{"id":14335,"date":"2026-10-09T07:00:31","date_gmt":"2026-10-09T14:00:31","guid":{"rendered":"https:\/\/www.infoblox.com\/blog\/?p=14335"},"modified":"2026-10-09T07:48:49","modified_gmt":"2026-10-09T14:48:49","slug":"when-a-wallet-drainer-asks-dns-where-to-go","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/","title":{"rendered":"When a Wallet Drainer Asks DNS Where to Go"},"content":{"rendered":"<p><em><strong>How the Noir kit uses DNS TXT records and DoH as a dynamic infrastructure control plane<\/strong><\/em><\/p>\n<h3>Executive summary<\/h3>\n<ul class=\"list-spacing\">\n<li>We found a cryptocurrency wallet-drainer kit, self-branded as Noir, that uses DNS TXT records to locate its hosted pool; currently these run on Cloudflare Pages. The loader races three public DNS-over-HTTPS (DoH) services and uses the first valid answer.<\/li>\n<li>The architecture separates long-lived lure pages from short-lived operational infrastructure. Changing one TXT record can repoint deployed lures without rebuilding them, while a 60-second cache and self-healing retry logic help the kit recover when a pool host is retired.<\/li>\n<li>The drainer does not need a seed phrase, password, or private key. It tailors content to the user after receiving initial read permissions, developing a plan for the specific wallet. Then it obtains spending permissions that can look less alarming than a direct transfer and performs the theft from attacker-controlled infrastructure.<\/li>\n<li>The source is unusually self-documenting. Plain-English comments describe bugs, fixes, operator support, and design decisions. It seems likely this software is created and maintained with AI assistance.<\/li>\n<li>DoH provides threat actors with a highly resilient command-and-control (C2) mechanism. Risk averse networks may want to block access to DoH and fully monitor their DNS.<\/li>\n<\/ul>\n<p>The wallet drainer was interesting. The fact that it found its location via DNS was more interesting to us.<\/p>\n<p>While investigating a fake crypto voting page, we found a loader for a wallet-drainer kit that calls itself Noir. The lure looked like the familiar sort of thing: a token vote, airdrop, listing, decentralized exchange clone, or eligibility check that invites the visitor to connect a wallet. Underneath, however, the page did not contain a durable link to the drainer infrastructure. Before the operational flow could begin, the loader queried a DNS TXT record through public DoH services to learn which backend pool was active. See Figure 1.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-image1.jpg\"><\/p>\n<p class=\"image-caption\">Figure 1. The attack flow and DNS C2 element of Noir crypto draining service.<\/p>\n<p>That design turns DNS into a small but effective control plane. The lure is the durable entry point. The TXT record supplies the current pool. The pool serves the interface and connects the victim to the backend that assesses the wallet, prepares the requests, and captures the resulting permissions. If a pool is blocked or removed, the operator can change the DNS answer instead of replacing every lure already deployed.<\/p>\n<p>Noir is a useful case study because it combines several developments that defenders will continue to encounter elsewhere: public DoH used outside the enterprise resolver path, DNS records used as live configuration, cloud-hosted infrastructure that can be replaced quickly, per-victim decision-making, and code that arrives with unusually candid documentation from its own developer.<\/p>\n<p>We\u2019ve seen DNS TXT records used for a control plane many times over the years. Most notably by <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/detour-dog-dns-malware-powers-strela-stealer-campaigns\/\"><strong>Detour Dog<\/strong><\/a>, who used it to forward users through an affiliate marketing platform, as well as for the distribution of information stealers. A <a href=\"https:\/\/www.infoblox.com\/blog\/security\/dns-a-small-but-effective-c2-system\/\"><strong>wide range of other actors<\/strong><\/a> have used both TXT and other record types for C2, including the sophisticated remote access system, <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns\/\"><strong>Decoy Dog<\/strong><\/a>.<\/p>\n<h3>The Victim Does Not Hand Over a Wallet<\/h3>\n<p>The easiest way to misunderstand a wallet drainer is to imagine a victim typing a seed phrase into a form. Noir does not require that. The victim can lose assets without surrendering a password, private key, or recovery phrase, and without approving a transaction that plainly says \u201csend this amount to this address.\u201d<\/p>\n<p>The interaction begins with a standard wallet-connection flow. Connecting initially shares the public wallet address, which alone is not enough to steal funds. The kit then uses that address, the blockchain network, and an estimate of the portfolio value to request a plan from its backend. The backend can inspect what the wallet holds and return a sequence tailored to that victim rather than using one generic set of prompts.<\/p>\n<p>The important distinction is between transferring an asset and granting permission to spend it. Legitimate decentralized applications routinely request approvals or typed-data signatures to perform actions on a user\u2019s behalf. Noir uses the same underlying concepts for a different purpose. Depending on the wallet\u2019s capabilities, the victim may see a gasless signature request, a bundled confirmation containing multiple approvals, or individual approval transactions. A signature request can appear less consequential than an explicit transfer because the theft itself is not the transaction being shown at that moment.<\/p>\n<p>Each captured signature or approval is submitted to the backend immediately. The kit does not need to wait for the visitor to complete the entire sequence. Its own internal log language describes this as \u201cdraining at capture.