#dcloud — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dcloud, aggregated by home.social.
-
----------------
🎯 Threat Intelligence
===================Infoblox Threat Intel published research on DCloud Uni-App, a Chinese open-source cross-platform development framework (analogous to React Native or Flutter) that has become the technical foundation for a massive, decentralized scam infrastructure ecosystem primarily operated by Chinese threat actors.
Background
In 2024, the Argentine town of San Pedro made international headlines when approximately 20% of its population, including the chief of police and city council members, discovered that RainbowEx, a cryptocurrency platform they had invested in and promoted, was a coordinated scam. RainbowEx displayed fictional trading activity, drained victim deposits via stablecoin transfers, and blocked withdrawals once publicly exposed. The New York Times, Buenos Aires Herald, and La Opinión Semanario covered the scandal.
Core Discovery
RainbowEx was not bespoke fraud. Its entire visual scaffolding, registration flow, trading dashboard, and Telegram-driven price calls were built using DCloud Uni-App, an open-source toolkit that lets developers write a single Vue.js codebase and deploy across mobile, desktop, and web simultaneously. The scam was assembled from a shared template.
Scale
Infoblox identified 236,493 distinct second-level domains built with DCloud as scam infrastructure. The fraud types span fake cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation sites, and crypto wallet drainers. RainbowEx was one chapter of a much larger, older, and still-active operation.
Threat Actor Mapping
Infoblox mapped hosting patterns and private technical fingerprints that point to at least one large-scale threat actor controlling a significant portion of these scam sites. The infrastructure shows partial centralization despite the decentralized nature of the scam ecosystem.
Physical-World Crossover
The same template family anchors physical-world fraud operations, including the 2024-2025 Lightning Shared Scooter Co. (LSSC) mobility investment scam (covered by NBC News) and an active bicycle-sharing investment scam registered with the U.S. Treasury Department as a money-services business, currently recruiting American investors.
Detection
Every Uni-App project leaves recognizable default artifacts. Defenders can identify DCloud-built websites through code signatures, map scam infrastructure at scale across disparate fraud types, track hosting patterns correlated with specific threat actors, and correlate seemingly unrelated scams through shared technical scaffolding.
Caveat: DCloud is a legitimate Beijing-based company. No evidence of involvement in the fraudulent use of its framework.
🔹 ThreatIntel #DCloud #ScamInfrastructure #Infoblox #PigButchering