Cybersecurity News in Asia

RECENT STORIES:

SEGA moves faster with flow-based network monitoring
From frontier policy to boardroom action: how enterprises should gover...
How can APAC enterprises face AI governance questions deftly? Key ques...
China-linked cyber espionage group shifts focus to another brand of ro...
Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech...
Visa Launches Enhanced A2A Protect Innovations to Help Financial Insti...
LOGIN REGISTER
CybersecAsia
  • Features
    • Featured

      Dealing with agentic AI governance and resilience challenges

      Dealing with agentic AI governance and resilience challenges

      Tuesday, September 1, 2026, 11:51 AM Asia/Singapore | Features
    • Featured

      How well do you know your agent?

      How well do you know your agent?

      Thursday, August 20, 2026, 3:21 PM Asia/Singapore | Features
    • Featured

      Bringing proof of identity to the digital economy

      Bringing proof of identity to the digital economy

      Wednesday, August 19, 2026, 10:50 AM Asia/Singapore | Features
  • Opinions
  • Tips
  • Whitepapers
  • AWARDS 2026
  • Directory
  • E-Learning

Select Page

News

RainbowEx scam template scales to 236,493 domains with workplace spillover

By CybersecAsia editors | Tuesday, June 30, 2026, 1:52 PM Asia/Singapore

RainbowEx scam template scales to 236,493 domains with workplace spillover

Latest forensic findings suggest that the Ponzi scam in 2024 was based on a repeatable template in use since mid-2022.

An open-source framework has been used by cybercriminals to power more than 236,000 scam websites worldwide, including a fake cryptocurrency exchange that tricked thousands of residents in San Pedro, Argentina.

According to researchers, the cryptocurrency investment scam known as RainbowEx that occurred in late 2024, where roughly one-fifth of the population in the small town of San Pedro had lost money in a coordinated scam. Victims had been baited with promises of quick profits and then trapped in a Ponzi-style operation that blocked withdrawals once the scheme was exposed.

Since then, forensic efforts have shown that RainbowEx was not a unique fraud. It had been a repeatable template built on a legitimate Chinese web-developer toolkit called DCloud Uni-App. The same framework had actually been widely used since mid-2022 to create scam sites that impersonate crypto exchanges, run multi-language “pig-butchering” campaigns, deliver social media phishing messages, operate fake gambling platforms, and drain digital wallets.

The full scale of the operation is now clearer. Researchers from Infoblox have identified at least 236,493 distinct second-level domains tied to this framework, spanning fake trading sites, brand-impersonation pages and other fraud operations hosted on various cloud providers. The criminal activity is not new but has scaled dramatically, with domain creation accelerating after the RainbowEx scandal. The scam has rippled outwards to reach workplaces.

According to researchers, more than five million connections have been attempted from 985 organizations across 25 industries, including many small employee visits triggered by links shared through WhatsApp, Telegram and social media. This means such scams have increasingly crossed into office networks, creating risks of data exposure and financial loss that standard employee training may not fully address.

Said Zach Edwards, Staff Threat Researcher, Infoblox: “This is no longer just a consumer fraud problem. When scam traffic reaches work devices and work networks, companies inherit the fallout, from employee losses to possible data exposure and tougher scrutiny from leadership.”

Share:

PreviousSK shieldus Receives Frost & Sullivan’s 2026 APAC Customer Value Leadership Recognition for Excellence in Cybersecurity Services
NextIndia bank domain registry exposed sensitive data in security lapse: expose

Related Posts

What three business risks hogged the minds of APAC and global business leaders?

What three business risks hogged the minds of APAC and global business leaders?

Thursday, November 23, 2023

Ransomware attacks on health sectors are not easing up

Ransomware attacks on health sectors are not easing up

Wednesday, November 4, 2020

Amid crumbling public faith in online information, are voters worried about deepfakes?

Amid crumbling public faith in online information, are voters worried about deepfakes?