\u201d The attacker-side relayer can then exercise the granted permission and execute the transfer from its infrastructure. The victim\u2019s wallet may show the earlier permission, but not a straightforward outbound transaction initiated from the wallet for the eventual theft.<\/p>\n<p>The kit also cleans up after itself. Once the flow finishes, it disconnects the WalletConnect session, so the malicious application no longer remains visible in the wallet\u2019s connected-applications list. The combination matters: a familiar connection prompt, a request that does not look like a direct payment, attacker-side execution, and removal of the most obvious lingering clue.<\/p>\n<h3>A TXT Record Points to the Current Drainer<\/h3>\n<p>In the samples we reviewed, the attack begins with JavaScript file embedded in the lure page. That script contains a decimal character-code array, which is decoded and executed from the primary page, creating a loader for the drainer. For example, in one case:<\/p>\n<ul class=\"list-spacing\">\n<li>A URL hosted on listchoiseopenleaderboardseptember[.]netlify[.]app<\/li>\n<li>Loaded a script called k1xfns97l5w.5cgsbfh2.js<\/li>\n<li>Which contained a character-code array that was used to complete the loader initialization<\/li>\n<\/ul>\n<p>Once running, the loader races three DoH queries in parallel for the TXT record at _r.noir[.]black. The observed providers were Google Public DNS and two Cloudflare endpoints, including direct access to 1.1.1.1. The response includes the current drainer pool domain. For example, render-984.pages[.]dev was one of the returned domains.<\/p>\n<p>The loader also queries an API endpoint on noir[.]black for a \u201croad\u201d configuration. That response can provide an independently resolved fallback pool, which gives the kit another path on networks where direct DoH fails or is blocked. The client performs the DNS race and configuration request concurrently, a choice documented in the source as a latency improvement. The returned mode determines whether the malicious flow is imported into the lure page or displayed through a transparent, full-viewport frame that appears to belong to the page the visitor intentionally opened.<\/p>\n<p>Once the road directions are returned, a short script at the drainer pool domain, e.g., render-984.pages[.]dev, executes and effectively wires the drainer engine to the original page. See Figure 2.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-image2.jpg\"><\/p>\n<p class=\"image-caption\">Figure 2. The script from the domain found in the dynamic DNS TXT record. It loads the engine via index.js and constructs the per-deployment configuration including a WalletConnect project ID. This script was observed on render-984.pages[.]dev.<\/p>\n<p>Noir caches the pool hostname in local storage for 60 seconds, matching the TXT record\u2019s 60-second TTL. The comments explain why: an earlier, longer cache continued sending visitors to dead infrastructure after rotation. If the current host fails its readiness check, the loader removes the cached value and retries, preferring the server-provided fallback.<\/p>\n<h3>The Source Explains Itself<\/h3>\n<p>The most entertaining part of the investigation was not obfuscation. It was documentation: it resembles an internal engineering log accidentally, or indifferently, shipped with production code.<\/p>\n<p>We found extensive plain-English comments describing design decisions, dated defects, support reports, and corrective changes. The comments discuss dead pool hosts after TXT rotation, a wallet prompt that exposed the canonical origin, pages that turned white when framed incorrectly, and a requirement that closing the flow always carry a reason. They refer to a \u201cfounder,\u201d distinguish the visitor from the operator page, and include numbered fix-list language. The kit even provides a debug mode with an on-screen console and a way for an operator to copy a trace from a victim\u2019s phone for support. See Figure 3 for comments found in the script hosted at render-984.pages[.]dev.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-image3.jpg\"><\/p>\n<p class=\"image-caption\">Figure 3. Example commentary included the source code on render-984.pages[.]dev<\/p>\n<p>It reads like modern AI-assisted development: verbose explanatory prose wrapped around implementation, explicit reasoning about edge cases, and comments that restate intent for the next developer or model to consume. A human developer could have produced it. But most trained developers aren\u2019t telling their life story in their code comments. See Figure 4 for more examples of comments found in the code.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-image4.jpg\"><\/p>\n<p class=\"image-caption\">Figure 4. Various comments found in pieces of the Noir Drainer kit scripts<\/p>\n<p>The code and infrastructure both point toward a shared service used across many lure themes rather than a single actor. The notes identify fake community votes, airdrops, eligibility checks, exchange clones, and brand-specific spoofs that reuse the same engine. Operator-specific configuration identifiers connect the lure to the backend, while shared infrastructure and a common wallet-connection project identifier provide useful clustering signals. There appear to be service tickets being addressed in comments.<\/p>\n<p>Also pointing to a service is the variety of lures. We have seen:<\/p>\n<ul class=\"list-spacing\">\n<li><strong>Fake token &#8220;Community Voting&#8221; pages<\/strong> impersonating CoinMarketCap, DexScreener, OKX<\/li>\n<li><strong>Fake airdrop\/claim pages<\/strong> impersonating Uniswap, Lido, Hyperliquid, Morpho, Ondo, LayerZero, MegaETH<\/li>\n<li><strong>Fake DEX\/swap clones<\/strong><\/li>\n<li><strong>&#8220;ETH Airdrop Eligibility Check&#8221;<\/strong><\/li>\n<li><strong>&#8220;Desktop Browser Required&#8221;<\/strong> gate pages<\/li>\n<li><strong>brand spoofs<\/strong>: Polymarket, SpaceX\/Ondo tokenized-RWA, Grass, Venice, FoxFi<\/li>\n<\/ul>\n<h3>Indicators<\/h3>\n<p>_r.noir[.]black<\/p>\n<p>noir[.]black<\/p>\n<p>render-984.pages.dev<\/p>\n<p>listchoiseopenleaderboardseptember[.]netlify[.]app<\/p>\n<style>\n.savy-seahorse-table {\nfont-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.code-format {\/*font-family: 'Courier New';*\/}.