Suspected Iranian Threat Actors Compromise IP Camera Feeds in Iran, Israel, the UAE, Qatar, Bahrain

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Surveillance Compromise: Suspected Iran-nexus threat actors are actively exploiting exposed network cameras, possibly for real-time assessments of battle damage.
  • Targeted Hardware: The campaign targets known vulnerabilities in unpatched surveillance systems in Israel, the UAE, Qatar, and Bahrain.
  • Known Flaws: This operation exploits now-patched vulnerabilities in IP cameras from Hikvision and Dahua.

A significant surge in Iranian IP camera targeting was observed as state-aligned actors compromise surveillance networks across multiple nations. This campaign deliberately leverages now-patched IP camera vulnerabilities in widely deployed Hikvision and Dahua hardware to support active military engagements, which Check Point Research (CPR) attributed to Iranian threat actors.

Escalation in Middle East Cyber Warfare

Suspected Iranian attackers gain real-time visual telemetry of strategic geographic locations in Israel, the UAE, Qatar, Bahrain, Kuwait, and Cyprus, as well as specific areas in Lebanon, by exploiting unpatched firmware through command injection and authentication bypass flaws. 

Waves of activity against Israel | Source: CPR
Waves of activity against Israel | Source: CPR

CPR security analysts have observed synchronized spikes in camera scanning and exploitation activity that align precisely with geopolitical flashpoints, such as anticipated military strikes and sudden airspace closures. Iranian military likely used these compromised video feeds to support battle damage assessments (BDA) and execute target-correction protocols during missile operations. 

The attack infrastructure we track combines specific commercial VPN exit nodes (Mullvad, ProtonVPN, Surfshark, NordVPN) and virtual private servers (VPS), and is assessed to be employed by multiple Iran-nexus actors,” the report added.

Mitigating Cyber-Physical Conflict Risks

The weaponization of civilian and enterprise surveillance systems underscores a dangerous evolution in modern cyber-physical conflict. Organizations must:


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: