Spike in Attacks Targeting Digital Video Recorders in Ukraine
GreyNoise recorded a nine-day surge of CVE-2021-36260 exploitation attempts against Hikvision devices in Ukraine.
GreyNoise observed scanning and exploitation attempts against digital video recorders and Hikvision products in Ukraine from 21 September to 1 October 2026, after months of near-zero activity. Most attempts targeted CVE-2021-36260, an unauthenticated command-injection flaw, using a Hikvision IP camera/NVR remote command execution Nuclei template. Three PureVPN exit nodes in Lithuania (AS56630) and one Ukrainian address sent the same command test and installed nothing; GreyNoise attributes the VPN activity to one entity and rates the domestic IP as possibly related. The four IPs did not target sensors outside Ukraine, attempts from them stopped after 1 October, and GreyNoise did not connect the activity to concurrent Russian strikes.
- Nine-day surge of CVE-2021-36260 attempts against Ukraine, 21 Sep–1 Oct 2026
- Unauthenticated command injection via a public Nuclei remote-execution template
- Three Lithuanian PureVPN exits and one Ukrainian IP sent the same test
- Those four IPs did not hit GreyNoise sensors outside Ukraine
- GreyNoise did not link the activity to concurrent Russian strikes
Vulnerabilities mentionedAll →
- CVE-2021-362609.8100%Unauthenticated Command Injection in Hikvision Device Web Serverpublished · Hikvision Embedded web server of Hikvision security cameras and related surveillance devices KEV PoC ×3
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 195.238.124.178 | ay not be related due to legitimate shared use. IPs Network 195.238.124.178 , 195.238.124.181 , 195.238.124.188 AS56630, commercial VPN |
| ipv4 | 195.238.124.181 | due to legitimate shared use. IPs Network 195.238.124.178 , 195.238.124.181 , 195.238.124.188 AS56630, commercial VPN exits, Lithuania |
| ipv4 | 195.238.124.188 | shared use. IPs Network 195.238.124.178 , 195.238.124.181 , 195.238.124.188 AS56630, commercial VPN exits, Lithuania This article is |
Full article478 words · extracted from greynoise.io · click to collapse
GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an escalation in Russian strikes across the country. There are a myriad of malicious use cases for compromising DVRs; one involves gaining the ability to physically survey an area to gain battlespace awareness before, during, and after kinetic strikes.
Observed exploitation attemptsTLP:CLEAR
Hikvision exploitation attempts in Ukraine: a nine-day surge
Attempts to exploit CVE-2021-36260 against Ukraine, recorded by GreyNoise: near zero for months, scanning from one of four IPs, a nine-day surge from all four, then a stop. It came during wartime, as Russian missile and drone strikes hit Ukraine. GreyNoise cannot say whether the two are connected.
6 dated events on 6 daysExploitation attemptsSelect a date to read it.
5 days2
Sep 21, 2026
Reconnaissance begins
One of the four IPs, on a Ukrainian network, sends connection attempts to service ports in Ukraine, with no exploit. GreyNoise rates its link to the others low confidence.
Sep 22, 2026
Almost no attempts before the surge
Since early July, attempts at this exploit against Ukraine are rare, and none come from the four IPs.
Sep 27, 2026Exploitation attempts
Attempts continue
Attempts continue, almost all from the four IPs. Every recorded request from the four is the same command test, with nothing to install.
Oct 7, 2026
No attempts from the four since
GreyNoise has recorded no attempts from any of the four IPs since Oct 1.
Source: GreyNoise.
Dates are UTC days. The Ukrainian provider IP is not named here.
The majority of related activity GreyNoise observed focused on exploitation of CVE-2021-36260, which allows unauthenticated command injection against unpatched Hikvision products. The actors used the Hikvision IP camera/NVR - Remote Command Execution nuclei template.
The activity involved three PureVPN exit nodes and one Ukrainian domestic IP address. GreyNoise assesses the PureVPN-associated activity is attributable to a single entity; the activity from the domestic UA IP is possibly related (low confidence). GreyNoise did generally observe a spike in detection of exploitation and scanning attempts against CVE-2021-36260 globally; however, the four IP addresses did not attempt to exploit any of our sensors outside of Ukraine. GreyNoise observed almost no activity like this against Ukraine in the months prior, and none from these four IPs.
Indicators
PureVPN is a commercial virtual private network provider; activity from these exit nodes may not be related due to legitimate shared use.
| IPs | Network |
|---|---|
| 195.238.124.178, 195.238.124.181, 195.238.124.188 | AS56630, commercial VPN exits, Lithuania |
This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
