From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy
ID: be999630-cac5-561a-895a-045deb3d43c1
STIX ID: report--be999630-cac5-561a-895a-045deb3d43c1
Feed Name: Infoblox Threat Intel Blog
Infoblox Threat Intel documents a massive, global scam ecosystem built on the Chinese DCloud Uni-App framework: over 236,000 second-level domains since 2022 host fake crypto exchanges, wallet drainers, scam gambling sites, and phishing portals, with clusters tied to centralized operators and a notable bulletproof-hosting footprint (notably CTG Server). High-profile real-world frauds (RainbowEx in Argentina, LSSC in the U.S., and the active Yuechi operation) illustrate the cross-border consumer and enterprise impact, while the report maps technical fingerprints, hosting trends, enterprise DNS exposure, and a set of IOC domains for defenders to act on.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
