安全客July 21, 2026🇨🇳Translated from Chinese

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Russian military intelligence services are actively hijacking internet-connected security cameras across Europe and Ukraine to monitor military transport routes, weapons shipments to Kyiv, and Ukrainian troop positions, according to a joint alert issued on July 10 by the Netherlands General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).

The compromised cameras are not merely passive observers. In Ukraine, the live video feeds have been directly integrated into targeting processes, effectively turning ordinary commercial devices into battlefield aiming tools for strikes against Ukrainian military personnel and equipment. Similar access persists in EU and NATO countries, where the footage is used to gather broader military intelligence unrelated to direct combat operations.

The intrusion technique is disturbingly simple. Attackers use internet-wide scans to identify exposed IP cameras by brand fingerprints, then log directly into devices that still retain factory-default passwords, outdated firmware, or unchanged out-of-the-box configurations. No zero-day vulnerabilities are required. Once inside, image-recognition software automatically scans the video streams for military vehicles and cargo, eliminating the need for continuous human monitoring.

Internet scanning firm Censys mapped the exposure surface and found more than 87,000 cameras running services with known vulnerabilities across the EU, NATO member states, and Ukraine, including over 4,000 devices in Ukraine. In the Netherlands alone, Censys identified 45,386 publicly accessible cameras, of which 1,992 ran vulnerable services. Narrowing the scope to camera-specific software vulnerabilities reduced the Dutch figure to 541 devices.

Two specific vulnerabilities highlighted by Censys are CVE-2016-7407 affecting the Dropbear SSH server and CVE-2021-39275 in Apache HTTP Server version 2.4.49. Both issues were patched years ago and are not listed in CISA’s Known Exploited Vulnerabilities catalog, yet Censys still flagged hundreds of matching hosts.

Although the total number of confirmed compromised cameras remains lower than the overall exposure count, their locations are strategically critical. Many sit along Dutch military transport corridors, prompting authorities to notify affected organizations and request immediate isolation of the devices.

The agencies issued straightforward defensive recommendations: identify all publicly exposed cameras via forgotten port forwards or UPnP mappings, move video streams behind VPNs, replace default passwords and enable multi-factor authentication where possible, adjust camera angles to avoid sensitive logistics areas, and apply security updates promptly while choosing devices with long support lifecycles.

Related articles

BoletimSecState-Sponsored & APT

US Offers $10 Million Reward for Iranian IRGC Cyber Commander Amir Yaryab

The United States has announced a reward of up to $10 million through the Rewards for Justice program for information leading to the identification or location of Amir Yaryab, leader of the Cyber Operations Command within Iran's Islamic Revolutionary Guard Corps (IRGC). Yaryab oversees units responsible for cyber operations targeting critical infrastructure across the United States, Europe, and the Middle East. Groups under his direction, including Shahid Hemmat and Shahid Shushtari, have conducted campaigns against defense, energy, telecommunications, finance, transportation, hotels, and airlines sectors. He is also linked to structures associated with the CyberAv3ngers group, known for attacks on industrial control systems and operational technology equipment. Previous operations attributed to IRGC-linked actors compromised internet-exposed Unitronics programmable logic controllers, affecting at least 75 devices between November 2023 and January 2024, including 34 in the US water and wastewater sector. The reward specifically targets individuals acting under foreign government direction in malicious cyber activities against US critical infrastructure.

BoletimSecState-Sponsored & APT

APT28 Expands Espionage with New HOOKEDGE Backdoor Targeting European Organizations

The Russian-linked APT28 group, also known as BlueDelta, has deployed a new lightweight backdoor called HOOKEDGE as part of a cyber-espionage campaign against strategic European entities. The attacks, assessed with moderate confidence, targeted government, diplomatic, and defense manufacturing organizations in Romania, Spain, and Turkey between September 2025 and April 2026. Infection begins with spear-phishing emails delivering Microsoft Word documents containing malicious macros that mimic official Spanish government materials. Upon execution, the macros drop files, establish persistence via scheduled tasks, and deploy the HOOKEDGE backdoor written in batch scripts. The malware uses hidden Microsoft Edge instances and the legitimate webhook.site service to blend command-and-control traffic with normal web activity. In high-value victims, operators installed a second HOOKEDGE instance with five-minute check-ins for faster control and data collection. The backdoor shows strong code similarities to the older HEADLACE implant previously attributed to the same group.

BoletimSecState-Sponsored & APT

Iran-Linked Cyber Attack Leaves Small UK Power Plant Offline for Four Days

A cyber attack attributed to hackers with suspected ties to Iran took a small-scale UK power generation facility offline for approximately four days in July 2026. The incident affected a roughly 15 MW generator used to support peak demand periods, yet caused no customer outages or disruption to the national electricity grid. British authorities have not issued an official attribution, and investigators have not publicly identified the malware, vulnerability, or initial access vector used in the operation. Recovery required four days of extensive validation across controllers, configurations, security systems, and remote access points to ensure no residual risks remained. The case highlights the operational challenges of restoring industrial control environments after suspected nation-state activity. In response, UK authorities have strengthened guidance for the energy sector and are considering additional protective measures for critical infrastructure suppliers.

BoletimSecState-Sponsored & APT

Iran-Linked Tortoiseshell Group Deploys Malicious wtsapi32.dll Backdoor for Persistent Windows Access

Researchers have uncovered new tools deployed by the Tortoiseshell group, an Iranian-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore. The campaign features a Windows backdoor disguised as the legitimate wtsapi32.dll library that silently establishes reverse SSH tunnels over port 443 to maintain access to compromised networks. Active since at least 2018, the group has targeted defense, aerospace, technology, IT services, and military organizations primarily in the Middle East and the United States. The malware preserves expected Windows API functions while enabling command execution, file exfiltration, in-memory DLL loading, directory listing, and system reconnaissance. Associated infrastructure spans the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan.