FBI warns of HiatusRAT scanning campaigns against Chinese
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-7921 | Improper Authentication Bypass in Multiple Hikvision Products CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days. Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access. | 9.8 | 100% | KEV |
| mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed | |
| CVE-2018-9995 | TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-brand TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response. NVD description · AI analysis pending | 9.8 | 83% | PoC ×4 |
| — | |
| CVE-2020-25078 | Unauthenticated Admin Password Disclosure in D-Link DCS-2530L/2670L Cameras CVE-2020-25078 is an information-disclosure flaw in the unauthenticated /config/getuser endpoint of D-Link DCS-2530L and DCS-2670L network cameras, which allows a remote, unauthenticated attacker to retrieve the device's administrator password. It is triggered simply by sending a crafted request to that HTTP endpoint over the network, with no login or user interaction required. An attacker who obtains the administrator password can log into the camera's web interface to view footage, change settings, or pivot further into the network. Owners of a DCS-2530L running firmware before 1.06.01 Hotfix or a DCS-2670L running firmware through 2.02 with the camera's web interface reachable are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid active-exploitation evidence (with FBI/CISA alerts on HiatusRAT campaigns targeting webcams and DVRs), and its EPSS score of 97.9% indicates a very high near-term exploitation probability. Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and for DCS-2670L apply the latest vendor hotfix release newer than 2.02 (check D-Link's support page, as the exact fixed version is not specified in this data). Do not expose the camera web interface directly to the internet (remove port forwards/UPnP mappings or restrict access via firewall), and check device logs or perimeter traffic for unauthenticated requests to /config/getuser. Because these devices are end-of-life, plan replacement if current mitigations or firmware updates are unavailable, consistent with BOD 22-01 guidance. | 7.5 | 98% | KEV |
| moderatelikely on the order of tens of thousands of internet-exposed camera units (estimate; no authoritative counts in source data) | |
| CVE-2021-33044 | Authentication Bypass in Dahua IP Camera Firmware Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known. Do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device. | 9.8 | 100% | KEV PoC ×2 |
| massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices | |
| CVE-2021-36260 | Unauthenticated Command Injection in Hikvision Device Web Server CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet. Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first. | 9.8 | 100% | KEV PoC ×3 |
| massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet |
Full article543 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 17, 2024

The FBI warned of a fresh wave of HiatusRAT malware attacks targeting internet-facing Chinese-branded web cameras and DVRs.
The Federal Bureau of Investigation (FBI) released a Private Industry Notification (PIN) to warn of HiatusRAT malware campaigns targeting Chinese-branded web cameras and DVRs.
The report includes a set of recommendations to mitigate the exposure to the threat behind the current scanning campaigns.
“The Federal Bureau of Investigation (FBI) is releasing this Private Industry Notification (PIN) to highlight HiatusRAT1 scanning campaigns against Chinese-branded web cameras and DVRs.” reads the PIN report. “Private sector partners are encouraged to implement the recommendations listed in the “Mitigation” column of the table below to reduce the likelihood and impact of these attack campaigns.”
The Remote Access Trojan (RAT) has been active since July 2022. In March 2023, Lumen Black Lotus Labs researchers uncovered a sophisticated campaign called “HiatusRAT” that infected over 100 edge networking devices globally. Threat actors leveraged edge routers, or “living on the edge” access, to passively collect traffic and set up a covert C2 infrastructure.
In June 2023, the group started a reconnaissance and targeting activity aimed at a U.S. military procurement system and was spotted targeting Taiwan-based organizations
The choice of the new targets in the latest campaign suggests a strategic interest of the People’s Republic of China according to the 2023 ODNI threat assessment.
The threat actor hosted newly compiled malware on different procured virtual private servers (VPSs). One of these virtual private servers was exclusively employed in attacks against entities across Taiwan, including commercial firms and at least one municipal government organization.
Another VPS node was used to target a U.S. military server used for contract proposals and submissions.. Threat actors appeared to be interested in gathering intelligence about military requirements, with a focus on organizations involved in the Defense Industrial Base (DIB).
“Starting in mid-June through August 2023, Black Lotus Labs observed multiple newly compiled versions of the HiatusRAT malware discovered in the wild. In this latest campaign, our investigation also uncovered prebuilt Hiatus binaries that target new architectures such as Arm, Intel 80386, and x86-64 and previously targeted architectures such as MIPS, MIPS64, and i386.” reads the report published by Black Lotus Labs.
In March 2024, threat actors behind this campaign started targeting Internet of Things (IoT) devices in the US, Australia, Canada, New Zealand, and the United Kingdom. The threat actors attempted to exploit multiple vulnerabilities in DVRs, including CVE-2017-7921, CVE-2018-9995, CVE-2020-25078, CVE-2021-33044, and CVE-2021-36260. Attackers also attempted to exploit weak vendor-supplied passwords.
Threat actors exploited unpatched vulnerabilities in Xiongmai and Hikvision devices, using tools like Ingram for scanning and Medusa for brute-force attacks via Telnet. Targeted TCP ports included 23, 26, 554, 2323, 567, 5523, 8080, 9530, and 56575.
The FBI recommends limiting or isolating vulnerable devices, monitoring networks, and following cybersecurity best practices. Recommendations include timely patching, using strong and unique passwords, enabling multi-factor authentication, implementing security tools to detect abnormal activity, auditing accounts, scanning for open ports, segmenting networks, updating antivirus software, and creating offline backups.
The feds urge to report any signs of compromise to the FBI or IC3.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, HiatusRAT)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172074/malware/fbi-warns-of-hiatusrat-scanning-campaigns.html