Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A large campaign has compromised more than 14,000 internet-connected Dahua cameras, exposing how vulnerable surveillance equipment can become a gateway to video feeds and device settings.

The operation ran for 35 days, and hit devices worldwide, with confirmed compromises centered in Ukraine and Russia. It shows how unattended devices can create durable, long-lasting hidden access for intruders.

The operator scanned for exposed camera management services, tried weak credentials, and used two known authentication-bypass flaws against unpatched devices.

It also used a cloud relay path that can reach cameras behind network address translation by serial number, so even non-public devices could be targeted.

Analysts at Hunt.io identified the activity after finding an openly exposed operator directory containing 2,616 files and campaign tooling.

Hunt.io said in a report shared with Cyber Security News (CSN) the recovered material revealed parallel attack paths, persistent access, and an unrelated Windows payload.

The impact goes beyond unauthorized viewing. The toolkit collected credentials, captured camera snapshots, and exported device records in a format designed for large-scale administration.

Attack chain (Source - Hunt.io)
Attack chain (Source – Hunt.io)

Researchers also found offline recovery-code generation, creating a route to administrative resets that can remain useful even after a device owner changes a password.

Dahua Camera Backdoor Survives Password Changes

The most serious finding is persistence. After gaining administrator access through CVE-2021-33044 or CVE-2021-33045, the tool adds a separate account through the camera’s remote management interface.

That account is stored independently from the main administrator password, so changing the password does not remove it. On most affected firmware, a factory reset also fails to erase the hidden access. Hunt.io counted 1,923 cameras carrying the account.

That changes the response from a routine password reset into a compromise investigation, especially for organizations using cameras at sensitive sites.

The two flaws used for initial entry have patches available, yet exposed and unpatched cameras remain attractive targets. Readers can see why direct exposure matters in this coverage of threat actors targeting IP cameras, which also tracks authentication weaknesses affecting surveillance devices.

async_brute.py (Source – Hunt.io)

One exploit path impersonates a trusted hardware controller, while the other claims the request came from the camera itself. Both can provide administrator access without a valid password.

Researchers cautioned that a label used in the toolkit for the persistent-account technique points to an unrelated vulnerability, so defenders should focus on the observed behavior rather than that incorrect identifier.

Recovery Codes Expand Risk

The campaign also abused a cloud relay capability to find and contact cameras using serial numbers. According to the recovered logs, 89.4 percent of live serials tested returned a channel that did not require authentication.

That route can bypass the protection normally offered by placing a camera behind a home or business router. Attackers then generated recovery codes offline for live devices.

These codes can support password recovery without knowing the current device credentials. This makes the threat more durable: removing the unauthorized account may not end access.

Organizations should audit every camera account, remove the unauthorized account when found, rotate camera and linked recorder credentials, and review whether footage or passwords were accessed.

Both payloads side by side (Source – Hunt.io)

Administrators should also disable P2P features when they are not needed, restrict the management service to trusted internal networks, and apply the vendor update that fixes the two bypasses.

Unpatched-camera abuse also appeared in Iranian operations targeting US networks, underlining that camera security is now an operational concern, not a minor maintenance task.

Firmware updates are essential because they prevent new recovery codes from being generated and cause earlier codes to be refreshed and eventually invalidated.

Network teams should alert on suspicious controller or loopback login patterns, while Windows teams should investigate broad security-tool exclusions.

For broader context on the risks posed by exposed video equipment, see the FBI warning on webcam and DVR attacks and the analysis of automated camera exploitation toolkit.

Indicators of compromise (IoCs):-

Type Indicator Description
IPv4 154.86[.]119.60 Operator server that exposed the open directory and staged payloads
IPv4 185.132[.]53.56 Second host where the identical Windows payload was identified
Domain:Port easy4ipcloud[.]com:8800 Dahua P2P relay endpoint abused in the campaign; legitimate infrastructure, not inherently malicious
URL vk[.]com/wall-163997495 VKontakte link hardcoded into the operator’s Telegram notification template
Domains dahuaddns[.]comquickddns[.]com Dahua DDNS services used for serial-number enumeration; legitimate infrastructure abused by the operator
Port 37777/TCP Dahua Easy4IP binary management protocol targeted by the campaign
TLS Subject rbc[.]ru Certificate subject presented by the primary host; identified as a widely reused proxy-tool certificate, not a bank-specific compromise indicator
Discord discord[.]gg/cctv Community handle included in the recovery-code tool’s console title
Credential p2pwn / p2password RPC-installed persistent camera account and primary victim-side artifact
Credentials admin:admin666666:666666888888:888888admin:admin123default:tluafed Default credential pairs used by the backdoor tool’s brute-force list
Serial prefixes AH1058FPAG3E02C9DPAA7K01F36PCA5D03CF3PAJ3K04B95PAG4J00809PAJ3L05AF4PAG5E00106PAJ5F009F7PAJ5K09CA1PAJ6E0933FPAZ3J03016PAG5H01308PAJ Camera serial prefixes targeted by the serial-number brute-force process
SHA-256 de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c Hash for 1.exe / xeno.exe, a UPX-packed Windows payload assessed as SalatStealer
SHA-256 694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8 Compiled Go ELF backdoor tool
SHA-256 be2738c8a2beb55ac484d71c329381f3caabac80664283ad9a24dbab82b5b590 Operator copy of the backdoor source archive
Filename cidrs.txt Renamed IPDeny Russia CIDR list used to drive scanning activity
Service Port 8080 "Telemt Panel" Vite/React service observed on the primary operator host
Windows path C:UsersSystemXDownloadsseria Development path exposed in a Windows-side test log
PTR rogue-orbit-ryzhuuxu.expresshost.cloud Reverse-DNS hostname for the primary host; provider naming convention
Domain oxycod[.]one Legitimate personal domain associated with the second host’s pre-existing history
SSH fingerprint SHA-256 570963ee5a1253832c80e95ebb34dca5fe0f6bf7437857dcae511fbb023ed109 SSH host-key fingerprint associated with the primary host
SHA-256 7a963211a052a78899a8881d36b42b55690c02e95c1485f5d78d3cfdb3d2842a Original serial brute-force script at /CVE-2025-31702-main/dahua-sn-brute2.py
SHA-256 083c9ee06ed2ee1bc0051358b3eeb3242f474eacea4c88b3b10b06d15389b753 Mid-rewrite serial brute-force script at /cve-project/dahua-sn-brute2.py
SHA-256 5f60e5b45ecd67a987bdb1173d6a8063aa20a7946377da4698aaba3ebe72d088 Fully Russified serial brute-force script at /cve-2025-31702/dahua-sn-brute2.py
SHA-256 4a4a346df72c839272ea835e4717cd88f843333b3563e745e657895347ea3dbe Active serial brute-force launcher at /cve-project/start_all.sh

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices appeared first on Cyber Security News.