NatJack Attacks Exploit NAT Tables to Hijack Connections and Spoof DNS
Security researcher Malcolm Stagg has revealed a new class of network attacks called NatJack, presented at Black Hat USA 2026. These attacks work by manipulating how network address translation (NAT) systems track active connections. NAT is a common technology used in routers and firewalls to let multiple devices share a single internet connection, and it's used by nearly every small business network.
By interfering with NAT connection tracking, attackers can hijack active TCP sessions, spoof DNS responses to redirect users to malicious sites, expose internal port mappings that should remain hidden, and exhaust NAT tables to cause outages. The research found that this weakness affects multiple, independently developed NAT implementations, including systems running on Windows, suggesting the issue is widespread rather than limited to a single vendor's product.
Because NAT underpins so much everyday business networking, from office routers to firewalls and VPN gateways, this research is significant even though it's early-stage and mainly aimed at security professionals for now. Businesses should watch for vendor patches and guidance as more details and mitigations become available in the coming weeks.