The images in this article were generated with artificial intelligence. How we publish
Infoblox has identified a massive phenomenon: more than 236,000 second level domains that house investment scam templates built with the Chinese open source DCoud Uni-App. These templates are being used to mount false cryptomoneda exchanges, multilingual "pig-butching" operations, WhatsApp phishing networks, rigged casinos and lotteries, pages that supplant known brands and applications that try to empty crypto wallets by inducing the victim to connect its keys or approve transactions.
That a legitimate framework such as Uni-App is the basis does not imply malice inherent in the project, but does explain the speed and scale: reusable templates allow operators of different levels to deploy complete sites with credible interfaces in record time. The framework itself is publicly documented on its official site https: / / uniapp.dcloud /, which makes it easier for both honest developers and cybercriminals to take advantage of the same components.

Infoblox also provides signs of coordination and professionalization behind much of these operations: synchronized falls in new domain records, shared technical prints, common patterns in how they communicate with victims and hosting decisions. This combination draws two different populations: a basic "tier" where operators use the default signature of the framework and are usually housed in mainstream suppliers, and an evasive layer where the frame marks have been removed and more frequently used to bullet and take resistance tactics down.
The risk is real and documented. Cases such as the RainbowEx platform, which ended up being a ponzi facade with tens of thousands of victims in Argentina and led to public arrests, illustrate the consequence: massive economic loss, reputational damage and pressure networks that make victims recruiters through invitation codes and promises of return. A recurring feature is the entry door by means of an "invitation code," which forces the victim to be recruited and to become an agent for the expansion of the scheme.
The implications for public and private security are broad. First, the presence of millions of easy-to-deploy templates hampers the traditional response based only on closing individual domains; second, the use of legitimate suppliers such as Cloudflare, Alibaba, Tencent and AWS for a large part of the domains complicates the attribution and acceleration of debubs; and third, the existence of operators using takedowns-resistant infrastructure shows that technical defenses must be complemented by regulatory actions and international cooperation between registrators, hosts and law enforcement.

For individual users, the practical recommendations are clear: do not connect your wallet to unverified sites, distrust of interfaces that promise guaranteed returns, avoid entering private keys or approve signed transactions from links received by messaging, and prefer hardware wallets for funds that you don't want to risk. Review the age of the domain and the presence of independent reviews, confirm that communication comes from official channels and report any suspicious site to your local CERT or host provider are measures that reduce exposure.
Companies, platforms and infrastructure providers also have work to do: improve behavioural and template-based detection, share community engagement indicators, accelerate identity verification processes for digital financial services and work with authorities to dismantle organized networks. DNS filtering tools and endpoints security solutions can mitigate corporate and end-user exposure.
Infoblox's finding stresses that the modern fraud economy is based on technological and commercial chains that go through legitimate jurisdictions and suppliers. The response will require a combination of technical analysis, legal action and continuing education. For those who want to deepen the report and understand the methodology used, Infoblox explains his public findings on his website https: / / www.infoblox.com / where trends in DNS threats and abuse of common infrastructure are also discussed.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...