236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App

Infoblox researchers tie a sprawling fake-exchange and wallet-drainer ecosystem to a legitimate Chinese cross-platform dev framework.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
236,000 Sites Run Pig-Butchering Templates Built on DCloud Uni-App
Share

Key points

  • Infoblox has mapped more than 236,000 websites running investment-scam templates built on DCloud Uni-App, a legitimate Chinese open-source framework.
  • The kits power fake cryptocurrency exchanges, multilingual pig-butchering operations, WhatsApp phishing funnels, and wallet drainers.
  • Wallet-drainer variants hook into WalletConnect and request token approvals on first interaction, before any deposit is made.
  • There is no CVE and no patch: this is framework abuse, which makes takedown slow and jurisdiction-dependent.
  • Blue teams should prioritize DNS and proxy-layer detection and pull Infoblox's published indicators into blocklists.

What is DCloud Uni-App and why does it matter here?

DCloud Uni-App is a legitimate Chinese open-source framework that compiles a single Vue.js codebase into web, iOS, Android, and several Chinese mini-program runtimes. For scam operators, that reach is the point: one template, every surface a potential victim might land on. The framework itself is not the problem. What Infoblox found is an industrialized supply chain layered on top of it, complete with template marketplaces, repackaged builds, and heavy DNS reuse across clusters.

How do these scam templates actually work?

The fake-exchange templates include working order-book animations and a deposit flow that accepts cryptocurrency but never permits withdrawal. That's the core pig-butchering mechanic. WhatsApp phishing flows route victims through Uni-App-rendered landing pages before handing them off to human operators on messaging apps. Brand impersonation extends beyond crypto into retail and gambling, which broadens the victim pool well past crypto-native users.

Should you worry about these sites surviving a basic check?

Many of the 236,000-plus domains impersonate real exchanges or financial brands convincingly enough to pass a quick look at the URL bar. The volume alone is the threat: at that scale, even a low conversion rate funds significant criminal infrastructure. Our earlier coverage of DOJ action against the HuiOne network on 24 June 2026 showed how pig-butchering proceeds flow through layered corporate structures once victims are in; this Infoblox research describes the front end of that same pipeline.

What can defenders do right now?

Infoblox is publishing indicators tied to the template clusters. Defenders running DNS-based filtering, a layer that blocks malicious domains before a connection is established, should pull those into blocklists and watch for newly registered domains resolving into the same hosting ranges. Email and SMS gateways should treat WhatsApp-redirect landing pages with the same suspicion as credential-phishing kits.

The harder problem is structural. DCloud isn't responsible for what people build on its framework, and the hosting and DNS infrastructure is scattered across providers with wildly different abuse-response timelines. No single takedown fixes this. Detection at scale is the realistic answer for now.

If an exchange you've never heard of slides into your DMs offering guaranteed returns, close the tab.

Infoblox credits its threat-intelligence team for the discovery; the firm had not named individual researchers in its public writeup at time of publication.

© 2026 Threat Vectr