DCloud Uni-App Templates Help Fraudsters Scale Crypto, Mobility, and Messaging Phishing Scams

A seemingly legitimate open-source development framework has become the critical backbone for hundreds of thousands of fraudulent websites globally.

Malicious actors are leveraging standardized templates built on the Chinese cross-platform toolkit, DCloud Uni-App, to deploy massive campaigns involving fake cryptocurrency exchanges, mobility investment fraud, and messaging application phishing.

By utilizing this shared code framework, cybercriminals can rapidly generate mobile-optimized websites and full desktop applications from a single, highly efficient codebase.

The resulting infrastructure allows decentralized operators to launch sophisticated attacks with minimal development overhead. paste.txt

Infoblox Threat Intel has uncovered that the technical foundation underlying at least 236,493 distinct second-level domains is directly tied to this specific developer toolkit.

As reported by IntCyberDigest, the application framework is widely used by legitimate businesses in mainland China. However, it routinely leaves behind recognizable default scaffolding that scammers exploit for rapid deployment.

The New York Times previously highlighted one highly publicized scam operation: a fake cryptocurrency exchange named RainbowEx that successfully defrauded approximately 20% of the population of a small Argentine town.

Following the widespread international media coverage of that incident in late 2024, the deployment of new malicious domains utilizing these exact templates surged to roughly fifteen thousand new sites per month.

DCloud Templates Scale Phishing

The framework’s underlying versatility enables malicious actors to scale their deceptive operations across distinct scam categories with minimal financial effort.

Fraudsters have successfully cloned prediction markets, designed fake casino platforms informally known as scambling, and created convincing wallet-drainer prompts that flawlessly mimic official asset verification flows for major blockchain networks.

Distinct DCloud-built investment scam second-level domains observed over time, broken down by hosting operator: 236,493 total second level domains across from 2022-2026. The red dashed line marks October 2024, when the RainbowEx–DCloud connection became public (Source: infoblox)
Distinct DCloud-built investment scam second-level domains observed over time, broken down by hosting operator: 236,493 total second level domains across from 2022-2026. The red dashed line marks October 2024, when the RainbowEx–DCloud connection became public (Source: infoblox)

Criminal networks are also heavily utilizing the templates to execute widespread WhatsApp phishing attacks.

These specific campaigns present victims with realistic security help center pages, intricately designed to harvest user credentials and bypass standard authentication measures.

More recently, an ongoing bicycle-sharing investment scam operating under the corporate name Yuechi Sharing Technology has actively targeted victims in multiple Western countries.

Screenshot from bepviews[.]com, a DCloud-built wallet drainer impersonating BNB Chain verification flows; the “Verify Asset” button initiates a wallet drain (Source: infoblox)
Screenshot from bepviews[.]com, a DCloud-built wallet drainer impersonating BNB Chain verification flows; the “Verify Asset” button initiates a wallet drain (Source: infoblox)

This specific operation is uniquely dangerous because it effectively uses genuine government paperwork, including a United States FinCEN Money Services Business registration, to create a false sense of strict regulatory compliance.

Whenever targeted individuals encounter technical issues with deposits or withdrawals, automated customer service handlers seamlessly funnel them toward off-platform branded chats.

This highly coordinated communication pattern strongly points toward a centralized, well-funded operator controlling large swaths of these interconnected scam domains, Infoblox said.

Indicators of Compromise

Indicator of CompromiseThreat Category
rainbowex[.]ccFake Crypto Exchange
bepviews[.]comCrypto Wallet Drainer
lsscol[.]comLSSC Mobility Scam

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories