[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSeDmpQ_wjmxNxJHsf82n6WVDM_tb21VFQ95Ap4hr3N4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"5212eded-4f9c-45a1-8505-fe9a846a0c9c","236000-fraudulent-dcloud-sites-drive-global-crypto-scam-wave","0c2a9ec0-4d58-4d06-848e-fb6779e7fed4","236,000 Fraudulent DCloud Sites Drive Global Crypto Scam Wave","Threat actors are exploiting DCloud Uni-App, a legitimate open-source framework, as a ready-made infrastructure for running investment fraud, phishing, and crypto wallet drainer campaigns at massive scale. The root issue is that legitimate developer tooling and hosting platforms can be weaponized and resold as scam-as-a-service kits, lowering the barrier for criminal operators globally. This matters because victims across every continent are being deceived by convincing brand-impersonation sites built on trusted frameworks, making detection harder for both users and defenders. The longevity of this campaign — active since mid-2022 — underscores how slow the response to platform abuse can be when it spans multiple jurisdictions and operators.","**Immediate actions:**\n- Train users to verify URLs, SSL certificates, and domain registration details before entering credentials or connecting crypto wallets.\n- Deploy DNS-layer filtering and threat intelligence feeds that flag known DCloud-hosted scam domains at the network perimeter.\n- Alert employees and customers to the existence of brand-impersonation sites and provide clear reporting channels.\n\n**Long-term improvements:**\n- Establish a brand-protection monitoring program that continuously scans for unauthorized use of company names, logos, and domains across open-source hosting platforms.\n- Engage in coordinated disclosure with open-source framework maintainers (e.g., DCloud) to build abuse-reporting and takedown pipelines.\n- Vet third-party frameworks and hosting services during software procurement to assess their abuse-prevention policies and track record.\n\n**Detection measures:**\n- Integrate threat intelligence sources that track scam-as-a-service infrastructure, including template marketplaces, into SIEM alerting workflows.\n- Monitor for lookalike domain registrations using tools such as dnstwist or commercial brand-monitoring services on a continuous basis.\n- Correlate DNS query logs against known malicious DCloud Uni-App indicators of compromise to detect internal users visiting fraudulent sites.",[12,13,14,15,16,17,18,19,20],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","NIST CSF PR.AT-1 – Awareness and Training","NIST CSF DE.CM-7 – Monitoring for Unauthorized Activity","NIST SP 800-161 – Supply Chain Risk Management","GDPR Article 32 – Security of Processing (for EU-facing brand impersonation impact)","ITIL v4 – Service Configuration Management (third-party tooling governance)","NIST SP 800-150 – Guide to Cyber Threat Information Sharing","published","2026-06-29T14:21:42.859083+00:00","2026-06-29T14:21:42.752+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002F236000-dcloud-uni-app-sites-used-in.html","236-000-dcloud-uni-app-sites-used-in-crypto-scams-phishing-and-wallet-drainers-8ca2d5","236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]