Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance
Russian military intelligence services are actively hijacking internet-connected security cameras across Europe and Ukraine to monitor military transport routes, weapons shipments to Kyiv, and Ukrainian troop positions, according to a joint alert issued on July 10 by the Netherlands General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).
The compromised cameras are not merely passive observers. In Ukraine, the live video feeds have been directly integrated into targeting processes, effectively turning ordinary commercial devices into battlefield aiming tools for strikes against Ukrainian military personnel and equipment. Similar access persists in EU and NATO countries, where the footage is used to gather broader military intelligence unrelated to direct combat operations.
The intrusion technique is disturbingly simple. Attackers use internet-wide scans to identify exposed IP cameras by brand fingerprints, then log directly into devices that still retain factory-default passwords, outdated firmware, or unchanged out-of-the-box configurations. No zero-day vulnerabilities are required. Once inside, image-recognition software automatically scans the video streams for military vehicles and cargo, eliminating the need for continuous human monitoring.
Internet scanning firm Censys mapped the exposure surface and found more than 87,000 cameras running services with known vulnerabilities across the EU, NATO member states, and Ukraine, including over 4,000 devices in Ukraine. In the Netherlands alone, Censys identified 45,386 publicly accessible cameras, of which 1,992 ran vulnerable services. Narrowing the scope to camera-specific software vulnerabilities reduced the Dutch figure to 541 devices.
Two specific vulnerabilities highlighted by Censys are CVE-2016-7407 affecting the Dropbear SSH server and CVE-2021-39275 in Apache HTTP Server version 2.4.49. Both issues were patched years ago and are not listed in CISA’s Known Exploited Vulnerabilities catalog, yet Censys still flagged hundreds of matching hosts.
Although the total number of confirmed compromised cameras remains lower than the overall exposure count, their locations are strategically critical. Many sit along Dutch military transport corridors, prompting authorities to notify affected organizations and request immediate isolation of the devices.
The agencies issued straightforward defensive recommendations: identify all publicly exposed cameras via forgotten port forwards or UPnP mappings, move video streams behind VPNs, replace default passwords and enable multi-factor authentication where possible, adjust camera angles to avoid sensitive logistics areas, and apply security updates promptly while choosing devices with long support lifecycles.
Related articles
Iran-Linked Tortoiseshell Group Deploys Malicious wtsapi32.dll Backdoor for Persistent Windows Access
Researchers have uncovered new tools deployed by the Tortoiseshell group, an Iranian-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore. The campaign features a Windows backdoor disguised as the legitimate wtsapi32.dll library that silently establishes reverse SSH tunnels over port 443 to maintain access to compromised networks. Active since at least 2018, the group has targeted defense, aerospace, technology, IT services, and military organizations primarily in the Middle East and the United States. The malware preserves expected Windows API functions while enabling command execution, file exfiltration, in-memory DLL loading, directory listing, and system reconnaissance. Associated infrastructure spans the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan.
HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender
The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.
Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit
The North Korean Lazarus APT group has been actively exploiting a zero-day vulnerability in the Windows kernel to escalate privileges to SYSTEM level and install the FudModule rootkit. The flaw, tracked as CVE-2026-68820, resides in the afd.sys driver responsible for network functions and socket management. Microsoft released a patch for the issue on August 11. The attacks form part of the ongoing Operation Dream Job campaign, which uses fake job offers to target professionals in defense, aerospace, and aviation sectors. Victims in Brazil, Europe, and India are tricked into opening malicious PDF viewers or prepared files that deliver the MISTPEN downloader. Once initial access is obtained, the zero-day exploit elevates privileges, allowing FudModule to tamper with Windows telemetry and weaken EDR solutions as well as Smart App Control.
Iranian Hackers Disable Safety Alarms in US Industrial Control Systems
Iranian threat actors have been compromising internet-exposed industrial controllers across the United States since at least March 2026, modifying alarm and safety shutdown logic in critical infrastructure. The campaign has targeted government organizations and operators in the water, wastewater, and energy sectors, resulting in operational disruptions and financial losses. Attackers focus on devices with insecure remote access, weak credentials, or default configurations rather than exploiting zero-day vulnerabilities. Targeted hardware includes Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 PLCs, and Siemens S7-1200 models. Operators use rented foreign infrastructure and legitimate programming software to download, alter, and re-upload control logic projects. In at least one case, malicious code maintained normal operations while introducing instructions that bypassed safe operational limits and altered data displayed on HMI and SCADA interfaces. The tactics closely resemble prior activity attributed to the CyberAv3ngers group linked to Iran’s Islamic Revolutionary Guard Corps, though direct attribution remains unconfirmed.