SplitLoader is an intermediate loader/installer malware used by the North Korea-aligned threat actor Moonstone Sleet (formerly Storm-1789). Microsoft reported it in multi-stage intrusion chains delivered through social engineering, including a trojanized PuTTY executable distributed via LinkedIn, Telegram, and developer freelancing platforms, as well as malicious npm packages sent as fake technical skills assessments. In the PuTTY chain, the trojanized executable decrypts and executes an embedded payload, after which a SplitLoader installer/dropper writes a SplitLoader DLL to disk and executes it via a scheduled task or Windows Registry Run key. SplitLoader then initiates intermediate stages that ultimately launch a trojan loader which retrieves or executes an encrypted PE payload from command-and-control infrastructure. Microsoft also reported malicious npm packages using curl to connect to actor-controlled infrastructure and drop additional payloads such as SplitLoader. The malware is associated with campaigns targeting software/IT, education, and the defense industrial base, including aerospace-related organizations. The content also states Moonstone Sleet used loader malware such as SplitLoader and YouieLoader to create malicious services for execution. High-confidence behavioral details directly mentioned include DLL drop-and-execute behavior, use of scheduled tasks or Registry Run keys for execution, staged payload delivery, retrieval of encrypted payloads from C2, and service creation in Moonstone Sleet operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services.
Stage 2 – SplitLoader installer/dropper ... Stage 3 – SplitLoader ... In one example ... malicious npm package ... drop additional malicious payloads like SplitLoader.
"The trojanized PuTTY executable is designed to drop a custom installer dubbed SplitLoader that initiates a sequence of intermediate stages in order to ultimately launch a Trojan loader..."
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"targeting potential victims with projects that used malicious npm packages"; "skills assessment"; "malicious package used curl to connect to an actor-controlled IP and drop additional malicious payloads"
"Moonstone Sleet is observed to set up fake companies and job opportunities to engage with potential targets"; "delivering a trojanized version of PuTTY ... via apps like LinkedIn and Telegram as well as developer freelancing platforms"; "sending candidates a 'skills test' that instead delivers malware"
"...establish contact with a command-and-control (C2) server to retrieve additional payloads." and "...execute a portable executable received from a C2 server."
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom installer/loader dropped by a trojanized PuTTY that runs intermediate stages to ultimately launch a loader which executes a PE retrieved from C2.
Multi-stage loader chain component: an installer/dropper writes a SplitLoader DLL, persists via scheduled task or Run key, decrypts/decompresses staged content, and reconstructs/executes next-stage PE payloads.
Intermediate loader malware that creates malicious Windows services for execution/persistence.
Intermediate loader malware used by Moonstone Sleet; described as creating malicious services for execution/persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.