ThreatCluster

Exploitation of Ukrainian IP Cameras Using Custom Tooling by Russian Operator

First seen 11 Aug 2026, 02:04 UTC Reddit 77% similarity 73

Article Content

Browse articles
ThreatCluster

A Russian-speaking operator has been identified using a custom Docker project named camview to exploit and stream IP cameras in Ukraine. The tool, built with FastAPI, wraps the open-source Ingram scanner and employs a 3,811-entry dictionary to brute-force camera credentials over HTTP and RTSP. The operator's logs indicate live viewing sessions from 58 Ukrainian cameras, highlighting the scale of the operation. Notable CVEs targeted include CVE-2017-7921, CVE-2021-36260, CVE-2021-33044, CVE-2020-25078, and CVE-2024-53375. Additionally, the operator utilized a proxy script to relay traffic through compromised networks. The exploitation method leverages known vulnerabilities and public tools, indicating a sophisticated yet opportunistic approach. The current status of the operation remains active, with no state attribution confirmed.

Key Points: • A Russian operator exploited 58 Ukrainian IP cameras using a custom tool named camview. • The attack method involved brute-forcing credentials and leveraging known CVEs. • The operation utilized a proxy script to relay traffic through compromised networks.

ThreatCluster AI How this analysis works

Timeline

2021-01-26
CVE-2020-25169 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-09-22
CVE-2021-36260 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-08-21
CVE-2021-33044 added to CISA KEV
CVE-2021-33044 was added to the CISA KEV list, highlighting its exploitation in the wild.
Article 2
2024-12-02
CVE-2024-53375 published
CVE-2024-53375 was published, affecting TP-Link devices and linked to the operator's toolkit.
Article 2
2025-02-18
CVE-2024-57049 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-08-05
CVE-2020-25078 added to CISA KEV
CVE-2020-25078 was added to the CISA KEV list, indicating active exploitation of the vulnerability.
Article 2
2026-03-05
CVE-2017-7921 added to CISA KEV
CVE-2017-7921, affecting various camera brands, was added to the CISA KEV list due to active exploitation.
Article 2
Recent
Operator's toolkit analyzed
Hunt.io researchers reconstructed the operator's tooling from open directories, revealing the exploitation methods used.
Article 2

Community

Browse all →

Tracked Entities in This Story