YouieLoad is a custom malware loader tracked by Microsoft and associated with the North Korean state-aligned threat actor Moonstone Sleet (formerly Storm-1789). It was observed in campaigns beginning in February 2024 that used a malicious tank game, DeTankWar, also referred to as DeFiTankWar, DeTankZone, and TankWarsZone, as the infection vector. In this activity, targets were approached via email or messaging platforms by actor-controlled fake companies, including C.C. Waterfall, and directed to download the game. The game executable, delfi-tank-unity.exe, loads additional malicious DLLs and delivers YouieLoad.
Microsoft reported that YouieLoad is capable of loading next-stage payloads directly in memory and creating malicious services. Its observed functionality includes network discovery, user discovery, and browser data collection. The malware was used as part of broader Moonstone Sleet intrusion activity involving social engineering, credential theft, and hands-on-keyboard operations on high-interest compromised devices.
High-confidence associations in the reporting tie YouieLoad to Moonstone Sleet operations targeting software/IT, education, and the defense industrial base, including aerospace-related organizations. Known related lure and campaign artifacts mentioned in the reporting include the malicious game DeTankWar and the executable name delfi-tank-unity.exe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The payload is a custom malware loader that Microsoft tracks as YouieLoad. Similarly to SplitLoader, YouieLoad loads malicious payloads in memory and creates malicious services ... network and user discovery and browser data collection.
"The purported game (\"delfi-tank-unity.exe\") comes fitted with a malware loader referred to as YouieLoad, which is capable of loading next-stage payloads in memory and creating malicious services for network and user discovery and browser data collection."
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"targeting potential victims with projects that used malicious npm packages"; "skills assessment"; "malicious package used curl to connect to an actor-controlled IP and drop additional malicious payloads"
"Moonstone Sleet is observed to set up fake companies and job opportunities to engage with potential targets"; "delivering a trojanized version of PuTTY ... via apps like LinkedIn and Telegram as well as developer freelancing platforms"; "sending candidates a 'skills test' that instead delivers malware"
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
In-memory loader embedded in a malicious game; loads next-stage payloads and can create malicious services for discovery and browser data collection.
Custom in-memory loader delivered via the DeTankWar game; creates malicious services and supports discovery (network/user) and browser data collection, enabling follow-on hands-on-keyboard activity and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.