Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Summary
A new attack class named NatJack has been disclosed by security researcher Malcolm Stagg. This attack exploits network address translation (NAT) connection states to hijack active TCP sessions, spoof DNS responses, reveal victim IP addresses and mapped ports, and overload NAT tables.
IFF Assessment
The NatJack attack class allows for the hijacking of TCP sessions, spoofing of DNS responses, and disclosure of victim IP addresses, all of which are detrimental to network security.
Defender Context
Defenders need to be aware of the NatJack attack class, which leverages manipulation of NAT to disrupt network communications. This highlights the importance of monitoring network traffic for anomalies, particularly unusual DNS activity and session hijacking attempts, and ensuring network devices are properly configured to mitigate such exploits.