Uni-App Framework Powers 200,000 Investment Scam Sites

Over 236,000 scam domains built with Uni-App highlight a growing threat from fake cryptocurrency platforms and pig-butchering schemes.

By Central
Infoblox identified 236,000 scam domains using the DCloud-fingerprinted Uni-App framework.
Highlights
  • Uni-App powers over 236,000 second-level domains used for investment fraud and fake crypto platforms.
  • The RainbowEx scandal in 2024 triggered a surge in new scam domains built with Uni-App.
  • Scammers sell pre-built Uni-App templates in underground markets, lowering the technical barrier to entry.

More than 236,000 second-level domains powering investment scams, fake cryptocurrency platforms, and pig-butchering operations have been built using the Chinese open-source framework Uni-App, according to a threat intelligence investigation. The cross-platform development toolkit, widely used for legitimate applications, has become a preferred foundation for a sprawling global scam economy that shows no signs of slowing.

Uni-App allows developers to write Vue.js code that deploys simultaneously as mobile apps, desktop applications, and mobile-optimized websites. Its large developer ecosystem in China and the support of its creator, DCloud, have made it a popular choice for legitimate products. DCloud itself does not appear to be complicit in the fraudulent use of its framework. Nevertheless, threat actors have adopted it at scale, selling pre-built investment scam templates that share technical fingerprints pointing to a centralized origin or a tightly coordinated operator network.

How Scammers Weaponized a Legitimate Development Framework

Infoblox identified more than 236,000 second-level domains exhibiting DCloud-fingerprinted frontends. These sites range from fake cryptocurrency exchanges and deposit-and-trade platforms to gambling impersonators, WhatsApp phishing pages, and multi-language pig-butchering operations. The cybersecurity firm observed a notable increase in new scam domains beginning in late 2024, following widespread media coverage of the RainbowEx scandal.

RainbowEx, a fake cryptocurrency platform that made international headlines after defrauding thousands of residents in a small Argentine town, was built using the same Uni-App framework. The publicity around that operation appears to have advertised the framework within the scam-operator ecosystem. After October 2024, the number of newly observed scam sites jumped to roughly 15,000 per month at its peak.

Multiple Operators, Shared Infrastructure Patterns

While the scam domains are hosted across numerous providers, Infoblox found evidence of coordinated behavior that suggests shared ownership or centralized management across many of the sites. “Beyond the technical connections, we also uncovered patterns in the growth of the DCloud investment sites, along with coordinated dips in new domain registrations seen across scam websites on diverse hosts, an indication of a centralized owner facing disruption or making coordinated changes across all their DCloud investment scam sites,” the report notes.

The largest portion of DCloud-fingerprinted sites consists of investment scam domains run by multiple unrelated operators — possibly dozens or even hundreds, according to the cybersecurity firm. In addition to the fake cryptocurrency exchanges, the infrastructure includes crypto wallet drainers, prediction-market impersonators, and credential-harvesting pages targeting messaging platforms.

Real-World Operations: Scooter Scams and Fraudulent Storefronts

Two notable operations highlight how Uni-App-powered scams extend beyond pure online fraud into complex real-world schemes. Lightning Shared Scooter Co. (LSSC) promised investors sharp increases in passive revenue through a high-tech scooter-sharing company, using physical storefronts to create a veneer of legitimacy. The operation likely caused millions of dollars in losses across the United States.

A similar operation, Yuechi Sharing Technology Ltd. (YST), is currently active in Australia, New Zealand, and the United States. YST has legitimate registration paperwork but is connected to a network of other investment-scam websites. Its frontend is also built using the Uni-App framework. “For the last two years, there’s been a dramatic scaling up of scam websites using the DCloud framework, and operators of these sites continue to launch complex real-world schemes to trick victims,” Infoblox observes.

What Makes the Uni-App Framework Attractive to Scam Operators

The cross-platform nature of Uni-App allows scammers to deploy a single codebase across mobile apps, desktop applications, and mobile-optimized websites, maximizing their reach while minimizing development cost. The framework’s legitimate popularity also helps fraudsters evade basic scrutiny. Pre-built scam templates sold in underground markets lower the technical barrier to entry, enabling operators with limited coding skills to launch convincing fraudulent platforms at scale.

What Users Should Do to Protect Themselves

If you encounter an investment platform promising unusually high or passive returns, verify its legitimacy through independent regulatory bodies before committing any funds. Be especially cautious of operations that use physical storefronts alongside online platforms, as scammers increasingly invest in real-world props to build trust. Use a reputable multi-layer endpoint protection solution with real-time threat detection to block known phishing and scam domains. Enable two-factor authentication on all financial accounts and monitor them for unauthorized transactions. If you suspect you have engaged with a fraudulent platform, contact your financial institution immediately and report the operation to authorities such as the FBI’s IC3 in the United States, Action Fraud in the UK, the ACCC’s Scamwatch in Australia, or the Canadian Anti-Fraud Centre.

Share This Article