Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
North Korean Hackers Use Fake macOS Installers to Deliver RAT
September 4, 2026
Critical Dahua Camera Backdoor Persists After Factory Reset CVE-2023-XXXX
September 4, 2026
Critical Chrome 0-Day CVE-2023-XXXX Actively Exploited
September 4, 2026
Home/Threats/Critical Dahua Camera Backdoor Persists After Factory Reset CVE-2023-XXXX
Threats

Critical Dahua Camera Backdoor Persists After Factory Reset CVE-2023-XXXX

Key Takeaways More than 14,000 internet-connected Dahua cameras were compromised in a 35-day campaign. Attackers exploited known authentication bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045)...

Emy Elsamnoudy
Emy Elsamnoudy
September 4, 2026 4 Min Read
2 0

Key Takeaways

  • More than 14,000 internet-connected Dahua cameras were compromised in a 35-day campaign.
  • Attackers exploited known authentication bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045) and weak credentials.
  • A critical backdoor allows persistent administrative access that survives password changes and, in most cases, factory resets.
  • The campaign leveraged Dahua’s cloud relay service to target cameras even behind NAT.
  • Patches are available for the initial access flaws, but many devices remain unpatched.

Thousands of Dahua Cameras Compromised with Persistent Backdoor

A widespread cyberattack has infiltrated over 14,000 internet-connected Dahua surveillance cameras, revealing a concerning vulnerability in security infrastructure. This extensive 35-day operation highlights how easily compromised surveillance equipment can provide long-term, stealthy access to video feeds and device configurations for malicious actors.

Table Of Content

  • Key Takeaways
  • Thousands of Dahua Cameras Compromised with Persistent Backdoor
  • Attack Methodology and Discovery
  • Dahua Camera Backdoor Survives Resets and Password Changes
  • Recovery Codes Expand Risk
  • What You Should Do

The global campaign saw significant concentrations of compromised devices in Ukraine and Russia. It underscores a persistent challenge in cybersecurity: unattended internet-of-things (IoT) devices can become entrenched footholds for adversaries, providing durable and hidden access points.

Attack Methodology and Discovery

The attackers initiated their campaign by scanning for exposed camera management interfaces. They then attempted to exploit devices using common weak credentials and two previously identified authentication-bypass vulnerabilities, CVE-2021-33044 and CVE-2021-33045, targeting unpatched systems.

A particularly insidious aspect of the attack involved exploiting a cloud relay mechanism. This allowed attackers to reach cameras even when they were situated behind Network Address Translation (NAT) by using their serial numbers. This bypasses a common network security measure, making even non-public devices susceptible to targeting.

The activity was brought to light by analysts at Hunt.io, who discovered an openly accessible operator directory containing 2,616 files and the campaign’s operational tooling. Hunt.io said in a report that their analysis of the recovered materials revealed multiple attack vectors, mechanisms for persistent access, and an unrelated Windows-specific payload.

Beyond simply viewing live feeds, the attackers’ toolkit was designed for comprehensive control. It facilitated the collection of credentials, captured camera snapshots, and enabled the export of device records in a format optimized for large-scale administrative tasks. Furthermore, researchers uncovered methods for generating offline recovery codes, which could grant administrative reset capabilities even after a legitimate owner changed their device password.

Dahua Camera Backdoor Survives Resets and Password Changes

The most alarming discovery is the sophisticated persistence mechanism. After successfully gaining administrator privileges, typically through the exploitation of CVE-2021-33044 or CVE-2021-33045, the attackers installed a separate, unauthorized account via the camera’s remote management interface. This rogue account operates independently of the primary administrator password, meaning that a password change by the legitimate owner does not remove the backdoor. In fact, for the majority of affected firmware versions, even a factory reset fails to eradicate this hidden access. Hunt.io identified this persistent account on 1,923 cameras.

This level of persistence elevates the response to a suspected compromise from a simple password reset to a full-scale forensic investigation, particularly critical for organizations deploying these cameras in sensitive locations.

While patches for the initial authentication bypass flaws are available, a significant number of Dahua cameras remain unpatched and exposed, making them attractive targets. The exploitation methods leverage vulnerabilities that allow attackers to impersonate trusted hardware controllers or make requests appear to originate from the camera itself, both leading to unauthorized administrator access.

Researchers noted that a label within the recovered toolkit for the persistent account technique references an unrelated vulnerability. Therefore, defenders should prioritize the observed behavior and indicators of compromise rather than relying on this potentially misleading identifier.

Recovery Codes Expand Risk

The campaign further exploited a cloud relay feature, allowing attackers to locate and communicate with cameras using their serial numbers. Logs indicate that 89.4% of tested live serial numbers returned a channel that did not require authentication. This effectively bypasses the security typically provided by placing a camera behind a router, exposing devices that might otherwise be considered protected. Attackers then used this access to generate offline recovery codes for live devices. These codes enable password recovery without needing the existing device credentials, making the threat even more enduring as removing the unauthorized account may not permanently revoke access.

The broad implications of unpatched surveillance equipment are not new. Similar abuses of unpatched cameras have been observed in operations targeting US networks, emphasizing that camera security is a critical operational concern, not merely a minor maintenance detail.

What You Should Do

  • Audit All Accounts: Conduct a thorough audit of all accounts on every Dahua camera.
  • Remove Unauthorized Accounts: Immediately remove any unauthorized or suspicious accounts found.
  • Rotate Credentials: Change passwords for all camera accounts and any linked recording devices.
  • Investigate Access: Determine if footage, device settings, or passwords were accessed or exfiltrated.
  • Disable P2P: If not essential, disable Peer-to-Peer (P2P) features on your cameras.
  • Restrict Management Access: Limit camera management services to trusted internal networks only.
  • Apply Firmware Updates: Promptly apply all available firmware updates from Dahua to patch CVE-2021-33044 and CVE-2021-33045, and to prevent the generation of new recovery codes while invalidating old ones.
  • Monitor Network Activity: Network teams should implement alerts for suspicious controller or loopback login patterns.
  • Review Security Tool Exclusions: Windows teams should investigate any broad security tool exclusions that might hide malicious activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Chrome 0-Day CVE-2023-XXXX Actively Exploited

Next Post

North Korean Hackers Use Fake macOS Installers to Deliver RAT

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical ConnectWise ScreenConnect Vulnerabilities Let Attackers Spread Malware
September 3, 2026
Phantom Deal Hackers Impersonate Execs, Use Fake NDAs to Steal Wire Transfers
September 3, 2026
Claude AI Outage Impacts Mythos, Fable, and Opus Products
September 3, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us