236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
ID: 8a4c68ab-cd12-5c59-b492-7aca9f2eeb9e
STIX ID: report--8a4c68ab-cd12-5c59-b492-7aca9f2eeb9e
Feed Name: The Hacker News
Infoblox research uncovered 236,493 distinct domains using DCloud/Uni-App investment-scam templates that power fake cryptocurrency exchanges, wallet drainers, gambling and prediction markets, WhatsApp phishing, and generic credential-collection sites. The scams have been active since mid‑2022, target multiple languages/regions, use invitation-code affiliate recruitment and off-platform customer support, and are hosted largely on mainstream cloud providers with a minority on bulletproof hosts; operators also strip framework fingerprints to evade detection and evidence suggests centralized template sales or ownership.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
