A global network of critical scams driven by UniApp templates in more than 236,000 domains

Author: Published 3 min de lectura 152 reading

The images in this article were generated with artificial intelligence. How we publish

Infoblox has identified a massive phenomenon: more than 236,000 second level domains that house investment scam templates built with the Chinese open source DCoud Uni-App. These templates are being used to mount false cryptomoneda exchanges, multilingual "pig-butching" operations, WhatsApp phishing networks, rigged casinos and lotteries, pages that supplant known brands and applications that try to empty crypto wallets by inducing the victim to connect its keys or approve transactions.

That a legitimate framework such as Uni-App is the basis does not imply malice inherent in the project, but does explain the speed and scale: reusable templates allow operators of different levels to deploy complete sites with credible interfaces in record time. The framework itself is publicly documented on its official site https: / / uniapp.dcloud /, which makes it easier for both honest developers and cybercriminals to take advantage of the same components.

A global network of critical scams driven by UniApp templates in more than 236,000 domains
Image generated with IA.

Infoblox also provides signs of coordination and professionalization behind much of these operations: synchronized falls in new domain records, shared technical prints, common patterns in how they communicate with victims and hosting decisions. This combination draws two different populations: a basic "tier" where operators use the default signature of the framework and are usually housed in mainstream suppliers, and an evasive layer where the frame marks have been removed and more frequently used to bullet and take resistance tactics down.

The risk is real and documented. Cases such as the RainbowEx platform, which ended up being a ponzi facade with tens of thousands of victims in Argentina and led to public arrests, illustrate the consequence: massive economic loss, reputational damage and pressure networks that make victims recruiters through invitation codes and promises of return. A recurring feature is the entry door by means of an "invitation code," which forces the victim to be recruited and to become an agent for the expansion of the scheme.

The implications for public and private security are broad. First, the presence of millions of easy-to-deploy templates hampers the traditional response based only on closing individual domains; second, the use of legitimate suppliers such as Cloudflare, Alibaba, Tencent and AWS for a large part of the domains complicates the attribution and acceleration of debubs; and third, the existence of operators using takedowns-resistant infrastructure shows that technical defenses must be complemented by regulatory actions and international cooperation between registrators, hosts and law enforcement.

A global network of critical scams driven by UniApp templates in more than 236,000 domains
Image generated with IA.

For individual users, the practical recommendations are clear: do not connect your wallet to unverified sites, distrust of interfaces that promise guaranteed returns, avoid entering private keys or approve signed transactions from links received by messaging, and prefer hardware wallets for funds that you don't want to risk. Review the age of the domain and the presence of independent reviews, confirm that communication comes from official channels and report any suspicious site to your local CERT or host provider are measures that reduce exposure.

Companies, platforms and infrastructure providers also have work to do: improve behavioural and template-based detection, share community engagement indicators, accelerate identity verification processes for digital financial services and work with authorities to dismantle organized networks. DNS filtering tools and endpoints security solutions can mitigate corporate and end-user exposure.

Infoblox's finding stresses that the modern fraud economy is based on technological and commercial chains that go through legitimate jurisdictions and suppliers. The response will require a combination of technical analysis, legal action and continuing education. For those who want to deepen the report and understand the methodology used, Infoblox explains his public findings on his website https: / / www.infoblox.com / where trends in DNS threats and abuse of common infrastructure are also discussed.

Coverage

Related

More news on the same subject.