More than 200,000 websites are using investment scam templates built with the Chinese open-source framework Uni-App, according to an Infoblox report. Scam second-level domains utilizing the framework have been launched since mid-2022.

Infoblox identified over 236,000 second-level domains powering scam infrastructure. These domains include fake crypto exchanges, fake gambling sites, brand impersonation, WhatsApp phishing, and multi-language pig-butchering websites. An increase in scam sites using the framework was observed since late 2024, following the RainbowEx scandal.

After October 2024, the number of newly observed sites reached approximately 15,000 per month at its peak. Infoblox noted patterns in the growth of these investment sites and coordinated dips in new domain registrations across various hosts.

Uni-App is a cross-platform development toolkit that enables developers to create Vue.js codebases. These codebases can be deployed as mobile and desktop applications or mobile-optimized websites. The framework is widely used in China and supported by a developer ecosystem, powering thousands of legitimate products.

DCloud, the maker of Uni-App, does not appear to be involved in the fraudulent use of its framework. Infoblox discovered that threat actors are selling these investment scam templates. Some operations using Uni-App include RainbowEx, a fake cryptocurrency platform that caused losses for residents in an Argentine town, and Lightning Shared Scooter Co. (LSSC), which led to millions of dollars in losses in the U.S.

Yuechi Sharing Technology Ltd. (YST), an investment-scam operation active in Australia, New Zealand, and the United States, has a frontend built with the Uni-App framework. YST possesses legitimate registration paperwork but is linked to a network of other investment-scam websites, according to Infoblox.