By Interestana AI Editorial — AI-drafted, human-overseen. How we report
NatJack Attacks Hijack TCP Sessions by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a novel attack class named NatJack, which exploits vulnerabilities in Network Address Translation (NAT) tables to hijack active TCP sessions, spoof Domain Name System (DNS) responses, expose mapped ports, and exhaust NAT tables. Stagg presented his findings at Black Hat USA 2026, detailing how the attacks leverage the stateful nature of NAT devices to redirect or inject malicious traffic into legitimate network communications. The research indicated that this attack vector affects independently developed implementations, including those found in Windows operating systems, suggesting a widespread potential impact across various network environments. By manipulating the connection state within NAT tables, attackers can effectively impersonate trusted endpoints or intercept sensitive data flowing through the network. This manipulation can lead to session hijacking, where an attacker takes over an established TCP connection, allowing them to send or receive data as if they were one of the original participants. Furthermore, the ability to spoof DNS responses means attackers can direct users to malicious websites or servers, even if they attempt to access legitimate online resources. The exposure of mapped ports is another critical consequence, as it reveals internal network services that might otherwise be hidden from external access, creating new avenues for further exploitation. The exhaustion of NAT tables, a finite resource on most NAT devices, can lead to denial-of-service conditions, disrupting network connectivity for legitimate users. Stagg's research highlights a significant gap in network security that has been overlooked, as NAT devices are typically considered trusted components within a network perimeter. The implications of NatJack attacks are far-reaching, potentially impacting home users, enterprise networks, and cloud infrastructure that rely on NAT for address translation and network segmentation. The disclosure at Black Hat USA 2026, a prominent cybersecurity conference, underscores the severity and technical sophistication of this new attack class. Further investigation and the development of countermeasures are expected to be a priority for network security vendors and administrators worldwide. The research provides concrete evidence of how fundamental networking protocols and devices can be subverted through clever manipulation of their internal states and configurations. The attack's effectiveness across different NAT implementations suggests that a fundamental re-evaluation of NAT security practices may be necessary to mitigate these emerging threats. The ability to compromise active sessions without requiring prior authentication or exploiting application-level vulnerabilities makes NatJack a particularly insidious threat.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.