236,493 DCloud Uni-App-Built Sites Weaponized in Global Crypto Scam, Wallet-Drainer and Phishing Economy (RainbowEx, LSSC, Yuechi) — Threadlinqs Intelligence
As of 2026-07-11, 236,493 DCloud Uni-App-Built Sites Weaponized in Global Crypto Scam, Wallet-Drainer and Phishing Economy (RainbowEx, LSSC, Yuechi) is a high-severity phishing threat attributed to a China (suspected, based on tooling/language; unconfirmed)-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1211 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: China (suspected, based on tooling/language; unconfirmed) · FINANCIAL
Infoblox threat intelligence identified 236,493 distinct second-level domains built on the legitimate Chinese DCloud Uni-App cross-platform framework being reused as a fraud-as-a-service template for
Since mid-2022, threat actors have systematically abused DCloud's legitimate open-source Uni-App cross-platform development framework (Vue.js-based, package prefix `uni.UNI[HEX]`, application class `io.DCloud.application.DCloudApplication`) to mass-produce fraud sites and Android apps. Infoblox's DNS threat-intelligence telemetry logged 236,493 distinct second-level domains carrying DCloud fingerprints, generating 5+ million attempted connections from 985 distinct enterprise customers across 25 industries between January 2024 and mid-2026.
The campaign spans at least eight languages and every continent, with two technical populations: a 'vanilla' tier that retains default DCloud scaffolding (easier to fingerprint and take down) and an 'evasive' tier that strips framework signatures and disproportionately relies on bulletproof hosting (CTG Server Limited, AS152194, Hong Kong; listed on the Spamhaus DROP ASN list) at 2-3x the rate of the vanilla population. The vast majority of domains (~94%) sit on legitimate cloud infrastructure — Cloudflare, Alibaba Cloud, Tencent Cloud, and AWS — to blend with normal traffic and resist takedown.
Monetization templates observed include: fake cryptocurrency exchanges running closed-loop mock trading engines (victims deposit via USDT/stablecoin, see fabricated gains, cannot withdraw); crypto wallet drainers masquerading as BNB Chain/Tether wallet-verification flows; WhatsApp Security-Help-Center phishing kits harvesting credentials; Polymarket-style rigged prediction-market/gambling sites; multi-tier pyramid/MLM investment fronts (electric-scooter and bicycle 'sharing economy' schemes) requiring invitation codes to gate recruitment; and generic brand-impersonation credential-harvest pages (postal services, retail).
Named operations include RainbowEx, a fake Argentine crypto exchange whose collapse triggered a San Pedro, Buenos Aires Province prosecutor's investigation resulting in seven arrests (six in San Pedro, one in Junín) and roughly AR$30M plus $3.5M in USDT seized, with Interpol red notices requested for two Malaysian nationals; Lightning Shared Scooter Co. (LSSC), a US-focused electric-scooter investment pyramid with 8+ physical storefronts across 20+ states, celebrity/official endorsements (including a Sean Spicer Cameo appearance), an FBI Richmond field-office investigation, and a 'New LSSC' successor recruitment drive after collapse; and Yuechi Sharing Technology Ltd. (YST), a scooter/bicycle-sharing investment scam using a real Hong Kong corporate registration (No. 77975280, issued 2025-04-08) and a genuine US FinCEN money-services-business registration (No. 31000300306222, filed 2025-05-15, listed address 125 Deansgate, Manchester UK) as legitimacy props while targeting Australia, New Zealand, and the United States.
Publicity around RainbowEx in October 2024 appears to have acted as a force-multiplier rather than a deterrent: new DCloud-fingerprinted scam-site creation jumped from a few thousand per month to roughly 15,000 per month at peak. Two coordinated infrastructure die-offs (July-September 2025, a roughly two-thirds decline, and a second beginning January 2026) point to centralized control over a meaningful share of the ecosystem despite the presence of many independent, unrelated operators reusing the same commercial scam template. DCloud itself is a legitimate Beijing-based software company with no involvement in the fraud; the abuse is entirely downstream template reuse by criminal operators.
Target sectors: food-and-beverage, banking, government administration, consulting, education, financial-services, health, manufacturing, retail, telecoms, energy, agriculture
Target regions: argentina, united states of america, australia, new zealand, canada, china, hong kong, portugal, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1589, T1583, T1583, T1585, T1585, T1608, T1566, T1656, T1204