Inside a Russian-speaking operator’s toolkit for compromising Ukrainian IP cameras
Hunt.io researchers analyzed two open directories recovered through our Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine. Technical highlights: A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink) The operator’s logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator’s traffic through the victim network A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444 No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup submitted by /u/Straight-Practice-99 [link] [comments]Technical Information Security Content & DiscussionRead More