New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
A new attack class called NatJack exploits network address translation connection state to hijack TCP sessions, spoof DNS, and exhaust NAT tables, affecting implementations including Windows, as disclosed at Black Hat USA 2026.
Security researcher Malcolm Stagg disclosed a new attack class called NatJack at Black Hat USA 2026. It manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The research found affected behavior across independently developed implementations, including Windows.