The Quarry Phishing: Attackers Abuse RMM Tools in IRS, SSA Scams
Key Takeaways A sophisticated phishing-as-a-service (PhaaS) operation, dubbed “The Quarry,” is actively targeting U.S. taxpayers. The campaign leverages legitimate Remote Monitoring and...
Key Takeaways
- A sophisticated phishing-as-a-service (PhaaS) operation, dubbed “The Quarry,” is actively targeting U.S. taxpayers.
- The campaign leverages legitimate Remote Monitoring and Management (RMM) tools, specifically ConnectWise ScreenConnect, as its final payload to bypass traditional security defenses.
- Attackers impersonate the IRS and Social Security Administration (SSA) to trick victims into installing remote access software, leading to data theft, including W-2 tax documents and browser history.
- The operation has been active since at least April 2025, affecting over 500 unique IP addresses across 14 countries, with a significant majority in the United States.
A highly organized cybercrime initiative, identified as “The Quarry,” is executing extensive phishing campaigns against American taxpayers. This operation masterfully exploits legitimate Remote Monitoring and Management (RMM) software, impersonating the Internal Revenue Service (IRS) and the Social Security Administration (SSA) to ensnare unsuspecting individuals. New findings illuminate the intricate tactics employed by this Phishing-as-a-Service (PhaaS) provider, which offers a comprehensive toolkit to nearly 200 paying affiliates.
Table Of Content
The Quarry has maintained continuous activity since at least April 2025. While tax season represents a prime opportunity, the operation adapts its deceptive lures throughout the year to maximize effectiveness, as detailed in a recent report by SOCRadar analysts.
The PhaaS toolkit provides everything necessary to launch a full-scale phishing attack, eliminating the need for operators to develop their own tools. This includes pre-built phishing pages, advanced traffic cloaking infrastructure, remote access panels, bulk email dispatching capabilities, and various post-exploitation scripts.
The Mastermind Behind “The Quarry”
The individual orchestrating this sophisticated PhaaS platform operates under several aliases, including RockyBelling, Rock, Rockky, and Mike. This threat actor manages a Telegram channel named “Rocky War Room,” which, at the time of analysis, boasted 194 subscribers. This channel serves as a central hub for product showcasing, customer support, and announcements regarding new tool releases.
A critical aspect that amplifies The Quarry’s danger is its innovative use of legitimate RMM software as the ultimate payload. Rather than deploying easily identifiable malware, the operators facilitate a silent installation of ConnectWise ScreenConnect, a widely trusted remote access application. This strategy allows attackers to gain complete control over a victim’s device while effectively evading detection by security tools typically designed to flag malicious software.
The operation’s success also suggests a growing risk of downstream implications. Stolen credentials and access are potentially being sold to other cybercriminal groups, including ransomware syndicates, through initial access broker activities.
Investigations have revealed over 500 distinct victim IP addresses spanning 14 countries, with over 90 percent of these victims located within the United States.

Hackers Abuse Legitimate RMM Tools
The attack sequence typically commences with a mass email campaign meticulously crafted to appear as an official IRS refund notification, an SSA tax filing confirmation, or a document shared via a reputable platform like DocuSign. Upon clicking a link within this email, the victim is redirected to a sophisticated landing page. This page first filters out non-Windows operating systems and automated security scanners. A subsequent layer employs Adspect, a specialized traffic cloaking service, to prevent cybersecurity researchers from accessing the fraudulent content, ensuring only genuine targets proceed to the phishing page.
The phishing page itself is a highly convincing replica of the Social Security Administration portal, complete with the authentic SSA seal and familiar layout elements.

Victims are prompted to download a “Security Connector” to access their supposed statement. In reality, a legitimate ConnectWise ScreenConnect MSI installer is silently downloaded through a hidden iframe on the webpage. In April 2026, the developer introduced a new delivery method: a VBScript dropper sent via email. This script silently installs ScreenConnect while simultaneously opening a decoy PDF document to divert the victim’s attention.
