logo

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

ID: 8a4c68ab-cd12-5c59-b492-7aca9f2eeb9e

STIX ID: report--8a4c68ab-cd12-5c59-b492-7aca9f2eeb9e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-29

Date Updated: 2026-07-01

Author: [email protected] (The Hacker News)

...
...

Infoblox research uncovered 236,493 distinct domains using DCloud/Uni-App investment-scam templates that power fake cryptocurrency exchanges, wallet drainers, gambling and prediction markets, WhatsApp phishing, and generic credential-collection sites. The scams have been active since mid‑2022, target multiple languages/regions, use invitation-code affiliate recruitment and off-platform customer support, and are hosted largely on mainstream cloud providers with a minority on bulletproof hosts; operators also strip framework fingerprints to evade detection and evidence suggests centralized template sales or ownership.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.