236,493 DCloud Uni-App-Built Sites Weaponized in Global Crypto Scam, Wallet-Drainer and Phishing Economy (RainbowEx, LSSC, Yuechi)
236,493 DCloud Uni-App-Built Sites Weaponized in Global (TL-2026-1211), also tracked as DCloud Uni-App scam economy, is a high-severity phishing campaign, first published 2026-07-11. It is linked to a China-nexus actor with low confidence, affects DCloud (HCXY Technology / Beijing) Uni-App cross-platform development, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1211
- Threat ID
- TL-2026-1211
- Also known as
- DCloud Uni-App scam economy, RainbowEx-style scam network
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution confidence
- LOW
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- food-and-beverage, banking, government administration, consulting, education, financial-services, health, manufacturing, retail, telecoms, energy, agriculture
- Target regions
- argentina, united states of america, australia, new zealand, canada, china, hong kong, portugal, Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in 236,493 DCloud Uni-App-Built Sites Weaponized in Global
Malware and tooling: Lightning Shared Scooter Co. (LSSC), RainbowEx, Yuechi Sharing Technology Ltd. (YST)
Infoblox threat intelligence identified 236,493 distinct second-level domains built on the legitimate Chinese DCloud Uni-App cross-platform framework being reused as a fraud-as-a-service template for fake crypto exchanges, wallet drainers, pig-butchering investment scams, WhatsApp-lookalike phishing, and pyramid-scheme recruitment sites since mid-2022.
How 236,493 DCloud Uni-App-Built Sites Weaponized in Global works
Since mid-2022, threat actors have systematically abused DCloud's legitimate open-source Uni-App cross-platform development framework (Vue.js-based, package prefix `uni.UNI[HEX]`, application class `io.DCloud.application.DCloudApplication`) to mass-produce fraud sites and Android apps. Infoblox's DNS threat-intelligence telemetry logged 236,493 distinct second-level domains carrying DCloud fingerprints, generating 5+ million attempted connections from 985 distinct enterprise customers across 25 industries between January 2024 and mid-2026.
The campaign spans at least eight languages and every continent, with two technical populations: a 'vanilla' tier that retains default DCloud scaffolding (easier to fingerprint and take down) and an 'evasive' tier that strips framework signatures and disproportionately relies on bulletproof hosting (CTG Server Limited, AS152194, Hong Kong; listed on the Spamhaus DROP ASN list) at 2-3x the rate of the vanilla population. The vast majority of domains (~94%) sit on legitimate cloud infrastructure — Cloudflare, Alibaba Cloud, Tencent Cloud, and AWS — to blend with normal traffic and resist takedown.
Monetization templates observed include: fake cryptocurrency exchanges running closed-loop mock trading engines (victims deposit via USDT/stablecoin, see fabricated gains, cannot withdraw); crypto wallet drainers masquerading as BNB Chain/Tether wallet-verification flows; WhatsApp Security-Help-Center phishing kits harvesting credentials; Polymarket-style rigged prediction-market/gambling sites; multi-tier pyramid/MLM investment fronts (electric-scooter and bicycle 'sharing economy' schemes) requiring invitation codes to gate recruitment; and generic brand-impersonation credential-harvest pages (postal services, retail).
Named operations include RainbowEx, a fake Argentine crypto exchange whose collapse triggered a San Pedro, Buenos Aires Province prosecutor's investigation resulting in seven arrests (six in San Pedro, one in Junín) and roughly AR$30M plus $3.5M in USDT seized, with Interpol red notices requested for two Malaysian nationals; Lightning Shared Scooter Co. (LSSC), a US-focused electric-scooter investment pyramid with 8+ physical storefronts across 20+ states, celebrity/official endorsements (including a Sean Spicer Cameo appearance), an FBI Richmond field-office investigation, and a 'New LSSC' successor recruitment drive after collapse; and Yuechi Sharing Technology Ltd. (YST), a scooter/bicycle-sharing investment scam using a real Hong Kong corporate registration (No. 77975280, issued 2025-04-08) and a genuine US FinCEN money-services-business registration (No. 31000300306222, filed 2025-05-15, listed address 125 Deansgate, Manchester UK) as legitimacy props while targeting Australia, New Zealand, and the United States.
Publicity around RainbowEx in October 2024 appears to have acted as a force-multiplier rather than a deterrent: new DCloud-fingerprinted scam-site creation jumped from a few thousand per month to roughly 15,000 per month at peak. Two coordinated infrastructure die-offs (July-September 2025, a roughly two-thirds decline, and a second beginning January 2026) point to centralized control over a meaningful share of the ecosystem despite the presence of many independent, unrelated operators reusing the same commercial scam template. DCloud itself is a legitimate Beijing-based software company with no involvement in the fraud; the abuse is entirely downstream template reuse by criminal operators.
