Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DCloud Uni-App Framework Fuels Global Crypto Scams

DCloud Uni-App Framework Fuels Global Crypto Scams

Posted on June 29, 2026 By CWS

A Chinese development framework, DCloud Uni-App, has become a critical tool for cybercriminals, powering one of the largest scam networks on record. Initially created for legitimate application development, this cross-platform toolkit has been exploited to support a vast network of fraudulent activities including fake cryptocurrency exchanges and phishing sites.

Over 236,000 fraudulent second-level domains have been linked to this framework, making it one of the most heavily weaponized tools in recent cybercrime history. The widespread misuse became evident following the 2024 RainbowEx scandal, which targeted residents of San Pedro, Argentina, through a fraudulent crypto platform.

Massive Scam Network Revealed

The RainbowEx incident prompted a deeper investigation, revealing that the platform was just one component of a more extensive and organized criminal operation. Analysts from Infoblox reported that DCloud Uni-App serves as the foundation for at least 236,493 scam-related domains, emphasizing that the framework itself is not directly involved in fraudulent activities.

Despite DCloud’s legitimacy as a Chinese software company, malicious actors have co-opted its toolkit to carry out large-scale fraud. These scams span multiple languages and geographies, impersonating major stock exchanges and depleting users’ cryptocurrency wallets.

Crypto Fraud and Global Reach

The explosion of new scam sites built using DCloud Uni-App, particularly after the RainbowEx case, illustrates the framework’s appeal to cybercriminals worldwide. These fraudulent sites often mimic well-known crypto exchanges or invent names like DawnEx to appear credible without violating trademarks.

Victims are lured into depositing funds, typically via Tether or other stablecoins, only to find that their money vanishes when withdrawal attempts are made. This pattern of deception highlights the sophisticated nature of these operations.

Phishing Campaigns and Broader Impacts

Beyond cryptocurrency fraud, DCloud has been utilized to create extensive WhatsApp phishing sites. These sites often replicate the appearance of trusted interfaces like the WhatsApp Security Help Center to deceive users into surrendering login credentials.

Infoblox researchers observed several WhatsApp-themed domains actively engaging in credential harvesting. These pages typically feature simple designs to avoid raising suspicion, leading users to connect crypto wallets, which are then discreetly drained.

Experts recommend implementing DNS-level defenses to distinguish between malicious and legitimate DCloud sites, thereby protecting users across various industries. With scam networks expanding rapidly, tracking shared patterns across this ecosystem is crucial.

The use of DCloud Uni-App in cybercriminal activities underscores the need for ongoing vigilance and proactive defense strategies. Organizations are urged to adopt robust threat detection measures to mitigate risks associated with this evolving threat landscape.

Cyber Security News Tags:credential harvesting, crypto fraud, Cryptocurrency, Cybercrime, Cybersecurity, DCloud, Infoblox, investment scams, Phishing, RainbowEx, scam infrastructure, scam network, Uni-App framework, WhatsApp phishing, WhatsApp scams

Post navigation

Previous Post: Gamaredon’s Ukraine Cyber Attacks Intensify with New Tactics
Next Post: DCloud Uni-App Framework Fuels Global Crypto Scams

Related Posts

Hackers Attempted to Misuse Claude AI to Launch Cyber Attacks Hackers Attempted to Misuse Claude AI to Launch Cyber Attacks Cyber Security News
Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution Sitecore CMS Platform Vulnerabilities Enables Remote Code Execution Cyber Security News
Phishing Campaign Targets U.S. Firms with Fake Invitations Phishing Campaign Targets U.S. Firms with Fake Invitations Cyber Security News
New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control New Rust-Based ChaosBot Malware Leverages Discord for Stealthy Command and Control Cyber Security News
Hackers Exploited Samsung Galaxy S25 0-Day Vulnerability to Enable Camera and Track Location Hackers Exploited Samsung Galaxy S25 0-Day Vulnerability to Enable Camera and Track Location Cyber Security News
Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform Record-breaking 11.5 Tbps UDP Flood DDoS Attack Originated from Google Cloud Platform Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark