ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

NatJack enables TCP session hijacking and DNS spoofing via NAT state

Source headline: New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Threat level High
Signal strength 70/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A disclosed NatJack technique targets network address translation to hijack active TCP sessions. The method also enables spoofed DNS responses and can reveal mapped ports to outsiders. The research describes how manipulating NAT connection state can disrupt legitimate traffic and create opportunities for interception. It further shows that repeated manipulation can exhaust NAT tables, potentially degrading or blocking connectivity. Users running NAT-based network paths should review exposure to NAT manipulation and monitor for abnormal session and DNS behavior.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#network-security #dns-spoofing #nat #session-injection #tcp #tcp-session-hijacking
Original reporting The Hacker News New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Open original source