ShellCodeX Intelligence Brief
HIGH
Cybersecurity
NatJack enables TCP session hijacking and DNS spoofing via NAT state
Source headline: New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Threat level
High
Signal strength
70/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
A disclosed NatJack technique targets network address translation to hijack active TCP sessions. The method also enables spoofed DNS responses and can reveal mapped ports to outsiders. The research describes how manipulating NAT connection state can disrupt legitimate traffic and create opportunities for interception. It further shows that repeated manipulation can exhaust NAT tables, potentially degrading or blocking connectivity. Users running NAT-based network paths should review exposure to NAT manipulation and monitor for abnormal session and DNS behavior.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Open original source