VYPR
breachPublished Sep 4, 2026· 1 source

Dahua Camera Backdoor Persists Through Resets, Exposing 14,000+ Devices

A widespread campaign has compromised over 14,000 Dahua cameras, establishing persistent backdoor accounts that survive password changes and factory resets, granting attackers ongoing access to video feeds and device settings.

A significant cyber campaign has successfully compromised more than 14,000 internet-connected Dahua cameras globally, turning these surveillance devices into persistent gateways for attackers to access video feeds and sensitive device settings. The operation, which ran for 35 days, primarily targeted devices in Ukraine and Russia but had a worldwide impact, underscoring the risks posed by unsecured IoT devices.

The attackers employed a multi-pronged approach, first scanning for exposed camera management services and attempting to exploit weak credentials. Crucially, they leveraged two known authentication-bypass vulnerabilities, CVE-2021-33044 and CVE-2021-33045, to gain initial administrator access on unpatched devices. This initial compromise was the gateway to establishing a durable, hidden access mechanism.

One of the most alarming aspects of this campaign is the persistence of the backdoor. After gaining administrator privileges, the attackers installed a separate, hidden account through the camera's remote management interface. This account operates independently of the main administrator password, meaning that changing the primary password does not remove the unauthorized access. Furthermore, on most affected firmware versions, even a factory reset fails to eliminate this persistent backdoor, leaving devices vulnerable.

Adding to the persistence, the campaign utilized a cloud relay path, enabling attackers to reach cameras even if they were behind network address translation (NAT) firewalls. By using device serial numbers, attackers could establish a connection through legitimate Dahua P2P relay endpoints, effectively bypassing traditional network perimeter defenses. This allowed for targeting of devices that were not directly exposed to the public internet.

Researchers from Hunt.io, who identified the activity, recovered a trove of campaign tooling and data, including 2,616 files from an openly exposed operator directory. This material revealed parallel attack paths, the sophisticated persistence techniques, and even an unrelated Windows payload, suggesting a broader toolkit at the attacker's disposal. The recovered toolkit was capable of collecting credentials, capturing snapshots, and exporting device records in a format suitable for large-scale management.

Beyond the persistent account, the attackers also abused an offline recovery code generation process. These codes can facilitate password recovery without requiring knowledge of current device credentials, further enhancing the threat's durability. This means that even if an unauthorized account is detected and removed, the ability for attackers to regain access through recovery codes remains a significant risk.

While patches for CVE-2021-33044 and CVE-2021-33045 are available, the continued exploitation highlights the persistent problem of unpatched devices in the wild. Organizations using Dahua cameras are urged to audit all camera accounts, remove any unauthorized accounts, rotate credentials for cameras and linked recorders, and investigate any potential compromise of footage or passwords. Disabling P2P features when not needed, restricting management services to trusted internal networks, and applying vendor firmware updates are critical mitigation steps.

The campaign's sophistication and the persistence of its backdoors serve as a stark reminder that surveillance equipment security is a critical operational concern. The ability for attackers to maintain access through password changes and factory resets transforms a routine security task into a complex investigation, demanding vigilance and proactive security measures from organizations worldwide.

Synthesized by Vypr AI