From Fake Amazon Security Alert to HarborWatch Agent: ClickFix Delivery of a Custom Monitoring RAT

June 10, 2026, 11 a.m.

Description

A sophisticated phishing campaign exploits Amazon's brand reputation through spoofed security alerts to deliver HarborWatch Agent, a custom remote access trojan. The attack chain begins with emails impersonating Amazon security notifications about suspicious account activity, directing victims to lookalike domains. Users are presented with fake CAPTCHA verification pages that employ ClickFix social engineering techniques, instructing them to execute PowerShell commands on their own systems. The multi-stage infection downloads mysql.exe from compromised infrastructure, which communicates with a Chinese-language command and control panel branded Harbor Sentinel. The RAT collects extensive system information including OS details, architecture, CPU count, disk usage, memory status, and network configurations, exfiltrating data through API endpoints to the threat actor's monitoring infrastructure.

Date

  • Created: June 9, 2026, 3:50 p.m.
  • Published: June 9, 2026, 3:50 p.m.
  • Modified: June 10, 2026, 11 a.m.

Indicators

  • 3a87cab1e8c6868a7939eb422f1851ecc746405cda6b3d3502b9d8eedc360898
  • 5f7bb80bf85c1fae7413eb534cc2f022402c8753f75666525adb1dc85a677f4c
  • cf94ff2ecc4f3157704c9cfed5e446c405e7729141019045cb05ef6ffad122d5
  • 185.193.127.44
  • https://amazonattention.com/verify
  • https://amazonalert.xyz/download/code.txt

Additional Informations

  • security.amazonassist.xyz
  • amazonattention.com
  • amazonalert.xyz