Full Report
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence
Analysis Summary
# Threat Actor: Unnamed Russian Intelligence Service(s)
## Attribution & Identity
* **Identification:** Attributed to at least one Russian intelligence service by the AIVD (General Intelligence and Security Service) and MIVD (Military Intelligence and Security Service) of the Netherlands.
* **Aliases/Associations:** Referred to generally as "Russian state actors." While specific Unit numbers (e.g., Unit 26165 or 74455) are not explicitly named in this article, the activities align with Russian military and civilian intelligence mandates.
## Activity Summary
* **Campaign Description:** A systematic, ongoing operation (reported July 2026/2024 context) involving the hijacking of internet-connected IP security cameras across Europe and Ukraine.
* **Recent Operations:** The actors are actively monitoring military transport routes and weapons shipments bound for Kyiv. In Ukraine, the feeds are used for kinetic targeting to neutralize military personnel and equipment. In NATO/EU states, the focus is on long-term military intelligence and logistics monitoring.
## Tactics, Techniques & Procedures
* **Internet Scanning:** Systematic scanning for exposed IoT devices and fingerprinting IP cameras by brand.
* **Credential Exploitation:** Utilizing default passwords and factory settings.
* **Exploitation of N-Days:** Targeting devices running obsolete firmware and unpatched vulnerabilities.
* **Automated Intelligence:** Use of image-recognition software to automate the detection of military vehicles and cargo within live video feeds.
* **Lateral Movement:** Footholds gained on one service (e.g., SSH) are leveraged to take over the entire host.
**MITRE ATT&CK IDs (Inferred):**
* **T1190:** Exploit Public-Facing Application
* **T1595.002:** Active Scanning: Vulnerability Scanning
* **T1078:** Valid Accounts (Default Credentials)
* **T1210:** Exploitation of Remote Services
## Targeting
* **Sectors:** Military logistics, transportation infrastructure, private businesses with roadside-facing cameras, and government/civilian security.
* **Geography:** Ukraine, Netherlands, and various NATO and EU member states.
* **Victims:** Specifically organizations located directly on military logistics routes; Ukrainian military personnel and equipment.
## Tools & Infrastructure
* **Vulnerabilities Mentioned:**
* **CVE-2016-7407:** A vulnerability in the `dropbearconvert` tool of the Dropbear SSH server.
* **CVE-2021-39275:** An out-of-bounds write vulnerability in Apache HTTP Server.
* **Automation:** Proprietary or integrated image-recognition software for automated video analysis.
* **Infrastructure:** Censys identified over 87,000 potentially vulnerable cameras across the targeted regions, including 4,000+ in Ukraine and 45,386 reachable devices in the Netherlands.
## Implications
* **Kinetic Impact:** In active conflict zones (Ukraine), cyber espionage directly enables kinetic strikes and personal targeting of troops.
* **Strategic Surveillance:** For NATO/EU states, this provides Russia with detailed insights into Western military aid logistics, potentially allowing them to predict delivery timelines or identify high-value transit hubs.
* **Privacy Erosion:** The hijacking of private/business cameras demonstrates the dual-use nature of civilian infrastructure in modern hybrid warfare.
## Mitigations
* **Exposure Management:** Identify all internet-reachable cameras and minimize the public-facing surface area.
* **Credential Hygiene:** Immediately change all factory-default passwords to strong, unique credentials.
* **Vulnerability Management:** Update camera firmware and associated services (like Apache or SSH servers) to the latest patched versions.
* **Network Isolation:** Place IP cameras on isolated VLANs or behind a VPN/Firewall to prevent direct public internet access.
* **Monitoring:** Use tools to detect unauthorized access or unusual outbound traffic from IoT devices.