Exploitation of Ukrainian IP Cameras Using Custom Tooling by Russian Operator
Article Content
- •A Russian operator exploited 58 Ukrainian IP cameras using a custom tool named camview.
- •The attack method involved brute-forcing credentials and leveraging known CVEs.
- •The operation utilized a proxy script to relay traffic through compromised networks.
A Russian-speaking operator has been identified using a custom Docker project named camview to exploit and stream IP cameras in Ukraine. The tool, built with FastAPI, wraps the open-source Ingram scanner and employs a 3,811-entry dictionary to brute-force camera credentials over HTTP and RTSP. The operator's logs indicate live viewing sessions from 58 Ukrainian cameras, highlighting the scale of the operation. Notable CVEs targeted include CVE-2017-7921, CVE-2021-36260, CVE-2021-33044, CVE-2020-25078, and CVE-2024-53375. Additionally, the operator utilized a proxy script to relay traffic through compromised networks. The exploitation method leverages known vulnerabilities and public tools, indicating a sophisticated yet opportunistic approach. The current status of the operation remains active, with no state attribution confirmed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Chisel and CVE-2017-7921 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Breeze Comet Targets Brazilian Financial Sector with Systemic Fraud Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and eCommerce organizations, executing hundreds of fraudulent transactions via the Pix payment system. This group, previously known as UNC5669, employs tactics such as password spraying and social…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…