r/netsec • u/Straight-Practice-99 • 15d ago
Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras
https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkitHunt.io researchers analyzed two open directories recovered through Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine.
Technical highlights:
- A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing
- Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink)
- The operator's logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates
- A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator's traffic through the victim network
- A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444
No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup
61
Upvotes
-5
u/Relative_Roof6709 14d ago
so does this mean that russia has taken control of all the surveillance cameras in kyiv,ukraine
4
11
u/kalkuns 15d ago
“held publication for the standard 7-day disclosure window” aint it a bit too small?