Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Moonwalk++ PoC Demonstrates How Malware Can Forge Windows Call Stacks to Evade Detection

## Cybersecurity: Moonwalk++ Malware Evasion Technique

Cybersecurity: Moonwalk++ Malware Evasion Technique

Security researchers have identified a new malware evasion technique named Moonwalk++. This method allows malware to disguise itself by manipulating Windows call stacks, thereby bypassing modern endpoint detection systems.

Moonwalk++ builds on previous research into Stack Moonwalking, exposing vulnerabilities in how security tools verify malware calls to sensitive Windows functions. By altering the function call chains in system memory, the technique makes malicious code appear as though it originates from legitimate software.

The technique forges call stack data, misleading security tools by pointing to legitimate Windows system functions. This method exploits the way Windows records function calls, masking the actual origin of the malware.

Moonwalk++ can encrypt malicious code during execution, a capability not present in earlier versions. This is achieved through stack manipulation, allowing the malware to evade detection while running.

Security researchers have identified a new malware evasion technique named Moonwalk++.
Rebecca Stone · Thehackingpost

Researchers tested Moonwalk++ against several detection tools, including Hunt-Sleeping-Beacons and Hollow's Hunter. These tools failed to detect the technique when integrated into legitimate processes such as OneDrive.exe.

Removing references to malicious code from the call stack Making threads appear to originate from legitimate functions Concealing suspicious memory regions

The research, initially presented at DEFCON 31, underscores the limitations of relying solely on call stack analysis. It advocates for enhanced detection strategies that include behavioral analysis, memory pattern monitoring, and API usage review.

Advertisement

Security teams can access the full technical details and proof-of-concept code to further study and mitigate such advanced evasion techniques.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories