The rapid advancement of cyber defence products has necessitated sophisticated memory evasion techniques employed by the Red Team and Malware Development communities. Thread stack spoofing, an integral part of these approaches, conceals malicious calls within the stack by replacing selected stack frames with counterfeit ones. In this talk, we will explore the evolution of thread stack spoofing, highlighting significant breakthroughs and limitations of previously implemented techniques. Furthermore, we will present Stack Moonwalking, a set of novel techniques that we have developed to implement a fully dynamic stack spoofer. Specifically, we will introduce a unique approach that we named “”Full Moon””, which leverages advanced mechanisms to desynchronize the control flow from the unwinding information, thereby maintaining a fully unwindable stack during the spoofing process. After that, we will introduce Eclipse, a detection algorithm that extends the Windows unwinding algorithm to identify spoofed stack frames. We will delve into the technical details of Eclipse, focusing on its role in detecting spoofed stack frames. By extending the existing Windows unwinding algorithm, Eclipse analyses the characteristics and patterns of stack frames to differentiate genuine frames from spoofed ones. Towards the end of the talk, we will also evaluate the performance and shortcomings of this detection algorithm and see how it is possible for an attacker to abuse some gaps to remain unnoticed.