A seemingly legitimate open-source development framework has become the critical backbone for hundreds of thousands of fraudulent websites globally.
Malicious actors are leveraging standardized templates built on the Chinese cross-platform toolkit, DCloud Uni-App, to deploy massive campaigns involving fake cryptocurrency exchanges, mobility investment fraud, and messaging application phishing.
By utilizing this shared code framework, cybercriminals can rapidly generate mobile-optimized websites and full desktop applications from a single, highly efficient codebase.
The resulting infrastructure allows decentralized operators to launch sophisticated attacks with minimal development overhead. paste.txt
Infoblox Threat Intel has uncovered that the technical foundation underlying at least 236,493 distinct second-level domains is directly tied to this specific developer toolkit.
As reported by IntCyberDigest, the application framework is widely used by legitimate businesses in mainland China. However, it routinely leaves behind recognizable default scaffolding that scammers exploit for rapid deployment.
The New York Times previously highlighted one highly publicized scam operation: a fake cryptocurrency exchange named RainbowEx that successfully defrauded approximately 20% of the population of a small Argentine town.
Following the widespread international media coverage of that incident in late 2024, the deployment of new malicious domains utilizing these exact templates surged to roughly fifteen thousand new sites per month.
DCloud Templates Scale Phishing
The framework’s underlying versatility enables malicious actors to scale their deceptive operations across distinct scam categories with minimal financial effort.
Fraudsters have successfully cloned prediction markets, designed fake casino platforms informally known as scambling, and created convincing wallet-drainer prompts that flawlessly mimic official asset verification flows for major blockchain networks.

Criminal networks are also heavily utilizing the templates to execute widespread WhatsApp phishing attacks.
These specific campaigns present victims with realistic security help center pages, intricately designed to harvest user credentials and bypass standard authentication measures.
More recently, an ongoing bicycle-sharing investment scam operating under the corporate name Yuechi Sharing Technology has actively targeted victims in multiple Western countries.
![Screenshot from bepviews[.]com, a DCloud-built wallet drainer impersonating BNB Chain verification flows; the “Verify Asset” button initiates a wallet drain (Source: infoblox)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh78Fbzwdc7KX-xRpa3HtLnLhR_zTTS_tsWwltiJnT1Pr9-5PUIP-2-hTUi03swKE-2cEA1vAhYvUbYhzg5mu0NAFC6677xSTpsprnnOJvm25lJ5bz1-1X5QRjLUpUaXkyJF87cxGgY_L1m1VMapaXYDUiv1pewwmMm_z6wPjicBHGRUq8vWKeOukv5CoWD/s725/dcloud-uni-app-image4.webp)
This specific operation is uniquely dangerous because it effectively uses genuine government paperwork, including a United States FinCEN Money Services Business registration, to create a false sense of strict regulatory compliance.
Whenever targeted individuals encounter technical issues with deposits or withdrawals, automated customer service handlers seamlessly funnel them toward off-platform branded chats.
This highly coordinated communication pattern strongly points toward a centralized, well-funded operator controlling large swaths of these interconnected scam domains, Infoblox said.
Indicators of Compromise
| Indicator of Compromise | Threat Category |
|---|---|
rainbowex[.]cc | Fake Crypto Exchange |
bepviews[.]com | Crypto Wallet Drainer |
lsscol[.]com | LSSC Mobility Scam |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.