HackMyIP
← Back to News
2026-06-27 SecurityWeek

200,000 Scam Sites Built on Chinese Uni-App Framework

PhishingThreat Intel

More than 236,000 second-level domains powering investment scam infrastructure have been built using Uni-App, a Chinese open-source cross-platform development framework maintained by DCloud, according to new research from Infoblox. Uni-App enables developers to write a single Vue.js codebase that deploys simultaneously as mobile apps, desktop applications, and mobile-optimized websites — a feature set that legitimate developers widely embrace, but one that scammers have exploited at industrial scale. Infoblox's analysis suggests a centralized operator coordinating growth and dips in domain registrations across multiple hosts, pointing to a single threat cluster despite the appearance of independent operations.

The scam templates, actively sold within underground circles, are used to spin up fake cryptocurrency exchanges, deposit-and-trade platforms, crypto wallet drainers, prediction-market impersonators, messaging app phishing pages, and multi-language pig-butchering sites. Among the most notorious is RainbowEx, the fake crypto platform that devastated residents of a small Argentine town and drew global media coverage after late 2024. Following that publicity, new DCloud-fingerprinted scam sites surged to roughly 15,000 per month at peak, as opportunistic operators cloned the template. Two physically branded scooter-sharing investment schemes — Lightning Shared Scooter Co. (LSSC) in the US and Yuechi Sharing Technology Ltd. (YST) operating across Australia, New Zealand, and the US — also leveraged Uni-App frontends to lend credibility to their high-yield passive-income pitches.

DCloud itself does not appear complicit; the framework powers thousands of legitimate Chinese products and simply provides the technical scaffolding. However, the concentration of fraudulent activity on a single platform has made Uni-App a recognizable signature within the scam-operator ecosystem. Investigators and victims can begin tracing suspect domains with a WHOIS lookup to surface registration patterns, and confirm a site's underlying hosting and encryption configuration via an SSL/TLS checker — both useful first steps when a too-good-to-be-true investment portal lands in your inbox.

The campaign underscores how legitimate developer tooling, when paired with accessible scam templates, can democratize fraud at a scale previously reserved for sophisticated state-sponsored operations. With domains launched continuously since mid-2022 and now numbering well into six figures, defenders should treat Uni-App-fingerprinted sites as a high-fidelity indicator of investment fraud and incorporate the framework's signatures into threat-intel feeds and blocklists.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →