ThreatCluster

Moonwalk++ PoC Enables Malware to Evade Windows Call Stack Detection

First seen 17 Dec 2025, 12:59 UTC GbhackersCybersecuritynews 31

Article Content

Browse articles
ThreatCluster

A new proof-of-concept, Moonwalk++, demonstrates how malware can spoof Windows call stacks to evade detection by security solutions like Elastic. This technique builds on previous stack-spoofing research and highlights vulnerabilities in current endpoint detection strategies used by enterprises.