Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Daybreak Cyber Adds GPT-5.6 for Exploit Validation and Pentesting
August 11, 2026
Gunra Ransomware Exploits Fortinet VPN Flaws, Bypasses MFA
August 10, 2026
Anthropic Claude: New Security Feature Automates Agent Access Approvals
August 10, 2026
Home/Threats/The Quarry Phishing: Attackers Abuse RMM Tools in IRS, SSA Scams
Threats

The Quarry Phishing: Attackers Abuse RMM Tools in IRS, SSA Scams

Key Takeaways A sophisticated phishing-as-a-service (PhaaS) operation, dubbed “The Quarry,” is actively targeting U.S. taxpayers. The campaign leverages legitimate Remote Monitoring and...

Emy Elsamnoudy
Emy Elsamnoudy
June 16, 2026 5 Min Read
47 0

Key Takeaways

  • A sophisticated phishing-as-a-service (PhaaS) operation, dubbed “The Quarry,” is actively targeting U.S. taxpayers.
  • The campaign leverages legitimate Remote Monitoring and Management (RMM) tools, specifically ConnectWise ScreenConnect, as its final payload to bypass traditional security defenses.
  • Attackers impersonate the IRS and Social Security Administration (SSA) to trick victims into installing remote access software, leading to data theft, including W-2 tax documents and browser history.
  • The operation has been active since at least April 2025, affecting over 500 unique IP addresses across 14 countries, with a significant majority in the United States.

A highly organized cybercrime initiative, identified as “The Quarry,” is executing extensive phishing campaigns against American taxpayers. This operation masterfully exploits legitimate Remote Monitoring and Management (RMM) software, impersonating the Internal Revenue Service (IRS) and the Social Security Administration (SSA) to ensnare unsuspecting individuals. New findings illuminate the intricate tactics employed by this Phishing-as-a-Service (PhaaS) provider, which offers a comprehensive toolkit to nearly 200 paying affiliates.

Table Of Content

  • Key Takeaways
  • The Mastermind Behind “The Quarry”
  • Hackers Abuse Legitimate RMM Tools
  • Post-Exploitation Tools and Victim Impact
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The Quarry has maintained continuous activity since at least April 2025. While tax season represents a prime opportunity, the operation adapts its deceptive lures throughout the year to maximize effectiveness, as detailed in a recent report by SOCRadar analysts.

The PhaaS toolkit provides everything necessary to launch a full-scale phishing attack, eliminating the need for operators to develop their own tools. This includes pre-built phishing pages, advanced traffic cloaking infrastructure, remote access panels, bulk email dispatching capabilities, and various post-exploitation scripts.

The Mastermind Behind “The Quarry”

The individual orchestrating this sophisticated PhaaS platform operates under several aliases, including RockyBelling, Rock, Rockky, and Mike. This threat actor manages a Telegram channel named “Rocky War Room,” which, at the time of analysis, boasted 194 subscribers. This channel serves as a central hub for product showcasing, customer support, and announcements regarding new tool releases.

A critical aspect that amplifies The Quarry’s danger is its innovative use of legitimate RMM software as the ultimate payload. Rather than deploying easily identifiable malware, the operators facilitate a silent installation of ConnectWise ScreenConnect, a widely trusted remote access application. This strategy allows attackers to gain complete control over a victim’s device while effectively evading detection by security tools typically designed to flag malicious software.

The operation’s success also suggests a growing risk of downstream implications. Stolen credentials and access are potentially being sold to other cybercriminal groups, including ransomware syndicates, through initial access broker activities.

Investigations have revealed over 500 distinct victim IP addresses spanning 14 countries, with over 90 percent of these victims located within the United States.

The Quarry PhaaS operation attack chain (Source - SOCRadar)
The Quarry PhaaS operation attack chain (Source – SOCRadar)

Hackers Abuse Legitimate RMM Tools

The attack sequence typically commences with a mass email campaign meticulously crafted to appear as an official IRS refund notification, an SSA tax filing confirmation, or a document shared via a reputable platform like DocuSign. Upon clicking a link within this email, the victim is redirected to a sophisticated landing page. This page first filters out non-Windows operating systems and automated security scanners. A subsequent layer employs Adspect, a specialized traffic cloaking service, to prevent cybersecurity researchers from accessing the fraudulent content, ensuring only genuine targets proceed to the phishing page.

The phishing page itself is a highly convincing replica of the Social Security Administration portal, complete with the authentic SSA seal and familiar layout elements.

