Skip to content
Spike in attacks targeting digital video recorders in Ukraine

Spike in attacks targeting digital video recorders in Ukraine

Greynoise • October 8, 2026

GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an escalation in Russian strikes across the country. There are a myriad of malicious use cases for compromising DVRs; one involves gaining the ability to physically survey an area to gain battlespace awareness before, during, and after kinetic strikes .

The majority of related activity GreyNoise observed focused on exploitation of CVE-2021-36260 , which allows unauthenticated command injection against unpatched Hikvision products. The actors used the Hikvision IP camera/NVR - Remote Command Execution nuclei template.

The activity involved three PureVPN exit nodes and one Ukrainian domestic IP address. GreyNoise assesses the PureVPN-associated activity is attributable to a single entity; the activity from the domestic UA IP is possibly related (low confidence). GreyNoise did generally observe a spike in detection of exploitation and scanning attempts against CVE-2021-36260 globally; however, the four IP addresses did not attempt to exploit any of our sensors outside of Ukraine. GreyNoise observed almost no activity like this against Ukraine in the months prior, and none from these four IPs.

PureVPN is a commercial virtual private network provider; activity from these exit nodes may not be related due to legitimate shared use.

Extracted Entities