Scanning and remote code execution attempts targeting video surveillance devices in Ukraine rose between September 21 and October 1, 2026.
Most activity focused on CVE-2021-36260, a critical command injection flaw in unpatched Hikvision products. The surge occurred alongside Russian missile and drone strikes, but researchers have not established a connection between the cyber activity and those attacks.
The findings highlight renewed interest in an older vulnerability that can let attackers control exposed cameras and recording equipment without signing in.
However, GreyNoise’s observations document exploitation attempts, not confirmed takeovers of real surveillance systems. That distinction matters when assessing the campaign’s impact and possible purpose.
Hikvision Camera Vulnerability
According to GreyNoise’s timeline, initial reconnaissance began on September 21, when an IP address on a Ukrainian network attempted connections to service ports without sending an exploit.
Exploitation attempts rose sharply on September 23 and continued through October 1, creating a nine-day surge after months of almost no comparable activity against Ukraine.
Four IP addresses accounted for almost all attempts during the surge. Three were PureVPN exit nodes, while the fourth belonged to a domestic Ukrainian network.
GreyNoise assessed that one entity drove the VPN activity, but linked the Ukrainian address to that activity with low confidence.
The VPN addresses were 195.238.124.178, 195.238.124.181, and 195.238.124.188, associated with AS56630 in Lithuania. Commercial VPN exits can serve unrelated users, so these indicators should not, by themselves, be treated as proof of a shared operator. The Ukrainian address was not publicly named.
Although GreyNoise also observed increased global scanning for the flaw, these four addresses did not attempt exploitation against its sensors outside Ukraine.
Every recorded request from the group used the same command test, with no installation payload. No further attempts from those addresses were recorded through October 7.
CVE-2021-36260 affects the web server in certain Hikvision products. Poor input checks allow crafted requests containing malicious commands to reach the device’s operating system. NIST assigns the vulnerability a critical CVSS score of 9.8, reflecting exploitation over a network without authentication or user interaction.
The observed activity used the publicly available Nuclei template titled “Hikvision IP camera/NVR – Remote Command Execution.” Its use points to automated vulnerability testing, rather than establishing that attackers installed malware or accessed video feeds. GreyNoise’s command-test observations support that narrower reading.
Cybersecurity News previously covered more than 80,000 exposed, vulnerable Hikvision cameras in 2022. That historical finding shows the flaw’s long-running exposure problem, but it is not a current count of vulnerable devices.
Compromised cameras can reveal sensitive locations and activity. In January 2024, Ukrainian authorities reported disabling two cameras that Russian intelligence had compromised to observe Kyiv’s air defenses and infrastructure. That earlier case illustrates the potential risk; it does not establish who conducted this latest campaign.
Administrators should identify affected models and apply Hikvision’s firmware updates, as CISA recommends. Restricting public access and separating surveillance equipment from critical networks can also reduce exposure while updates are arranged. Changing passwords alone does not fix an unauthenticated command injection flaw.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