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;flex-wrap: wrap;justify-content: space-between;}.img-container img {width: 49%;margin-bottom: 10px;}.img-container-3-col img {width: 30%;margin-bottom: 10px;object-fit: contain;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;margin-bottom: 20px;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  max-width: 100%;  height: auto;width: auto;}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n.img-400{\nmax-width: 400px; width: 100%;\n}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">When a Wallet Drainer<\/span> Asks DNS Where to Go');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How the Noir kit uses DNS TXT records and DoH as a dynamic infrastructure control plane Executive summary We found a cryptocurrency wallet-drainer kit, self-branded as Noir, that uses DNS TXT records to locate its hosted pool; currently these run on Cloudflare Pages. The loader races three public DNS-over-HTTPS (DoH) services and uses the first [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":14337,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[1915,1756,1916,1917,1918,1919,1254,1004,510,1920,1921,1906,1922,40,1923,1189],"class_list":{"0":"post-14335","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-noir-drainer","9":"tag-wallet-drainer","10":"tag-cryptocurrency-theft","11":"tag-crypto-phishing","12":"tag-dns-txt-records","13":"tag-dns-abuse","14":"tag-detecting-dns-command-and-control","15":"tag-dns-c2","16":"tag-dns-over-https","17":"tag-doh-abuse","18":"tag-cloud-hosted-infrastructure","19":"tag-cloudflare-pages","20":"tag-walletconnect","21":"tag-threat-intelligence","22":"tag-ai-developed-malware","23":"tag-phishing-kit","24":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer<\/title>\n<meta name=\"description\" content=\"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer\" \/>\n<meta property=\"og:description\" content=\"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-09T14:00:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-09T14:48:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer\" \/>\n<meta name=\"twitter:description\" content=\"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"When a Wallet Drainer Asks DNS Where to Go\",\"datePublished\":\"2026-10-09T14:00:31+00:00\",\"dateModified\":\"2026-10-09T14:48:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/\"},\"wordCount\":1577,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\",\"keywords\":[\"Noir drainer\",\"wallet drainer\",\"cryptocurrency theft\",\"crypto phishing\",\"DNS TXT records\",\"DNS abuse\",\"Detecting DNS Command and Control\",\"DNS C2\",\"DNS over HTTPS\",\"DoH abuse\",\"cloud-hosted infrastructure\",\"Cloudflare Pages\",\"WalletConnect\",\"Threat Intelligence\",\"AI developed malware\",\"phishing kit\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/\",\"name\":\"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\",\"datePublished\":\"2026-10-09T14:00:31+00:00\",\"dateModified\":\"2026-10-09T14:48:49+00:00\",\"description\":\"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/when-a-wallet-drainer-asks-dns-where-to-go\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"When a Wallet Drainer Asks DNS Where to Go\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer","description":"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/","og_locale":"en_US","og_type":"article","og_title":"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer","og_description":"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/","og_site_name":"Infoblox Blog","article_published_time":"2026-10-09T14:00:31+00:00","article_modified_time":"2026-10-09T14:48:49+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer","twitter_description":"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"When a Wallet Drainer Asks DNS Where to Go","datePublished":"2026-10-09T14:00:31+00:00","dateModified":"2026-10-09T14:48:49+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/"},"wordCount":1577,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","keywords":["Noir drainer","wallet drainer","cryptocurrency theft","crypto phishing","DNS TXT records","DNS abuse","Detecting DNS Command and Control","DNS C2","DNS over HTTPS","DoH abuse","cloud-hosted infrastructure","Cloudflare Pages","WalletConnect","Threat Intelligence","AI developed malware","phishing kit"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/","name":"DNS as C2 in Noir, An AI-Developed Crypto Wallet Drainer","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","datePublished":"2026-10-09T14:00:31+00:00","dateModified":"2026-10-09T14:48:49+00:00","description":"Researchers uncovered a likely AI-developed wallet drainer that uses DNS TXT records and public DoH services as a dynamic C2 infrastructure control plane.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/when-a-wallet-drainer-asks-dns-where-to-go-thumbnail-v2.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/when-a-wallet-drainer-asks-dns-where-to-go\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"When a Wallet Drainer Asks DNS Where to Go"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=14335"}],"version-history":[{"count":8,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14335\/revisions"}],"predecessor-version":[{"id":14348,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14335\/revisions\/14348"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/14337"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=14335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=14335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=14335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}