Infoblox Threat Intel has identified over 236,000 scam domains built on the Chinese open-source DCloud Uni-App framework, constituting a massive decentralized scam economy spanning fake crypto exchanges, wallet drainers, gambling sites, and investment frauds. The framework's default build fingerprints enable large-scale identification of malicious sites, though sophisticated operators strip these signatures and migrate to bulletproof hosting (primarily AS152194 CTG Server). Active scams like Yuechi Sharing Technology Ltd. demonstrate evolution toward weaponizing genuine government registrations (FinCEN MSB, Hong Kong Companies Registry) as legitimacy props. Enterprise exposure is substantial, with 985 customers generating 5M+ DNS queries to scam infrastructure, primarily through employee personal device usage.
Brand Impersonation
10 posts
From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler The ThreatLabz 2026 Phishing and Initial Access Report highlights a shift towards highly targeted, AI-enabled phishing campaigns against the public sector. Despite a 20% overall drop in phishing volume, attackers are increasingly utilizing AI site builders, encrypted delivery channels, and AiTM/BiTM techniques to bypass traditional MFA and secure initial access.
AI brands as bait: How threat actors are using the AI hype in social engineering Threat actors are increasingly leveraging the hype around AI platforms like ChatGPT, Claude, and DeepSeek to conduct social engineering attacks. These campaigns utilize phishing, malvertising, and SEO poisoning to distribute infostealers such as Vidar or facilitate credential theft via adversary-in-the-middle (AiTM) infrastructure.
8th June – Threat Intelligence Report This threat intelligence report highlights active exploitation of critical vulnerabilities, including a Windows Netlogon RCE (CVE-2026-41089) and an Android Framework flaw. It also details significant data breaches affecting DentaQuest and the UN WFP, emerging AI-driven threats such as EDR evasion labs, a supply chain compromise of the Hola browser, and Iranian state-sponsored espionage operations utilizing Dutch hosting infrastructure.
The Meta 2FA Trap: From Verified Badge to Account Takeover A credential phishing campaign identified by the Cofense Phishing Defense Center targets Meta (Facebook/Instagram) account holders, particularly page administrators, by impersonating Meta's verification badge program. The multi-stage attack chain routes victims through a spoofed Gmail sender to a Google Form, then to a Vercel-hosted phishing page that collects PII, passwords, and 2FA tokens in real time — enabling near-instant account takeover before TOTP codes expire. The abuse of legitimate hosting infrastructure (Google Forms, Vercel) allows the campaign to bypass conventional URL-reputation and email security controls.
Interactive Brokers Phishing Scam: Fake IRS W-8BEN Renewal Alert A recently discovered phishing campaign targets Interactive Brokers users by sending fake IRS Form W-8BEN renewal notices. The emails contain malicious links that direct victims to a spoofed login page designed to harvest their credentials and potentially compromise their financial investments.
Xiaomi Phishing Attempt - Red Flags You Can't Afford to Ignore A recent phishing campaign targets Xiaomi users by impersonating corporate HR communications regarding a new certification. The emails contain masked hyperlinks that redirect victims to a convincing replica of the Xiaomi login portal designed to harvest account credentials.
ClickFix Campaigns Targeting Windows and macOS Insikt Group identified five distinct threat clusters utilizing the ClickFix social engineering technique to trick users into manually executing malicious commands via native system tools. This living-off-the-land approach bypasses traditional browser security to deliver payloads like NetSupport RAT and macOS infostealers across both Windows and macOS environments.
LiveChat Abuse: How Phishers Are Exploiting SaaS Support Tools to Steal Sensitive Data A novel phishing campaign is abusing the legitimate LiveChat SaaS platform to impersonate brands like PayPal and Amazon. By engaging victims in real-time chat interfaces using automated bots or human operators, attackers successfully harvest sensitive information, including account credentials, multi-factor authentication (MFA) codes, personally identifiable information (PII), and credit card details.
Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials Threat actors are leveraging fake digital invitations mimicking trusted brands like Paperless Post to redirect victims to credential harvesting sites. These phishing pages impersonate major login portals and utilize fake error messages to extract multiple sets of credentials, employing newly registered domains and URL shorteners to evade detection.