236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App

Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

ThreatVectr Newsdesk· 2 min read
236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App
Share

Researchers at Infoblox have mapped more than 236,000 websites running off-the-shelf investment-scam templates built on top of DCloud Uni-App, a legitimate Chinese open-source framework for cross-platform app development.

The framework itself isn't the problem. The templates are.

Infoblox says the kits power fake cryptocurrency exchanges, multilingual pig-butchering operations, WhatsApp-based phishing funnels, sham gambling platforms, brand-impersonation sites, and wallet drainers. The common thread: shared Uni-App scaffolding that lets a single operator clone a working scam frontend in minutes and localize it for whichever victim pool they're courting that week.

That's the operational story. Uni-App compiles to web, iOS, Android, and a handful of Chinese mini-program runtimes from one Vue.js codebase. For a developer, that's leverage of the legitimate kind. For a scam crew, it's a force multiplier — one template, every surface a mark might land on.

Infoblox's data set of 236,000+ domains suggests this isn't a handful of affiliates. It's an industrialized supply chain, with template marketplaces, repackaged builds, and (per the researchers' telemetry) heavy DNS reuse across clusters. Many of the sites impersonate real exchanges or financial brands well enough to survive a casual glance at the URL bar.

A few specifics worth flagging for defenders:

  • The fake-exchange templates typically include working order-book animations and a deposit flow that accepts crypto but never permits withdrawal. Classic pig-butchering economics.
  • Wallet-drainer variants hook into WalletConnect and request token approvals on first interaction rather than waiting for a deposit.
  • WhatsApp phishing flows route victims through Uni-App-rendered landing pages before handing them off to human operators on messaging apps.
  • Brand impersonation extends past crypto into retail and gambling, which broadens the victim demographic considerably.

There is no CVE here. No patch. This is abuse of a legitimate development framework, which makes takedown messy: DCloud isn't responsible for what people build, and the hosting and DNS infrastructure is scattered across providers that respond to abuse reports at wildly different speeds.

For blue teams, the practical move is detection at the DNS and proxy layer. Infoblox is publishing indicators tied to the template clusters; defenders running DNS-based filtering should pull those into blocklists and watch for newly registered domains resolving into the same hosting ranges. Email and SMS gateways should treat WhatsApp-redirect landing pages with the same suspicion as credential-phish kits.

For everyone else, the boring advice still holds. If an exchange you've never heard of slides into your DMs offering guaranteed returns, the frontend was probably compiled from the same template as 235,999 others.

Infoblox credits its threat-intelligence team for the discovery; the firm hasn't named individual researchers in the public writeup at time of publication.

© 2026 Threat Vectr