Adspect cloaking decision flow showing real victims versus bots (Source - SOCRadar)
Adspect cloaking decision flow showing real victims versus bots (Source – SOCRadar)

Victims are prompted to download a “Security Connector” to access their supposed statement. In reality, a legitimate ConnectWise ScreenConnect MSI installer is silently downloaded through a hidden iframe on the webpage. In April 2026, the developer introduced a new delivery method: a VBScript dropper sent via email. This script silently installs ScreenConnect while simultaneously opening a decoy PDF document to divert the victim’s attention.

Post-Exploitation Tools and Victim Impact

Once ConnectWise ScreenConnect is successfully installed, operators deploy PowerShell scripts to extract sensitive data. One such script is designed to retrieve six months of browser history, forcibly closing the browser to unlock its database before transmitting the collected data to the operator via Telegram. Another script systematically scans the victim’s file system for W-2 tax documents, specifically targeting Social Security numbers, employer details, and salary information.

The developer’s Telegram channel also advertises “VioletRAT,” a tool equipped with capabilities for credential dumping and cookie theft. Furthermore, campaign logs have revealed AWS access keys, which were harvested from publicly accessible JavaScript files belonging to targeted organizations. These advanced post-exploitation capabilities underscore that The Quarry operation is actively pursuing high-value financial and corporate data, extending beyond mere credential harvesting.

What You Should Do

  • Implement Application Whitelisting: Maintain an approved list of remote access tools and immediately investigate any unauthorized or unexpected installations of software like ScreenConnect.
  • Monitor Network Traffic: Scrutinize Telegram API traffic originating from endpoints that do not typically use the platform, as this could indicate active data exfiltration.
  • Educate Employees on Phishing: Reinforce that government agencies like the IRS and SSA will never send executable files or installers via email. Train staff to recognize and report suspicious emails, especially those requesting software downloads.
  • Restrict VBScript Execution: Implement policies to restrict or disable VBScript execution from user-writable directories to disrupt the VBS dropper delivery chain.
  • Regular Data Backups: Ensure critical data is regularly backed up and stored securely offline to mitigate the impact of potential data theft or ransomware.
  • Multi-Factor Authentication (MFA): Enable MFA on all accounts, especially for financial services and email, to add an extra layer of security against stolen credentials.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain estatetaxarchives[.]com Operator-registered phishing domain, fiscal-portal naming pattern
Domain hub[.]ssa-guidance[.]com Operator-registered phishing domain impersonating SSA
Domain inherittaxpapers[.]site Operator-registered phishing domain, fiscal-portal naming pattern
Domain verify[.]federal-docviewer[.]com Operator-registered phishing domain impersonating federal document service
Domain portal[.]federalverify-ssaclientportal[.]com Operator-registered phishing domain impersonating SSA
Domain trusttaxportal[.]com Operator-registered phishing domain, fiscal-portal naming pattern
Domain estatetaxrecords[.]com Operator-registered phishing domain, fiscal-portal naming pattern
Domain tax-filecenter-irs[.]matthewtarwater[.]com Compromised domain hosting The Quarry phishing kit
Domain apps[.]docu-sign[.]net Operator-registered phishing domain impersonating DocuSign
Domain secure[.]login-socialsecurity[.]com Operator-registered phishing domain impersonating SSA login
Domain hub[.]ssa-userstatus[.]com Operator-registered phishing domain impersonating SSA
Domain secure[.]ssa-documentsync[.]com Operator-registered phishing domain impersonating SSA
MD5 Hash 8974830446d35e234881696092aded87 Malicious payload sample identified during research
MD5 Hash ef970697c5094c443f0456774cfee9bc Malicious payload sample identified during research
MD5 Hash 935413b08ef60cd819b2e1b573fc9050 Malicious payload sample identified during research
MD5 Hash 2163afa18a3cdfa525b767e0e1baaba1 Malicious payload sample identified during research
MD5 Hash 1827aa636cd86d1a4064e112aa197303 Malicious payload sample identified during research
MD5 Hash 00b69eb7f44b5987f68667343aaafb6a Malicious payload sample identified during research
MD5 Hash 01ab231bcd9533f90e99651521b6e1bb Malicious payload sample identified during research

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

LockBit Alumni, Qilin, Hyflock, and The Gentlemen Consolidate Ransomware Landscape

Next Post

Critical OptinMonster Vulnerability Exposes 1.2M WordPress Sites

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Windows WalletService Bug (CVE-2024-XXXX) Lets Attackers Escalate Privileges
August 10, 2026
CISA Warns of Progress LoadMaster Command Injection Vulnerability Exploited in Attacks
August 10, 2026
Critical Red Hat ACM Vulnerability Lets Attackers Gain Cluster-Admin Access
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us