Infoblox researchers identified over 236,000 fraudulent websites utilizing the DCloud Uni-App framework to facilitate global investment scams, cryptocurrency theft, and phishing operations targeting users across multiple continents.
Key Points
- Infoblox discovered 236,493 malicious domains leveraging the legitimate DCloud Uni-App framework for various fraudulent schemes since mid-2022.
- Scams include fake cryptocurrency exchanges, wallet drainers, gambling platforms, and phishing sites impersonating brands like WhatsApp.
- The infrastructure often utilizes an "invitation code" system to facilitate pyramid schemes, requiring existing affiliates to recruit new victims.
- While many sites use mainstream hosting like Cloudflare and AWS, sophisticated operators use "bulletproof hosting" to evade detection and takedown efforts.
- Notable examples include the RainbowEx Ponzi scheme in Argentina and the Yuechi Sharing Technology scooter investment scam targeting the U.S. and Australia.