Attacks Against Ukrainian Soldiers and Materiel Tied to Hacking of European Devices
Mathew J. Schwartz (euroinfosec) •
August 14, 2026

Image: Shutterstock/ISMG
Russian-speaking hackers are using internet-connected cameras located in frontline Ukrainian cities and allied states to spy against Europe’s efforts to counter the Kremlin’s ongoing war of territorial expansion.
See Also: Rise of Malicious AI Skills Expands Enterprise Risk
Threat intelligence firm Hunt.io recently discovered a server used by hackers housed a “custom platform built to find, exploit and catalog internet-exposed IP cameras.” Every file and bash script they recovered was written primarily in Russian, and “Python scripts scanning for vulnerable cameras were named for the areas they targeted, namely the frontline cities of Dobropillia, Kramatorsk and Slavyansk.”
The researchers shared their findings with CERT-UA, the Computer Emergency Response Team of Ukraine, on July 30. Hunt.io said its investigation was spurred by Dutch intelligence warning last month, four years into the Russian invasion, that Kremlin threat actors were hacking into internet-connected cameras across Ukraine and Europe, including in NATO member states. They spotted the server by tracing attacks against a Ukrainian e-commerce site used by the hackers as a proxy server.
An open directory on the Ukrainian e-commerce site included clues that led them back to servers being hosted by sanctioned Russian hosting provider Aeza Group (see: US Sanctions Aeza Group for Hosting Infostealers, Ransomware).
That server also contained an instance of a Docker project named “camview,” which the attacker was using together with Ingram, a publicly available webcam vulnerability scanner, to identify unpatched, internet-connected Dahua and Hikvision cameras and gain remote access to them by exploiting known vulnerabilities. Also in the attackers’ directories was “a mock Dahua camera server,” which the researchers believe was used to test attacks before launching them in the wild.
Researchers found signs that attackers targeted TP-Link, MikroTik and generic routers and cameras based in 15 different European countries, and used these to launch proxy attacks against servers primarily based in the Ukrainian cities of Burshtyn, Kherson and Odessa.
The hackers additionally targeted IP cameras in Austria and Moldova, as well as NATO member states Bulgaria, Czechia, France, Germany, Hungary, Italy, the Netherlands, Poland, Romania, Slovakia, Spain and the United Kingdom.
The vulnerabilities being targeted by attackers don’t appear new. They included an authentication bypass flaw in Hikvision gear patched in 2017, D-Link and Reolink flaws patched in 2020, and Dahua and Hikvision vulnerabilities patched in 2021. The newest, targeted vulnerabilities appeared to be two TP-Link Archer router flaws, for which the vendor issued patches in 2024.
Further tools identified by researchers included a collection of scripts designed to query personal data on Ukrainians, named “Eye of God Ukraine – main engine,” that appeared to be named for “Eye of God,” which is “a notorious Russian ‘probiv’ service, operated over Telegram that builds reports on individuals using open-source and leaked personal data,” they said (see: Nation-State, Cyber and Hacktivist Threats Pummel Europe).
The tool is designed to take an input such as an individual’s name, license plate or vehicle identification number, and query open-source intelligence amassed in part from breaches of Ukrainian vehicle databases. The tool didn’t appear to be active when the researchers gained access to the infrastructure, indicating possible technical challenges or a still-in-development feature.
Researchers said that every technique they found to be used by these attackers “can be stopped in its tracks by basic security measures: strong credentials, current firmware and removing internet access for devices that don’t require it.”
Cyberespionage Alerts
Russian military intelligence has been tied to previous hacking campaigns that targeted surveillance cameras with an eye on potential targets for its missile and drone strikes. This has included Ukraine’s air defenses and critical infrastructure in Kyiv.
Such hacking appears to be widespread, and not confined to Ukraine, with reports suggesting that Israel has long used such attacks to monitor Tehran. After the United States and Israel launched a war against Iran on Feb. 28, reports suggested Iranian forces had been accessing IP cameras to facilitate targeting for their drones and missiles, and post-attack to assess damage inflicted (see: Cyberattacks and Unpredictable Targeting Remain an Iran Risk).
Dutch intelligence agencies warned last month that at least one Russian intelligence and security service has been targeting internet-connected cameras in Europe, including Ukraine, as part of a cyberespionage campaign designed to gather military intelligence.
This campaign includes “automated analysis of imagery through image recognition software to conduct targeted searches for military vehicles and the military cargo they are transporting,” with that information being used to try and “neutralize Ukrainian military personnel and to destroy their military materiel.” While there are no signs the Russians are using this intelligence to launch military attacks outside Ukraine, the agencies warned “that the same tactics could possibly be implemented by Russian military units in a future conflict.”
Given such risks, Dutch intelligence reiterated longstanding advice being promulgated by Western governments’ cyber agencies for all users of internet-cameras, including in homes. These include ensuring urged internet-camera feeds aren’t publicly accessible, unless that’s explicitly required, as well as disabling any unneeded protocols, such as SSH, FTP, Bonjour, Telnet and Universal Plug and Play, all of which attackers could abuse.
“If possible, use only secured protocols such as HTTPS and RTSPS,” they advised.
In addition, always change the default password on any device before deploying it, restrict access to the device using a VPN and isolate it using a virtual network, and keep firmware and software updated, they said. Also beware every camera’s field of view, which will “ideally” not feature any “part of logistical flows or public infrastructure, including roads, harbors and loading zones, and “mask sensitive zones within the field of view, for example by blurring them,” which is a feature built into some cameras.