View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Hunt.io Reconstructs Toolkit Targeting Ukrainian IP Cameras

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Hunt.io Reconstructs Russian-Speaking Toolkit Targeting Ukrainian IP Cameras Hunt.io researchers reconstructed a toolkit used to compromise Ukrainian IP cameras.

    • Internet-exposed Ukrainian IP cameras were targeted, with live-view sessions recorded from 58 cameras.
    • The toolkit targeted Hikvision, Dahua, D-Link, and Reolink cameras affected by CVE-2017-7921, CVE-2021-36260, CVE-2021-33044, CVE-2021-33045, CVE-2020-25078, and CVE-2020-25169.
    • A FastAPI/Docker project called camview wrapped the open-source Ingram scanner.
    • The operator brute-forced HTTP and RTSP credentials using a 3,811-pair dictionary.
    • The toolkit transcoded RTSP streams into MJPEG for browser viewing. ๐Ÿ“Ž Coverage: hunt.io ยท ๐Ÿ‘ via r/netsec
  • Picus Finds Play Ransomware Evaded Most Security Controls in 2026 Tests Picus found Play ransomware had the lowest prevention score among 10 tested ransomware families.

    • The analysis covered Play, BlackByte, LockBit, BabLock, Magniber, FAUST, Sodinokibi/REvil, Hive, BlackKingdom, and Maori.
    • Play achieved a 13% prevention score, while the other families scored 25% to 38%.
    • Ransomware families used obfuscation, process injection, masquerading, registry modification, and reflective code loading.
    • BabLock disabled security and backup services and cleared Windows event logs; LockBit 5.0 patched ETW telemetry.
    • Magniber used thread hijacking and in-memory .NET loading, while Play masqueraded tools and services as legitimate utilities. ๐Ÿ“Ž Coverage: cyberpress.org ยท ๐Ÿ‘ via securityboulevard.com (discovered)

๐Ÿ”“ CVEs & KEV

  • Other โ€” 18 CVEs (worst 10.0)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check