Recent findings reveal that Russian intelligence services are systematically compromising internet-connected security cameras across Europe and Ukraine. This operation aims to monitor military transport routes, weapons shipments to Kyiv, and the positioning of Ukrainian troops.
The Netherlands’ civilian and military intelligence agencies, AIVD and MIVD, detailed this ongoing surveillance in a cybersecurity advisory published on July 10. The report indicates that in Ukraine, the hijacked camera feeds have been utilized not only for observation but also to facilitate direct attacks on military personnel and equipment.
In EU and NATO member states, the compromised cameras are being exploited to gather military intelligence unrelated to the conflict in Ukraine. The method employed by Russian operatives involves scanning the internet for exposed devices, identifying IP cameras by brand, and accessing those with default passwords, outdated firmware, or unchanged factory settings.
Once access is gained, image-recognition software analyzes the video feeds, automatically detecting military vehicles and their cargo. Notably, this infiltration does not require sophisticated zero-day exploits; rather, it capitalizes on basic security oversights.
Extent of Camera Vulnerabilities
The scale of this vulnerability is significant. Internet-scanning firm Censys reports over 87,000 internet-connected cameras across the EU, NATO countries, and Ukraine running services with known-exploited vulnerabilities. In Ukraine alone, more than 4,000 such cameras have been identified.
In the Netherlands, Censys found 45,386 cameras accessible from the public internet, with 1,992 running services with known vulnerabilities. Narrowing the focus to vulnerabilities within the camera software itself, 541 cameras were identified. These figures underscore the widespread nature of the issue.
It’s important to note that while a camera being publicly accessible doesn’t inherently make it hackable, the presence of known vulnerabilities significantly increases the risk. For instance, vulnerabilities like CVE-2016-7407 in Dropbear SSH server and CVE-2021-39275 in Apache HTTP Server have been exploited in the wild, though they are not listed in CISA’s Known Exploited Vulnerabilities catalog.
Despite the vast number of potentially vulnerable devices, Dutch intelligence services have identified only a small number of cameras that have been actively breached. These compromised devices were located directly on military logistics routes within the Netherlands, and the responsible organizations have been notified to implement necessary security measures.
This development highlights the critical need for robust cybersecurity practices, especially concerning IoT devices like security cameras. Organizations must ensure that default credentials are changed, firmware is regularly updated, and devices are configured securely to prevent unauthorized access.