AUTO-UPDATED

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

Infoblox researchers identified over 236,000 fraudulent websites utilizing the DCloud Uni-App framework to facilitate global investment scams, cryptocurrency theft, and phishing operations targeting users across multiple continents.

Key Points

  • Infoblox discovered 236,493 malicious domains leveraging the legitimate DCloud Uni-App framework for various fraudulent schemes since mid-2022.
  • Scams include fake cryptocurrency exchanges, wallet drainers, gambling platforms, and phishing sites impersonating brands like WhatsApp.
  • The infrastructure often utilizes an "invitation code" system to facilitate pyramid schemes, requiring existing affiliates to recruit new victims.
  • While many sites use mainstream hosting like Cloudflare and AWS, sophisticated operators use "bulletproof hosting" to evade detection and takedown efforts.
  • Notable examples include the RainbowEx Ponzi scheme in Argentina and the Yuechi Sharing Technology scooter investment scam targeting the U.S. and Australia.

Why it Matters

The widespread abuse of a legitimate development framework demonstrates how easily threat actors can scale complex, multi-language financial fraud operations globally. This trend highlights a significant challenge for cybersecurity defenders, as attackers increasingly blend malicious content with reputable infrastructure to evade detection and exploit unsuspecting investors.
Internet Published by info@thehackernews.com (The Hacker News)
Read original