AUTO-UPDATED

Chinese Framework Powers 200,000 Scam Sites

Cybersecurity firm Infoblox reports that over 200,000 websites are utilizing the Chinese Uni-App framework to facilitate large-scale investment scams, including fake cryptocurrency exchanges and sophisticated phishing operations.

Key Points

  • Infoblox identified more than 236,000 second-level domains using the Uni-App framework for fraudulent activities since mid-2022.
  • The framework, developed by DCloud, is a legitimate tool that threat actors have repurposed to build scalable, cross-platform scam templates.
  • Scam categories include pig-butchering schemes, fake gambling platforms, brand impersonation, and credential-harvesting sites.
  • The infamous RainbowEx cryptocurrency platform and the Lightning Shared Scooter Co. (LSSC) are among the operations linked to this infrastructure.
  • New site registrations surged to approximately 15,000 per month following the international media coverage of the RainbowEx scandal in late 2024.

Why it Matters

The widespread adoption of a single development framework allows criminal syndicates to rapidly deploy and manage massive, coordinated networks of fraudulent investment sites. This trend highlights the growing challenge for security researchers and platforms in tracking decentralized scam operations that leverage legitimate software tools to deceive global investors.
Securityweek.com Published by Ionut Arghire
Read original