Chinese Framework Powers 200,000 Scam Sites
More than 200,000 websites are using investment scam templates built with the Chinese open source framework Uni-App, Infoblox reports.
A cross-platform development toolkit, Uni-App allows developers to create Vue.js codebases that can be deployed as mobile and desktop applications, or as mobile-optimized websites simultaneously.
Widely used in China and supported by a developer ecosystem, the framework powers thousands of legitimate products, and its maker DCloud does not appear to be involved in its fraudulent use.
However, Infoblox discovered that threat actors are selling investment scam templates, and that numerous scam websites using such templates appear linked to the same cluster of activity.
“Beyond the technical connections, we also uncovered patterns in the growth of the DCloud investment sites, along with coordinated dips in new domain registrations seen across scam websites on diverse hosts, an indication of a centralized owner facing disruption or making coordinated changes across all their DCloud investment...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE