Cybersecurity firm Infoblox reports that over 200,000 websites are utilizing the Chinese Uni-App framework to facilitate large-scale investment scams, including fake cryptocurrency exchanges and sophisticated phishing operations.
Key Points
- Infoblox identified more than 236,000 second-level domains using the Uni-App framework for fraudulent activities since mid-2022.
- The framework, developed by DCloud, is a legitimate tool that threat actors have repurposed to build scalable, cross-platform scam templates.
- Scam categories include pig-butchering schemes, fake gambling platforms, brand impersonation, and credential-harvesting sites.
- The infamous RainbowEx cryptocurrency platform and the Lightning Shared Scooter Co. (LSSC) are among the operations linked to this infrastructure.
- New site registrations surged to approximately 15,000 per month following the international media coverage of the RainbowEx scandal in late 2024.