in the recovery-code tool’s console title |
| Credential | p2pwn / p2password |
RPC-installed persistent camera account and primary victim-side artifact |
| Credentials | admin:admin, 666666:666666, 888888:888888, admin:admin123, default:tluafed |
Default credential pairs used by the backdoor tool’s brute-force list |
| Serial prefixes | AH1058FPAG, 3E02C9DPAA, 7K01F36PCA, 5D03CF3PAJ, 3K04B95PAG, 4J00809PAJ, 3L05AF4PAG, 5E00106PAJ, 5F009F7PAJ, 5K09CA1PAJ, 6E0933FPAZ, 3J03016PAG, 5H01308PAJ |
Camera serial prefixes targeted by the serial-number brute-force process |
| SHA-256 | de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c |
Hash for 1.exe / xeno.exe, a UPX-packed Windows payload assessed as SalatStealer |
| SHA-256 | 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8 |
Compiled Go ELF backdoor tool |
| SHA-256 | be2738c8a2beb55ac484d71c329381f3caabac80664283ad9a24dbab82b5b590 |
Operator copy of the backdoor source archive |
| Filename | cidrs.txt |
Renamed IPDeny Russia CIDR list used to drive scanning activity |
| Service | Port 8080 "Telemt Panel" |
Vite/React service observed on the primary operator host |
| Windows path | C:UsersSystemXDownloadsseria |
Development path exposed in a Windows-side test log |
| PTR | rogue-orbit-ryzhuuxu.expresshost.cloud |
Reverse-DNS hostname for the primary host; provider naming convention |
| Domain | oxycod[.]one |
Legitimate personal domain associated with the second host’s pre-existing history |
| SSH fingerprint SHA-256 | 570963ee5a1253832c80e95ebb34dca5fe0f6bf7437857dcae511fbb023ed109 |
SSH host-key fingerprint associated with the primary host |
| SHA-256 | 7a963211a052a78899a8881d36b42b55690c02e95c1485f5d78d3cfdb3d2842a |
Original serial brute-force script at /CVE-2025-31702-main/dahua-sn-brute2.py |
| SHA-256 | 083c9ee06ed2ee1bc0051358b3eeb3242f474eacea4c88b3b10b06d15389b753 |
Mid-rewrite serial brute-force script at /cve-project/dahua-sn-brute2.py |
| SHA-256 | 5f60e5b45ecd67a987bdb1173d6a8063aa20a7946377da4698aaba3ebe72d088 |
Fully Russified serial brute-force script at /cve-2025-31702/dahua-sn-brute2.py |
| SHA-256 | 4a4a346df72c839272ea835e4717cd88f843333b3563e745e657895347ea3dbe |
Active serial brute-force launcher at /cve-project/start_all.sh |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices appeared first on Cyber Security News.
