Security researcher Malcolm Stagg has presented a new attack class at Black Hat USA 2026, demonstrating how NatJack can hijack active TCP sessions, spoof DNS responses, and expose mapped ports by manipulating network address translation (NAT) connection state. The attack class exploits vulnerabilities in the way NAT tables are managed, allowing attackers to redirect traffic and hijack sessions. Researchers have found that NatJack can exhaust NAT tables, leaving the network vulnerable to further attacks.
Malcolm Stagg, the security researcher who discovered the NatJack attack, has highlighted the importance of securing NAT tables and improving the security of NAT-based networks. The discovery has sparked concerns about the potential for NatJack to be used in malicious attacks, highlighting the need for improved security measures to protect against such threats.
According to Stagg, NatJack can be launched using a combination of exploit tools and social engineering tactics, making it a highly effective and potentially devastating attack. The attack class has been tested on various NAT-based networks, including those used by major organizations and governments.