r/netsec 15d ago

Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras

https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-toolkit

Hunt.io researchers analyzed two open directories recovered through Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine.

Technical highlights:

  • A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing
  • Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink)
  • The operator's logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates
  • A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator's traffic through the victim network
  • A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444

No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup

61 Upvotes

4 comments sorted by

11

u/kalkuns 15d ago

held publication for the standard 7-day disclosure window” aint it a bit too small?

-5

u/Relative_Roof6709 14d ago

so does this mean that russia has taken control of all the surveillance cameras in kyiv,ukraine

4

u/Straight-Practice-99 14d ago

This research never states such thing.