Russian Intelligence Hijacks IP Cameras to Monitor Weapons Deliveries to Ukraine

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

Russian intelligence services have been accused of turning everyday internet-connected cameras into surveillance tools for tracking weapons deliveries to Ukraine.

The campaign shows how a device installed for basic security can become a source of military intelligence when it is left exposed online.

The operation targets cameras in the Netherlands, other EU and NATO countries, and Ukraine.

Its apparent purpose is to observe transport routes, weapons shipments, and the locations of Ukrainian military personnel without needing to penetrate a military network.

Analysts from AIVD and Censys identified the activity as part of a wider Russian espionage effort that relies on compromised camera feeds.

The findings underline that video from a petrol station, warehouse entrance, or roadside business can reveal far more than its owner may expect.

Censys said in a report shared with Cyber Security News (CSN) that artificial intelligence can help analysts process images from multiple cameras and connect isolated sightings into a broader picture of movements and military locations.

This makes even a single overlooked camera valuable to an espionage operation.

Russian Intelligence Hijacks IP Camera

The campaign does not depend on a new piece of malware with a public name. Instead, it relies on gaining access to poorly protected or unpatched IP cameras, then using the live feeds as a low-cost reconnaissance source.

Russian operators can use footage to identify vehicle types, follow convoy movements, and establish patterns around facilities that support Ukraine.

Cameras on the Internet (Source – Censys)

A camera pointing at a public road may capture passing equipment, while one near a loading area can expose delivery schedules and security routines.

This threat is especially serious because cameras are often managed separately from core IT systems.

Security teams may monitor servers and employee devices closely, yet forget an ageing camera that has been connected directly to the public internet for years.

The risk is not limited to government or military sites. As coverage of IP camera attacks across regions has shown, surveillance devices can be exploited for intelligence gathering wherever they expose physical activity, including transport hubs, utilities, manufacturers, and commercial premises.

Censys found more than 45,000 cameras directly accessible from the public internet in the Netherlands alone.

Nearly 2,000 associated hosts appeared to have an unpatched vulnerability known to be exploited in real-world attacks, although the vulnerable service was not necessarily the camera software itself.

The researchers also identified 541 camera services that appeared exposed through known exploited vulnerabilities in camera software.

Across EU and NATO countries plus Ukraine, the dataset contained more than 87,000 potentially exploitable internet-connected cameras, including more than 4,000 in Ukraine.

Old software remains a major concern. The report highlighted devices exposed through long-known weaknesses, reinforcing why organisations should treat a camera’s firmware, web interface, and remote-access services as security-critical components rather than simple facilities equipment.

Reducing Surveillance Risk

The first defensive step is to identify every camera and related service exposed to the internet.

Organisations cannot secure devices they do not know exist, especially when old installations, temporary deployments, or outsourced systems may have escaped normal asset-management processes.

Once identified, camera operators should apply current firmware and software updates, replace equipment that is no longer supported, and use strong, unique access credentials.

The advice closely matches guidance in camera command injection warnings, where limiting public exposure and isolating device networks are central safeguards.

Direct internet access should be removed wherever possible. Cameras should sit behind firewalls, use tightly controlled remote access, and be separated from business networks so that a compromised device cannot become a path to more sensitive systems.

Operators should also review what each camera can see. A feed intended to protect a gate may unintentionally reveal a road, loading dock, fuel stop, security post, or staff routine that is useful to an adversary. Limiting the field of view can reduce that intelligence value.

Security teams should watch for unusual logins, configuration changes, outbound connections, and unexplained viewing activity.

Recent reporting on unauthenticated camera code execution illustrates how exposed management services can allow an attacker to take control without normal user access.

The broader lesson is that physical security technology now carries cyber risk. A camera may hold no documents or customer records, but a live stream can still disclose operations, schedules, entrances, vehicle movements, and other details that support targeting.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.