MITRE ATT&CK techniques used in TL-2026-1211
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Credential Access
Execution
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains; T1598 Phishing for Information
Impact
stealth
Affected products and versions in 236,493 DCloud Uni-App-Built Sites Weaponized in Global
- DCloud (HCXY Technology / Beijing) — Uni-App cross-platform development framework
Vulnerable versions: N/A - legitimate framework abused as a fraud-site template, not a software vulnerability
Remediation for 236,493 DCloud Uni-App-Built Sites Weaponized in Global
Immediate actions
- Block DNS resolution / proxy access to known DCloud-fingerprinted scam domains at the enterprise DNS resolver or secure web gateway
- Block or flag connections to CTG Server Limited (AS152194) IP ranges given its disproportionate use for bulletproof-hosted scam infrastructure
- Alert employees who click WhatsApp/Telegram/social-media links to unfamiliar crypto, exchange-verification, or investment-recruitment sites
- Freeze/report any employee cryptocurrency wallet-connect actions triggered by unsolicited 'verification' prompts impersonating BNB Chain or Tether
Workarounds
- Treat any investment platform requiring an 'invitation code' to register, or charging an 'account verification fee' to release withdrawals, as a confirmed pyramid/Ponzi indicator
Longer-term hardening
- Deploy DNS/web threat intelligence feeds that fingerprint DCloud Uni-App scaffolding (uni.UNI[HEX] package naming, io.DCloud.* Android classes) to catch newly registered look-alike domains pre-emptively
- Run periodic awareness training on pig-butchering, wallet-drainer, and pyramid-investment recruitment lures, since entry vector is overwhelmingly social (WhatsApp/Telegram/social media) rather than technical
- Monitor for brand-impersonation domain registrations against corporate brand names using DNS-based brand-protection monitoring
Timeline of 236,493 DCloud Uni-App-Built Sites Weaponized in Global
- DCloud Uni-App investment-scam template subset first observed in the wild; a few thousand new fingerprinted scam sites per month.
- RainbowEx-DCloud connection becomes public via international press; monthly new-site creation jumps to roughly 15,000 at peak.
- San Pedro, Buenos Aires Province prosecutor's office launches investigation into RainbowEx, culminating in seven arrests and asset seizures (AR$30M cash, $3.5M USDT); Interpol red notices requested for two Malaysian nationals.
- Yuechi Sharing Technology Ltd. incorporated in Hong Kong (Registration No. 77975280) as a legitimacy prop for its scooter/bicycle-sharing investment scam.
- Yuechi Sharing Technology files a genuine U.S. FinCEN money-services-business registration (No. 31000300306222) to lend legitimacy to its scheme.
- Brian Krebs publishes a 'scambling' investigation, coinciding with an observed increase in prediction-market/gambling-themed DCloud scam sites.
- First coordinated die-off of DCloud-fingerprinted scam infrastructure begins, with visible domain counts declining roughly two-thirds through September 2025.
- NBC News publishes an investigation into Lightning Shared Scooter Co. (LSSC), documenting US victims and an FBI Richmond field-office inquiry.
- Second coordinated infrastructure disruption begins; visible domain counts fall from roughly 8,500 back to under 5,000.
- The Hacker News and other outlets (SecurityWeek, GBHackers, Cybersecurity News, CybersecAsia) syndicate the Infoblox findings.
- Infoblox publishes 'From San Pedro to Salinas,' documenting 236,493 DCloud-fingerprinted domains, 5M+ enterprise connection attempts from 985 organizations, and the RainbowEx/LSSC/Yuechi case studies.
Sources cited for 236,493 DCloud Uni-App-Built Sites Weaponized in Global
- 236,000+ DCloud Uni-App Sites Used in Fraud, Phishing, and Crypto Scam Campaigns
- From San Pedro to Salinas: How a Chinese Framework (DCloud Uni-App) Powers a Global Scam Economy
- Infoblox links DCloud app to vast scam website network
- DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud and WhatsApp Phishing
- DCloud Uni-App Framework Powers 236,000+ Scam Domains Across Global Fraud Economy
- Chinese Framework Powers 200,000 Scam Sites
- Seven arrested in RainbowEx Ponzi scheme investigation
- Argentina Freezes $3.5M USDT Linked to Rainbowex Ponzi Scheme: Report
- RainbowEx scam template scales to 236,493 domains with workplace spillover
- Argentine Prosecutors Arrest 24, Seize Over $8M in USDT in 'Fake Coins' Crypto-Fraud Sweep
Threats related to 236,493 DCloud Uni-App-Built Sites Weaponized in Global
Detection coverage for TL-2026-1211
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1211 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.