Infoblox Threat Intel has identified over 236,000 scam domains built on the Chinese open-source DCloud Uni-App framework, constituting a massive decentralized scam economy spanning fake crypto exchanges, wallet drainers, gambling sites, and investment frauds. The framework's default build fingerprints enable large-scale identification of malicious sites, though sophisticated operators strip these signatures and migrate to bulletproof hosting (primarily AS152194 CTG Server). Active scams like Yuechi Sharing Technology Ltd. demonstrate evolution toward weaponizing genuine government registrations (FinCEN MSB, Hong Kong Companies Registry) as legitimacy props. Enterprise exposure is substantial, with 985 customers generating 5M+ DNS queries to scam infrastructure, primarily through employee personal device usage.
Pig Butchering
3 posts
From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers An Android banking trojan is being distributed globally as a Malware-as-a-Service (MaaS) from scam centers in Cambodia, utilizing forced labor to conduct social engineering campaigns. The malware features extensive surveillance capabilities, including SMS interception and biometric capture, allowing attackers to bypass KYC and OTP protections to commit direct financial fraud.
Banners, Bots and Butchers: An Automated Long Con Targeting Japan, Asia, and Beyond A hybrid investment scam campaign is targeting users in Asia and globally by combining malvertising with pig butchering tactics. Threat actors use RDGA-generated domains and AI chatbots on popular messaging apps to automate social engineering, impersonate financial experts, and extract funds from victims.