DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ Domains

DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto (TL-2026-1219), also tracked as RainbowEx Scandal, is a medium-severity fraud campaign, first published 2026-07-11. It is attributed to DCloud Uni-App Scam Network with low confidence, affects DCloud Uni-App (cross-platform development framework), maps to 20 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-1219

Threat ID
TL-2026-1219
Also known as
RainbowEx Scandal, Uni-App Scam Economy, San Pedro Crypto Fraud
Severity
MEDIUM
Status
ACTIVE
Category
FRAUD
First published
2026-07-11
Last reviewed
2026-07-11
Attribution
DCloud Uni-App Scam Network
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, cryptocurrency, retail, consumer, food and beverage, banking, government administration, consulting, education
Target regions
argentina, united states of america, australia, new zealand, Global (all continents)
Detection rules
9
Indicators of compromise
35

A global cybercriminal ecosystem has repurposed the legitimate Chinese cross-platform toolkit DCloud Uni-App to mass-produce fake cryptocurrency exchanges, wallet drainers, and WhatsApp phishing kits across more than 236,000 fraudulent second-level domains since 2022. The network, exposed via the 2024 RainbowEx Ponzi scandal in Argentina, spawned copycat operations (LSSC, Yuechi Sharing Technology, XAEL-AI) that drain BNB Chain and Tether wallets from victims across at least eight languages and every continent.

How DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto works

Since at least mid-2022, threat actors have abused DCloud Uni-App — a legitimate, widely-used open-source cross-platform application development framework built by the Chinese company DCloud — to rapidly scaffold and deploy fraudulent cryptocurrency exchanges, investment 'pig-butchering' platforms, wallet drainers, gambling/prediction-market clones, and messaging-platform (WhatsApp) phishing portals. Infoblox threat intelligence, corroborated by reporting from The Hacker News, GBHackers, SecurityWeek, and CybersecAsia, identified 236,493 distinct second-level domains (SLDs) built on this framework, with roughly 18,000 concurrently visible at peak and around 1,024 hosted on bulletproof infrastructure.

The operation came to international attention through the October 2024 RainbowEx scandal, in which a bogus cryptocurrency exchange defrauded a large share of the population of San Pedro, Argentina, in a Ponzi/investment-fraud scheme; seven people were reportedly arrested in connection with the case. Public disclosure of the RainbowEx-DCloud link (via New York Times coverage) triggered a surge in new scam-domain registration, peaking at roughly 15,000 new DCloud-based scam sites per month.

Operators reuse a nearly identical technical and behavioral playbook across campaigns: a six-field victim registration flow (phone number, password, confirm password, graphic CAPTCHA, SMS verification code, and a gated invitation/affiliate code that prevents signup without an existing recruiter), fabricated trading dashboards showing fictitious gains, stablecoin (primarily Tether/USDT) deposit collection, blocked withdrawals once the scheme is publicly exposed, and last-ditch 'account verification fee' extortion (documented at $75). Wallet-drainer variants (e.g., bepviews.com) impersonate official BNB Chain and Tether verification flows with a 'Verify Asset'/'Connect Wallet' button that authorizes on-chain asset transfer to attacker-controlled addresses. WhatsApp-impersonation phishing kits (faq-whatsapp-center.com, verify-what.com, and a cluster of whats-z*.vip domains) harvest credentials and session data under the guise of a WhatsApp Help Center or account-verification flow.

Distinct campaign families identified include: RainbowEx (Argentine fake exchange, October 2024), Lightning Shared Scooter Co. / LSSC (U.S. mobility-sharing investment pyramid active in 8+ cities through August 2025, prompting FBI/state investigation, individual losses documented above $370,000), Yuechi Sharing Technology Ltd. / YST (active 2026 bicycle/scooter-sharing investment scam targeting Australia, New Zealand, and the U.S.), and XAEL-AI (an AI-investment-narrative variant sharing YST's backend registration/support infrastructure). Operators construct legitimacy through real government business registrations (Hong Kong Companies Registry, U.S. FinCEN MSB registrations), stock footage (e.g., Nasdaq closing-bell ceremony clips), physical storefronts with functioning products (LSSC's scooters), branded/scripted customer-service chat funnels, and even endorsements from local officials.

Infrastructure is predominantly hosted on legitimate cloud providers (Cloudflare, Alibaba Cloud, Tencent Cloud, AWS) to blend with normal traffic — roughly 94% of scam domains resolve to ASNs also carrying legitimate traffic — while a harder-to-disrupt subset (roughly 6%, rising to 14-17% among 'evasive-tier' operators who strip DCloud's default framework fingerprints) sits on bulletproof hosting, dominated by AS152194 CTG Server Limited, a Hong Kong-registered provider listed on the Spamhaus DROP ASN list. Technical fingerprinting relies on DCloud's recognizable default build scaffolding: Android package naming patterns (uni.UNI[hex], io.DCloud.application.DCloudApplication) and manifest components (DCloudApplication, WebviewActivity, WebAppActivity, ProcessMediator), plus a shared 29-language localization pack including uncommon diaspora languages (Haitian Creole, Kinyarwanda, Albanian, Uzbek) used to target migrant and diaspora victim communities globally.

