logo

From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy

ID: be999630-cac5-561a-895a-045deb3d43c1

STIX ID: report--be999630-cac5-561a-895a-045deb3d43c1

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel documents a massive, global scam ecosystem built on the Chinese DCloud Uni-App framework: over 236,000 second-level domains since 2022 host fake crypto exchanges, wallet drainers, scam gambling sites, and phishing portals, with clusters tied to centralized operators and a notable bulletproof-hosting footprint (notably CTG Server). High-profile real-world frauds (RainbowEx in Argentina, LSSC in the U.S., and the active Yuechi operation) illustrate the cross-border consumer and enterprise impact, while the report maps technical fingerprints, hosting trends, enterprise DNS exposure, and a set of IOC domains for defenders to act on.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.