Infoblox Threat Intel has identified over 236,000 scam domains built on the Chinese open-source DCloud Uni-App framework, constituting a massive decentralized scam economy spanning fake crypto exchanges, wallet drainers, gambling sites, and investment frauds. The framework's default build fingerprints enable large-scale identification of malicious sites, though sophisticated operators strip these signatures and migrate to bulletproof hosting (primarily AS152194 CTG Server). Active scams like Yuechi Sharing Technology Ltd. demonstrate evolution toward weaponizing genuine government registrations (FinCEN MSB, Hong Kong Companies Registry) as legitimacy props. Enterprise exposure is substantial, with 985 customers generating 5M+ DNS queries to scam infrastructure, primarily through employee personal device usage.
Investment Scam
3 posts
From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams Threat actors are extensively abusing the legitimate Keitaro Tracker platform to conduct domain cloaking, facilitating large-scale, AI-driven investment and tech support scams. By combining traffic distribution systems with AI-generated deepfakes and localized lures, attackers effectively evade automated security scanners while maximizing victim engagement and conversion rates.
Banners, Bots and Butchers: An Automated Long Con Targeting Japan, Asia, and Beyond A hybrid investment scam campaign is targeting users in Asia and globally by combining malvertising with pig butchering tactics. Threat actors use RDGA-generated domains and AI chatbots on popular messaging apps to automate social engineering, impersonate financial experts, and extract funds from victims.