Infoblox observed two centralized infrastructure disruption events — July-September 2025 (visible monthly active SLDs dropped from ~14,000 to under 5,000) and a second beginning late January 2026 — suggesting a small number of centralized operators control large swaths of the ecosystem despite its apparent sprawl. Enterprise DNS telemetry recorded 985 distinct enterprise customers across 25 industry verticals (led by Food & Beverage, Banking, Government, IT Consulting, Education, and Financial Services) generating over 5 million DNS queries to this scam infrastructure, with query volume patterns (no domain exceeding 20,000 queries per customer) suggesting employee personal-device exposure rather than deliberate enterprise targeting.

MITRE ATT&CK techniques used in TL-2026-1219

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie

Command and Control

T1090 Proxy; T1102 Web Service

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Collection

T1213 Data from Information Repositories

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1590 Gather Victim Network Information; T1593 Search Open Websites/Domains

reconnaissance

T1598 Phishing for Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto

  • DCloud — Uni-App (cross-platform development framework)
    Vulnerable versions: all versions abused for scaffolding fraudulent apps/sites
    Fixed in: not applicable - framework itself is not vulnerable; abuse is of legitimate default scaffolding for social engineering

Remediation for DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto

Immediate actions

  • Block known DCloud-scam domains and wallet-drainer domains at DNS/perimeter firewall
  • Add AS152194 (CTG Server Limited) and other bulletproof-hosting ASNs flagged by Spamhaus DROP to network blocklists
  • Deploy DNS filtering with threat intelligence feeds that track DCloud Uni-App technical fingerprints
  • Alert users to never connect crypto wallets to sites reached via unsolicited WhatsApp/social-media links
  • Educate finance/treasury and crypto-holding employees on pig-butchering and wallet-drainer red flags

Workarounds

  • Disallow corporate device access to domains matching WhatsApp Help Center lookalike patterns (whats-z*.vip, faq-whatsapp-center.com, verify-what.com)
  • Flag/block SMS or WhatsApp messages containing unsolicited crypto-investment or wallet-verification links

Longer-term hardening

  • Deploy DNS-level detection for DCloud framework fingerprints (Android package naming, manifest components) to proactively flag newly-registered scam infrastructure
  • Monitor enterprise DNS telemetry for queries to newly-observed second-level domains matching DCloud scaffolding patterns
  • Establish takedown/reporting relationships with Cloudflare, Alibaba Cloud, Tencent Cloud, and AWS abuse teams for rapid scam-site removal
  • Track BNB Chain and Tether wallet addresses associated with drainer campaigns for blockchain analytics correlation
  • Coordinate with law enforcement (FBI, international partners) given cross-border, multi-jurisdiction nature of the fraud

Timeline of DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto

  • Investment-scam-specific DCloud Uni-App template family begins circulating among cybercriminal groups, building on broader framework abuse dating to 2021
  • RainbowEx fake cryptocurrency exchange, built on DCloud Uni-App, defrauds a large share of the population of San Pedro, Argentina, in a Ponzi/investment fraud scheme
  • New York Times coverage publicly links the RainbowEx scandal to the DCloud Uni-App framework, triggering a surge in new scam-domain registrations to roughly 15,000 per month at peak
  • Seven individuals reportedly arrested in connection with the RainbowEx fraud scheme in Argentina
  • Lightning Shared Scooter Co. (LSSC) investment pyramid scheme actively operating across 8+ U.S. cities, promising passive revenue via a scooter-sharing model
  • First major centralized infrastructure disruption observed; visible monthly active second-level domains drop from approximately 14,000 to under 5,000, indicating a small number of centralized operators
  • LSSC scheme collapses; documented individual victim losses exceeding $370,700 in a single U.S. jurisdiction prompt FBI and state fraud investigations
  • Second centralized infrastructure disruption event begins in late January 2026, again suggesting concentrated operator control of the domain ecosystem
  • Yuechi Sharing Technology Ltd. (YST) actively recruiting new victims for a bicycle/scooter-sharing investment scam targeting Australia, New Zealand, and the United States, alongside the related XAEL-AI variant
  • Infoblox publishes threat intelligence report 'From San Pedro to Salinas', documenting 236,493 DCloud Uni-App scam domains, enterprise DNS exposure across 985 organizations, and bulletproof-hosting infrastructure patterns
  • Cyber Security News and other outlets (The Hacker News, GBHackers, SecurityWeek, CybersecAsia) publish coverage summarizing the DCloud Uni-App scam network for general audiences

Sources cited for DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto

Threats related to DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto

Detection coverage for TL-2026-1219

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1219 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats