Uni-App scam framework is powering more than 200,000 fake investment, crypto, gambling, and phishing websites

Researchers say criminals have used templates built with DCloud's Uni-App framework to launch more than 200,000 scam websites targeting internet users. Infoblox identified over 236,000 second-level domains tied to the ecosystem, including fake crypto exchanges, pig-butchering investment sites, gambling and prediction-market impersonators, WhatsApp phishing pages, and credential-harvesting sites; the activity has grown since mid-2022 and accelerated after late 2024.
Why it matters: This is a mass-scale fraud and phishing infrastructure that can steal money, passwords, and cryptocurrency from ordinary users. Consumers should be wary of unsolicited investment offers and crypto platforms, while defenders can use the shared framework fingerprints and domain patterns to block or investigate related sites.

Sources

Chinese Framework Powers 200,000 Scam Sites
Ionut Arghire 2026.06.27 100% relevant
This article establishes a distinct underlying story: a specific shared scam-site ecosystem built on Uni-App templates, with quantified scale, infrastructure patterns, and named fraud operations such as RainbowEx, LSSC, and YST.
← Back to all stories