Wednesday, August 28, 2024

News Exclusive: Autonomous vehicles can be hacked using rigged signages!

News Exclusive: Autonomous vehicles can be hacked using rigged signages!

Wednesday, February 19, 2020

Leave a reply Cancel reply

You must be logged in to post a comment.

Voters-draw/RCA-Sponsors

Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
Slide
previous arrow
next arrow

CybersecAsia Voting Placement

Gamification listing or Participate Now

PARTICIPATE NOW

Vote Now -Placement(Google Ads)

Top-Sidebar-banner

Whitepapers

  • Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Critical Security Threatsand the Need for ZTNA: How evolving cyberattacks demand a Zero Trust approach

    Cyber threats have become more frequent and sophisticated, targeting organizations of all sizes across all …Download Whitepaper
  • Zero Trust Made Simple: Why it matters and how to get started

    Zero Trust Made Simple: Why it matters and how to get started

    Data breaches and cyberattacks are no longer limited to large, high-profile organizations.Download Whitepaper
  • Cloud Secure Edge: Remote access, better security

    Cloud Secure Edge: Remote access, better security

    ​SonicWall Cloud Secure Edge™ is a modern, cloud-native Security Service Edge (SSE) solution that addresses …Download Whitepaper
  • Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Closing the Gap in Email Security:How To Stop The 7 Most SinisterAI-Powered Phishing Threats

    Insider threats continue to be a major cybersecurity risk in 2024. Explore more insights on …Download Whitepaper

Middle-sidebar-banner

Case Studies

  • How a Vietnamese D2C retailer built its own secure digital infrastructure

    How a Vietnamese D2C retailer built its own secure digital infrastructure

    Would your organization build your own digital infrastructure – including AI governance and cybersecurity – …Read more
  • Cyber protection for medical clinics in Singapore

    Cyber protection for medical clinics in Singapore

    As Singapore’s healthcare sector becomes increasingly digital and interconnected, clinics are facing heightened cyber risks, …Read more
  • India’s WazirX strengthens governance and digital asset security

    India’s WazirX strengthens governance and digital asset security

    Revamping its custody infrastructure using multi‑party computation tools has improved operational resilience and institutional‑grade safeguardsRead more
  • Bangladesh LGED modernizes communication while addressing data security concerns

    Bangladesh LGED modernizes communication while addressing data security concerns

    To meet emerging data localization/privacy regulations, the government engineering agency deploys a secure, unified digital …Read more

Bottom sidebar

Other News

  • Cohesity Delivers New Managed Clean Room Capability to Enhance HCLTech VaultNXT

    Wednesday, September 2, 2026
    Cohesity Clean Room solution and …Read More »
  • Visa Launches Enhanced A2A Protect Innovations to Help Financial Institutions Stop Fraud Before Money Leaves Accounts

    Wednesday, September 2, 2026
    New unified fraud score is …Read More »
  • Malaysia’s Cybersecurity Leaders to Convene at the 34th Edition Cyber Security Summit Malaysia 2026

    Tuesday, September 1, 2026
    Summit to Bring Together More …Read More »
  • ICAC Commissioner in Vienna to meet new UNODC Chief to foster anti-corruption strategic collaboration and unveil ICAC’s AI enforcement system “Tianma” at UNODC’s anti-graft conference

    Tuesday, September 1, 2026
    VIENNA, Sept. 1, 2026 /PRNewswire/ …Read More »
  • Visa Expands Support for its Clients and the Industry as Organisations Navigate New AI Era of Cybersecurity

    Friday, August 28, 2026
    Latest Visa Vulnerability Agentic Harness release …Read More »
  • Our Brands
  • DigiconAsia
  • MartechAsia
  • Home
  • About Us
  • Contact Us
  • Sitemap
  • Privacy & Cookies
  • Terms of Use
  • Advertising & Reprint Policy
  • Media Kit
  • Subscribe
  • Manage Subscriptions
  • Newsletter

Copyright © 2026 CybersecAsia All Rights Reserved.