# 14,500 Eyes for the Taking: Inside the 35-Day Dahua Camera Sweep


Someone just handed an attacker a surveillance network.


Over 35 days, threat actors systematically compromised 14,500 Dahua IP cameras — devices deployed in warehouses, parking structures, retail stores, hospital lobbies, government buildings, and apartment complexes around the world. The campaign wasn't opportunistic noise. The pace and consistency suggest automated scanning tools walking down a target list, checking credentials or probing known CVEs, then moving on. This is industrial-scale reconnaissance turned into infrastructure acquisition.


Dahua doesn't get the same mainstream press as, say, a healthcare breach or a ransomware hit on a city government. But in the security community, the name carries weight — and not the good kind.


## The Dahua Dossier


Dahua Technology is one of the two largest surveillance camera manufacturers on earth. The other is Hikvision. Both are Chinese state-linked firms. Both were added to the FCC's Covered List in 2022, effectively banning them from US federal networks. Both continue to appear in critical infrastructure deployments anyway, because procurement decisions made five and ten years ago don't disappear overnight, and because price still wins purchasing arguments more often than security posture does.


Dahua's vulnerability record is long and well-documented. CVE-2021-33044 and CVE-2021-33045 — authentication bypass flaws disclosed in 2021 — allowed unauthenticated attackers to take full control of affected cameras without so much as a username. Dahua patched them. Patches require firmware updates. Firmware updates require someone to apply them. On a camera bolted to a parking garage ceiling, nobody applies firmware updates.


The pattern here isn't new. It's the same pattern we saw with Mirai in 2016, when Dahua and Hikvision devices made up a significant fraction of the botnet that knocked Dyn's DNS infrastructure offline and took down half the internet's favorite websites for an afternoon. It's the same pattern we saw with Moobot, with Beastmode, with a dozen other IoT botnets that found these cameras to be ripe, undefended, and plentiful.


## What 14,500 Cameras Actually Buys You


The question defenders need to ask isn't just "how did attackers get in?" It's "what are they doing once inside?"


At minimum, compromised cameras become botnet nodes — reliable, low-power, always-on devices with decent uptime and outbound internet access, useful for DDoS amplification or as proxies to launder attack traffic. But the more disturbing possibility is the obvious one: these are cameras. They have lenses. They're pointed at things.


A compromised camera in a hospital lobby can capture patient foot traffic patterns, staff badge access timing, physical security procedures. One in a warehouse can map inventory and logistics workflows. One outside a government building can track personnel movements. Threat actors associated with espionage operations — and Dahua's ties to the Chinese government are not theoretical — have genuine intelligence interest in this kind of persistent visual access.


The 35-day duration of this campaign is worth pausing on. That's not a smash-and-grab. That's a methodical sweep, likely with tool-assisted scanning, followed by credential stuffing or exploit application, followed by implant installation and persistence mechanisms. Whoever is behind this was building something, not just counting coup.


## The Unpatched Reality


The security community has been warning about IoT device hygiene for the better part of a decade. The warnings haven't moved the needle enough.


The core problem is structural. Camera deployments are often handled by physical security integrators, not IT or infosec teams. The devices get installed, tested for image quality, handed off, and forgotten. Firmware update procedures don't get documented. Default credentials — often something like admin/admin or 888888/888888 on older Dahua units — never get rotated. Network segmentation that would contain a compromise often doesn't exist, because the camera system was wired into the same flat LAN as everything else.


And then there's the supply chain question that nobody wants to fully answer: if your surveillance infrastructure is manufactured by a company with documented ties to a foreign government that has strategic interests in what your cameras see, "apply the patch" may not be the complete solution.


## For Defenders: What to Actually Do Right Now


If your organization runs Dahua cameras, the action items are specific:


Inventory first. Many security teams genuinely don't know what camera firmware versions are running. Pull the list. Cross-reference against Dahua's security advisories. Any device running firmware older than 2022 should be treated as compromised until proven otherwise.


Network segment. Camera VLANs should not have unrestricted outbound internet access. Legitimate camera systems don't need to call home to arbitrary external IPs. Firewall rules that restrict camera traffic to known update servers and NVR/VMS endpoints will limit attacker utility even on compromised devices.


Credential rotation is not optional. Any Dahua device still running default credentials is not a security device. It's a liability.


Consider the replacement calculus. For organizations covered by federal procurement rules or operating in sensitive sectors, the question of whether to continue running FCC Covered List devices isn't just technical. It's compliance and risk posture.


Monitor outbound traffic. Compromised cameras trying to reach C2 infrastructure will generate unusual outbound connections. If you're not watching that, you won't see it.


---


## HackWire Analysis


The Dahua campaign sits at the intersection of three trends that aren't slowing down.


First: IoT as attack infrastructure. Botnet operators have known for years that consumer and commercial IoT devices are the path of least resistance to building persistent, globally distributed networks. Cameras are better than routers for certain use cases — they tend to have more stable connections, lower churn, and better uptime. As defenders have gotten better at locking down traditional endpoints, attackers have doubled down on the unmanaged device layer.


Second: the supply chain trust problem hasn't been resolved, it's been papered over. The FCC added Dahua and Hikvision to the Covered List. The Department of Defense has procurement restrictions. But there are hundreds of thousands — likely millions — of these devices already deployed in US commercial and government-adjacent infrastructure, and removal has been slow and underfunded. The 14,500 figure in this campaign is almost certainly a floor, not a ceiling.


Third: the intelligence community has been explicit that Chinese state-affiliated actors are pre-positioning inside US infrastructure for potential future use. VOLT TYPHOON, the campaign targeting critical infrastructure for exactly this kind of dormant access, was disclosed in 2023. Camera networks offer a variant of the same capability — persistent, low-profile access with real-world intelligence value. The 35-day disciplined sweep in this campaign is behaviorally consistent with a deliberate collection operation, not vandalism.


Most coverage of IoT compromises focuses on the botnet angle because it's the most measurable outcome. The harder, less visible risk is that some fraction of these 14,500 cameras are now providing someone with a persistent window into physical spaces that nobody thinks of as "hacked."


That's the story other coverage is missing.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)