Thehackernews DCloud Uni-App Framework Fuels Global Scam Network with 236,000+ Domains
Article Content
- •DCloud Uni-App powers over 236,000 scam domains linked to various fraudulent activities.
- •More than five million connection attempts to these scams were recorded from 985 organizations.
- •Consumer scams are increasingly infiltrating workplace networks, posing significant risks.
The DCloud Uni-App framework, originally intended for legitimate app development, has been exploited by cybercriminals to create a vast network of scams, including over 236,000 distinct fraudulent domains. These scams encompass fake crypto exchanges, phishing sites, and investment traps, affecting numerous organizations across various sectors. Infoblox Threat Intel reported over five million attempts to connect to these scam sites from 985 organizations in 25 industries. The operations have expanded to include physical-world fraud schemes, with new brands emerging to replace those shut down by authorities. The scale of this operation highlights a shift in consumer fraud, now impacting business networks and raising concerns at the board level. Security professionals are urged to recognize the growing threat as traditional phishing training may not suffice to address these new risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…