DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ Domains — Threadlinqs Intelligence
As of 2026-07-11, DCloud Uni-App Scam Network Powers RainbowEx-Style Crypto Fraud Across 236,000+ Domains is a medium-severity fraud threat attributed to DCloud Uni-App Scam Network, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1219 · Severity: MEDIUM · Status: ACTIVE · Category: FRAUD
Attribution: DCloud Uni-App Scam Network · FINANCIAL
A global cybercriminal ecosystem has repurposed the legitimate Chinese cross-platform toolkit DCloud Uni-App to mass-produce fake cryptocurrency exchanges, wallet drainers, and WhatsApp phishing kits
Since at least mid-2022, threat actors have abused DCloud Uni-App — a legitimate, widely-used open-source cross-platform application development framework built by the Chinese company DCloud — to rapidly scaffold and deploy fraudulent cryptocurrency exchanges, investment 'pig-butchering' platforms, wallet drainers, gambling/prediction-market clones, and messaging-platform (WhatsApp) phishing portals. Infoblox threat intelligence, corroborated by reporting from The Hacker News, GBHackers, SecurityWeek, and CybersecAsia, identified 236,493 distinct second-level domains (SLDs) built on this framework, with roughly 18,000 concurrently visible at peak and around 1,024 hosted on bulletproof infrastructure.
The operation came to international attention through the October 2024 RainbowEx scandal, in which a bogus cryptocurrency exchange defrauded a large share of the population of San Pedro, Argentina, in a Ponzi/investment-fraud scheme; seven people were reportedly arrested in connection with the case. Public disclosure of the RainbowEx-DCloud link (via New York Times coverage) triggered a surge in new scam-domain registration, peaking at roughly 15,000 new DCloud-based scam sites per month.
Operators reuse a nearly identical technical and behavioral playbook across campaigns: a six-field victim registration flow (phone number, password, confirm password, graphic CAPTCHA, SMS verification code, and a gated invitation/affiliate code that prevents signup without an existing recruiter), fabricated trading dashboards showing fictitious gains, stablecoin (primarily Tether/USDT) deposit collection, blocked withdrawals once the scheme is publicly exposed, and last-ditch 'account verification fee' extortion (documented at $75). Wallet-drainer variants (e.g., bepviews.com) impersonate official BNB Chain and Tether verification flows with a 'Verify Asset'/'Connect Wallet' button that authorizes on-chain asset transfer to attacker-controlled addresses. WhatsApp-impersonation phishing kits (faq-whatsapp-center.com, verify-what.com, and a cluster of whats-z*.vip domains) harvest credentials and session data under the guise of a WhatsApp Help Center or account-verification flow.
Distinct campaign families identified include: RainbowEx (Argentine fake exchange, October 2024), Lightning Shared Scooter Co. / LSSC (U.S. mobility-sharing investment pyramid active in 8+ cities through August 2025, prompting FBI/state investigation, individual losses documented above $370,000), Yuechi Sharing Technology Ltd. / YST (active 2026 bicycle/scooter-sharing investment scam targeting Australia, New Zealand, and the U.S.), and XAEL-AI (an AI-investment-narrative variant sharing YST's backend registration/support infrastructure). Operators construct legitimacy through real government business registrations (Hong Kong Companies Registry, U.S. FinCEN MSB registrations), stock footage (e.g., Nasdaq closing-bell ceremony clips), physical storefronts with functioning products (LSSC's scooters), branded/scripted customer-service chat funnels, and even endorsements from local officials.
Infrastructure is predominantly hosted on legitimate cloud providers (Cloudflare, Alibaba Cloud, Tencent Cloud, AWS) to blend with normal traffic — roughly 94% of scam domains resolve to ASNs also carrying legitimate traffic — while a harder-to-disrupt subset (roughly 6%, rising to 14-17% among 'evasive-tier' operators who strip DCloud's default framework fingerprints) sits on bulletproof hosting, dominated by AS152194 CTG Server Limited, a Hong Kong-registered provider listed on the Spamhaus DROP ASN list. Technical fingerprinting relies on DCloud's recognizable default build scaffolding: Android package naming patterns (uni.UNI[hex], io.DCloud.application.DCloudApplication) and manifest components (DCloudApplication, WebviewActivity, WebAppActivity, ProcessMediator), plus a shared 29-language localization pack including uncommon diaspora languages (Haitian Creole, Kinyarwanda, Alban
Target sectors: financial services, cryptocurrency, retail, consumer, food and beverage, banking, government administration, consulting, education
Target regions: argentina, united states of america, australia, new zealand, Global (all continents)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
FRAUD, MEDIUM, threat intelligence, cybersecurity, T1583, T1583, T1587, T1585, T1608, T1589, T1590, T1593, T1566, T1566