🔐
Security 📅 2026-08-20 · 03:56 AM IST ⏱ 3 min read

Major Cyber Campaign Targets Central Asian Governments Through Hacked Security Cameras

Over 14,500 Dahua surveillance devices breached in espionage operation using newly discovered attack tools.

A Shadow Operation Unfolds

Security researchers have uncovered a sophisticated hacking campaign that has successfully infiltrated more than 14,500 devices manufactured by Dahua, one of the world's largest makers of surveillance and security equipment. The operation, now tracked under the name SilkParasite, appears designed to spy on government agencies across Central Asia, exploiting weaknesses in how these devices handle login credentials and access controls.

What makes this discovery particularly alarming is not just the scale of the breach, but the tools the attackers created to pull it off. The hackers developed seven different remote access programs—think of them as digital keys that let attackers control computers from afar—with five of these tools being completely new to the cybersecurity world. These newly discovered programs carry names like DriveSilkRAT, CookiETagRAT, and NomadRAT, identifying them as previously unknown weapons in the attacker's arsenal.

Understanding the Attack Method

The intrusions worked through three main approaches. First, attackers used credential attacks, meaning they either obtained or guessed login information—usernames and passwords—to access the devices. Second, they exploited authentication bypasses, essentially finding digital back doors that let them slip past security checkpoints without proper credentials. Third, they leveraged P2P (peer-to-peer) technology, which is a network method where devices communicate directly with each other rather than through a central server.

To understand this in everyday terms: imagine a building with locked doors (the devices). Attackers either stole the keys (credentials), found hidden passages (authentication bypasses), or befriended someone inside who could let them pass messages through the walls (P2P networks). Once inside, they installed their custom tools to maintain control and gather information.

What This Means

This operation represents a concerning shift in how nation-state hackers target critical infrastructure. Rather than attempting dramatic, headline-grabbing attacks, this campaign focuses on quietly establishing long-term spy networks within government facilities. The surveillance cameras and related security devices they compromised likely provided the attackers with visual access to sensitive locations, building layouts, security procedures, and personnel movements.

The discovery of five previously unknown attack tools suggests this operation has been running undetected for some time, with the attackers continuously developing new capabilities to avoid detection and stay ahead of security defenses.

Why You Should Care

Even if you don't work for a Central Asian government, this matters to you. First, these same vulnerabilities could affect Dahua devices installed elsewhere around the world, including potentially in your country. Second, the techniques and tools developed here often get shared or copied by other criminal groups. Third, this demonstrates how everyday security devices—cameras and sensors we often ignore—can become entry points for sophisticated attackers.

What You Can Do

This incident serves as a reminder that sophisticated hackers view even "simple" devices as valuable targets worthy of sustained attention and investment in custom tools.

📎 This is original ITVedas reporting. This story was inspired by coverage from source. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →