GreyNoise identified an increase in scanning and exploitation attempts targeting Digital Video Recorders (DVR) in Ukraine between 21 September and 1 October 2026. The activity coincides with an escalation in Russian strikes across the country. There are a myriad of malicious use cases for compromising DVRs; one involves gaining the ability to physically survey an area to gain battlespace awareness before, during, and after kinetic strikes. 

‍

Observed exploitation attemptsTLP:CLEAR
Hikvision exploitation attempts in Ukraine: a nine-day surge
Attempts to exploit CVE-2021-36260 against Ukraine, recorded by GreyNoise: near zero for months, scanning from one of four IPs, a nine-day surge from all four, then a stop. It came during wartime, as Russian missile and drone strikes hit Ukraine. GreyNoise cannot say whether the two are connected.
6 dated events on 6 daysExploitation attemptsSelect a date to read it.
5 days
Sep 21, 2026
Reconnaissance begins
One of the four IPs, on a Ukrainian network, sends connection attempts to service ports in Ukraine, with no exploit. GreyNoise rates its link to the others low confidence.
Open on the full timeline →
Sep 22, 2026
Almost no attempts before the surge
Since early July, attempts at this exploit against Ukraine are rare, and none come from the four IPs.
Open on the full timeline →
Sep 23, 2026Exploitation attempts
The surge begins
(Hikvision IP Camera RCE CVE-2021-36260 Attempt) Attempts against Ukraine jump from near zero. Across the surge, four IPs send almost all of them.
Open on the full timeline →
Sep 27, 2026Exploitation attempts
Attempts continue
Attempts continue, almost all from the four IPs. Every recorded request from the four is the same command test, with nothing to install.
Open on the full timeline →
Oct 1, 2026Exploitation attempts
The surge stops
GreyNoise records the last attempts from the four IPs.
Open on the full timeline →
Oct 7, 2026
No attempts from the four since
GreyNoise has recorded no attempts from any of the four IPs since Oct 1.
Open on the full timeline →
Source: GreyNoise.
Dates are UTC days. The Ukrainian provider IP is not named here.
GreyNoise

‍

The majority of related activity GreyNoise observed focused on exploitation of CVE-2021-36260, which allows unauthenticated command injection against unpatched Hikvision products. The actors used the Hikvision IP camera/NVR - Remote Command Execution nuclei template.

‍

The activity involved three PureVPN exit nodes and one Ukrainian domestic IP address. GreyNoise assesses the PureVPN-associated activity is attributable to a single entity; the activity from the domestic UA IP is possibly related (low confidence). GreyNoise did generally observe a spike in detection of exploitation and scanning attempts against CVE-2021-36260 globally; however, the four IP addresses did not attempt to exploit any of our sensors outside of Ukraine. GreyNoise observed almost no activity like this against Ukraine in the months prior, and none from these four IPs.

‍

Indicators

PureVPN is a commercial virtual private network provider; activity from these exit nodes may not be related due to legitimate shared use.

IPs Network
195.238.124.178, 195.238.124.181, 195.238.124.188 AS56630, commercial VPN exits, Lithuania

‍

This article is a summary of the full, in-depth version on the GreyNoise Labs blog.
Read the full report
GreyNoise Labs logo
Link to GreyNoise Twitter account
Link to GreyNoise Twitter account