Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Framework Fuels Massive Scam Network

Chinese Framework Fuels Massive Scam Network

Posted on June 27, 2026 By CWS

Over 200,000 websites have been identified as using investment scam templates that leverage the Chinese open-source framework Uni-App, according to cybersecurity firm Infoblox. Uni-App, known for its versatile development capabilities, is widely utilized in legitimate applications across China. However, its misuse by fraudulent actors has raised significant concerns.

Understanding Uni-App’s Role

The Uni-App framework facilitates the creation of Vue.js codebases, enabling deployment as mobile or desktop applications and websites. Despite its legitimate uses, Infoblox’s findings reveal that scammers are exploiting this technology by selling investment scam templates. This has resulted in a significant number of scam websites that appear to be interconnected.

Infoblox’s research indicates a pattern of coordinated activity among these scam sites, with fluctuations in new domain registrations suggesting a centralized control. These developments highlight the need for increased vigilance and accountability in the use of such frameworks.

Scale and Impact of Scam Operations

Infoblox has identified over 236,000 second-level domains as part of this scam infrastructure. These sites range from fake cryptocurrency exchanges to phishing platforms, and impersonation of brands and services. A notable example is the RainbowEx platform, a fraudulent cryptocurrency site that swindled numerous investors in Argentina.

Since mid-2022, these scam domains have proliferated across various hosting providers, with a marked increase from late 2024, following the RainbowEx incident. At its peak, up to 15,000 new scam sites were observed monthly, indicating the widespread adoption of the Uni-App framework by scammers.

Broader Implications and Future Outlook

The bulk of these DCloud-marked sites are investment scams, operated by many independent groups. These include crypto wallet drainers and phishing sites, among others. Notably, the framework has also been used in schemes like Lightning Shared Scooter Co. (LSSC) and Yuechi Sharing Technology Ltd. (YST), which falsely promised high returns to investors.

Infoblox emphasizes the urgency of tracking these threat actors and identifying possible connections indicating shared ownership. Such efforts are crucial in the fight against this growing cybercrime ecosystem.

The expanding use of the DCloud framework in scams underscores a pressing need for comprehensive monitoring and intervention strategies to mitigate the risks posed by these fraudulent networks.

Security Week News Tags:Chinese framework, crypto scams, Cybercrime, Cybersecurity, DCloud, fraudulent websites, investment scams, online security, Phishing, RainbowEx, scam sites, Uni-App

Post navigation

Previous Post: OpenAI Unveils GPT-5.6 Sol with Enhanced Security
Next Post: Russian Intelligence Phishing Campaign Targets Messaging Apps

Related Posts

China’s Salt Typhoon Hackers Target Canadian Telecom Firms China’s Salt Typhoon Hackers Target Canadian Telecom Firms Security Week News
MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats  MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats  Security Week News
Enterprises Combat AI Threats with Autonomous Solutions Enterprises Combat AI Threats with Autonomous Solutions Security Week News
Philip Martin Appointed as Uber’s New CISO Philip Martin Appointed as Uber’s New CISO Security Week News
Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Security Week News
Vulnerabilities in CISA KEV Are Not Equally Critical: Report Vulnerabilities in CISA KEV Are Not Equally Critical: Report Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark