216.73.216.6

From Fake Amazon Security Alert to HarborWatch Agent: ClickFix Delivery of a Custom Monitoring RAT

· Published 09/06/2026 15:50 · Modified 10/06/2026 11:00

Export JSON

Essential information

Published
09/06/2026 15:50
Modified
10/06/2026 11:00
Tags
2026-06-09 clickfix fake captcha harbor sentinel phishing campaign
Related entities
6 observables, 20 techniques (mitre), 1 malware, 3 others

Description

A sophisticated exploits Amazon's brand reputation through spoofed security alerts to deliver HarborWatch Agent, a custom remote access trojan. The attack chain begins with emails impersonating Amazon security notifications about suspicious account activity, directing victims to lookalike domains. Users are presented with verification pages that employ social engineering techniques, instructing them to execute PowerShell commands on their own systems. The multi-stage infection downloads mysql.exe from compromised infrastructure, which communicates with a Chinese-language command and control panel branded . The RAT collects extensive system information including OS details, architecture, CPU count, disk usage, memory status, and network configurations, exfiltrating data through API endpoints to the threat actor's monitoring infrastructure.

External references