Post-Exploitation Tools and Victim Impact
Once ConnectWise ScreenConnect is successfully installed, operators deploy PowerShell scripts to extract sensitive data. One such script is designed to retrieve six months of browser history, forcibly closing the browser to unlock its database before transmitting the collected data to the operator via Telegram. Another script systematically scans the victim’s file system for W-2 tax documents, specifically targeting Social Security numbers, employer details, and salary information.
The developer’s Telegram channel also advertises “VioletRAT,” a tool equipped with capabilities for credential dumping and cookie theft. Furthermore, campaign logs have revealed AWS access keys, which were harvested from publicly accessible JavaScript files belonging to targeted organizations. These advanced post-exploitation capabilities underscore that The Quarry operation is actively pursuing high-value financial and corporate data, extending beyond mere credential harvesting.
What You Should Do
- Implement Application Whitelisting: Maintain an approved list of remote access tools and immediately investigate any unauthorized or unexpected installations of software like ScreenConnect.
- Monitor Network Traffic: Scrutinize Telegram API traffic originating from endpoints that do not typically use the platform, as this could indicate active data exfiltration.
- Educate Employees on Phishing: Reinforce that government agencies like the IRS and SSA will never send executable files or installers via email. Train staff to recognize and report suspicious emails, especially those requesting software downloads.
- Restrict VBScript Execution: Implement policies to restrict or disable VBScript execution from user-writable directories to disrupt the VBS dropper delivery chain.
- Regular Data Backups: Ensure critical data is regularly backed up and stored securely offline to mitigate the impact of potential data theft or ransomware.
- Multi-Factor Authentication (MFA): Enable MFA on all accounts, especially for financial services and email, to add an extra layer of security against stolen credentials.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | estatetaxarchives[.]com | Operator-registered phishing domain, fiscal-portal naming pattern |
| Domain | hub[.]ssa-guidance[.]com | Operator-registered phishing domain impersonating SSA |
| Domain | inherittaxpapers[.]site | Operator-registered phishing domain, fiscal-portal naming pattern |
| Domain | verify[.]federal-docviewer[.]com | Operator-registered phishing domain impersonating federal document service |
| Domain | portal[.]federalverify-ssaclientportal[.]com | Operator-registered phishing domain impersonating SSA |
| Domain | trusttaxportal[.]com | Operator-registered phishing domain, fiscal-portal naming pattern |
| Domain | estatetaxrecords[.]com | Operator-registered phishing domain, fiscal-portal naming pattern |
| Domain | tax-filecenter-irs[.]matthewtarwater[.]com | Compromised domain hosting The Quarry phishing kit |
| Domain | apps[.]docu-sign[.]net | Operator-registered phishing domain impersonating DocuSign |
| Domain | secure[.]login-socialsecurity[.]com | Operator-registered phishing domain impersonating SSA login |
| Domain | hub[.]ssa-userstatus[.]com | Operator-registered phishing domain impersonating SSA |
| Domain | secure[.]ssa-documentsync[.]com | Operator-registered phishing domain impersonating SSA |
| MD5 Hash | 8974830446d35e234881696092aded87 | Malicious payload sample identified during research |
| MD5 Hash | ef970697c5094c443f0456774cfee9bc | Malicious payload sample identified during research |
| MD5 Hash | 935413b08ef60cd819b2e1b573fc9050 | Malicious payload sample identified during research |
| MD5 Hash | 2163afa18a3cdfa525b767e0e1baaba1 | Malicious payload sample identified during research |
| MD5 Hash | 1827aa636cd86d1a4064e112aa197303 | Malicious payload sample identified during research |
| MD5 Hash | 00b69eb7f44b5987f68667343aaafb6a | Malicious payload sample identified during research |
| MD5 Hash | 01ab231bcd9533f90e99651521b6e1bb | Malicious payload sample identified during research |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.