Infoblox reported that criminals have abused DCloud’s legitimate Uni-App cross-platform framework to build a sprawling scam ecosystem spanning at least 236,493 second-level domains and more than 200,000 scam websites. The infrastructure has been used for fake cryptocurrency exchanges, investment-fraud portals, gambling and prediction-market impersonation, WhatsApp phishing pages, credential-harvesting sites, and crypto wallet drainers. Investigators said the domains have been launched since mid-2022 across many hosting providers, with technical and registration patterns indicating a coordinated network operated by multiple actors rather than a single group.
The activity drew wider attention after the RainbowEx scandal in San Pedro, Argentina, where investigators found the platform had been built with Uni-App, and researchers said domain creation accelerated sharply after late 2024, peaking at roughly 15,000 newly observed scam sites per month. Infoblox also linked the framework to other real-world schemes, including Lightning Shared Scooter Co. in the United States and Yuechi Sharing Technology Ltd. operating in Australia, New Zealand, and the United States, while observed templates impersonated brands and services such as WhatsApp, BNB Chain verification flows, the Hong Kong Stock Exchange, and other financial platforms. DCloud was identified as a legitimate Chinese software company and was not accused of participating in the fraud.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
In 2024, the RainbowEx scandal in San Pedro, Argentina, helped expose the broader scam network after investigators found RainbowEx had been built with Uni-App. The incident became a key real-world example linking the framework to investment fraud.
Infoblox linked the Uni-App-based ecosystem to other named investment scams, including Lightning Shared Scooter Co. in the United States and Yuechi Sharing Technology Ltd. operating in Australia, New Zealand, and the United States. The reporting also described phishing templates impersonating brands and services such as WhatsApp, BNB Chain verification flows, and the Hong Kong Stock Exchange.
Infoblox reported that more than 200,000 scam websites, spanning at least 236,493 distinct second-level domains, were using templates built with DCloud's Uni-App framework. The company said the infrastructure supported fake crypto exchanges, gambling and prediction-market impersonation, WhatsApp phishing, credential harvesting, multilingual pig-butchering schemes, and crypto wallet drainers.
The reported scam activity accelerated after October 2024, with newly observed DCloud-based scam sites peaking at roughly 15,000 per month. SecurityWeek similarly noted sharp domain growth after the RainbowEx scandal gained major media attention in late 2024.
Infoblox reported that scam domains built with DCloud's legitimate Uni-App framework have been launched since mid-2022 across many hosting providers. The infrastructure was later tied to a broad range of fraud, including fake investment platforms, phishing, and wallet-drainer sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.