The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access

The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to (TL-2026-0805), also tracked as The Quarry, is a high-severity phishing campaign, first published 2026-06-15. It is attributed to RockyBelling with medium confidence, affects ConnectWise ScreenConnect (ConnectWise Control), maps to 28 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 38 indicators of compromise.

Key facts for TL-2026-0805

Threat ID
TL-2026-0805
Also known as
The Quarry, Rocky War Room
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-06-15
Last reviewed
2026-06-15
Attribution
RockyBelling
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
SaaS, software development, healthcare, media and entertainment, fintech, finance, e-commerce, retail, real estate, education, travel and logistics, non-profit
Target regions
North America, United States, South America, Europe, Asia, Africa
Detection rules
9
Indicators of compromise
38

Malware and tooling in The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

Malware and tooling: VioletRAT, Adspect, ConnectWise ScreenConnect (ConnectWise Control), Rocky Gmail Sender

The Quarry is an active Phishing-as-a-Service and Malware-as-a-Service operation, run by an actor known as RockyBelling, that has supplied phishing toolkits to roughly 200 affiliate operators since April 2025. Affiliates impersonate the US IRS, Social Security Administration, and brands such as Adobe, Microsoft, DocuSign, and Dropbox to deliver remote access via legitimate ConnectWise ScreenConnect RMM software, using Adspect traffic cloaking and Telegram-based command and exfiltration infrastructure to evade detection.

How The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to works

The Quarry is a turnkey Phishing-as-a-Service (PhaaS) and Malware-as-a-Service (MaaS) operation documented by SOCRadar in June 2026 and active since at least April 2025. The operation is operated by a developer/seller using the alias RockyBelling (also Rock, Rockky, Mike), who markets the kit through a Telegram channel named "Rocky War Room" (~194 subscribers at analysis) and hosts ScreenConnect MSI installers, post-exploitation scripts, and bot tokens in a GitLab account. Arabic-language comments found in kit files suggest a possible regional connection, though origin is unconfirmed.

The Quarry sells tiered services: an entry-level "Rocky Gmail Sender" mass-mailer for ~$500, a self-hosted ScreenConnect panel setup for ~$2,000 with ~$100/month maintenance, and a full campaign setup with guidance for ~$3,000. Approximately 200 affiliate operators have enrolled. Each affiliate is provisioned a self-hosted ScreenConnect instance with a per-affiliate RSA-4096 certificate and a pre-compiled MSI installer for that panel.

The attack chain runs through six phases. Distribution uses the Rocky Gmail Sender with subject-line randomization, HTML templates, and sector/domain email scraping. Phase 1 performs initial filtering: index.php detects User-Agent and redirects non-Windows visitors to errorPage.php while appending random ~300-character URL fragments to defeat session correlation. Phase 2 applies Adspect traffic cloaking with WebGL vendor/renderer analysis, timezone validation, browser-object checks, nested-frame detection, TouchEvent analysis, and Array.prototype.includes fingerprinting; bots are 301-redirected to webmail.windstream.net while real victims proceed. Adspect stream_id reuse clusters campaigns by operator. Phase 3 serves high-fidelity lure pages, most prominently a fake SSA portal (SSA seal, "Estimated Benefits," "Earnings Record," "Security Verification" sections, 5-step interaction flow), with secondary Adobe, Dropbox, DocuSign, and Messenger panels on the same backend.

Phase 4 delivers payloads via a web kit (de.php selects a random variant from /sources/, stages it in a unique 12-character /downloads/ subdirectory, and delivers it through a hidden iframe) across three kit versions (X, Y, Z). Version Z adds a keepalive.php heartbeat (every 5s), a 3-second post-download redirect to webmail.windstream.net, and a safe_cleanup() directory-expiration routine. A VBS dropper introduced April 2026 uses ShellExecute with the runas verb for UAC elevation, downloads an RMM MSI from GitHub/GitLab raw-content URLs alongside a decoy PDF (commonly social-security-statement-upd.pdf), and installs the MSI silently via /quiet ALLUSERS=2 using MSXML2.ServerXMLHTTP.6.0 and ADODB.Stream COM objects, staging in TEMP and self-deleting afterward; obfuscation evolved from Base64 concatenation to hex encoding to an AES-decrypted PS1 second stage.

Phase 5 exfiltrates real-time victim telemetry (IP, User-Agent, filename, UTC timestamp, source file, direct link) to affiliate Telegram bots via HTTPS POST to api.telegram.org, requiring no panel access. Phase 6 post-exploitation tooling includes a PowerShell browser-history stealer (closes Chrome/Edge, exports 6 months of history to CSV via a runtime-downloaded SQLite binary), a W-2 document finder (recursive scan of C:\Users\{username}\ for filenames containing "w2"), the promoted VioletRAT (cookie recovery, credential dumping, background control), and AWS credential harvesting from publicly exposed JavaScript. The operation behaves as a likely Initial Access Broker pipeline, with access potentially resold to ransomware operators. SOCRadar observed 500+ distinct victim IPs across 14 countries, with 94.7% of victims in the United States, spanning SaaS/Dev, Healthcare, Media, and Fintech sectors. Infrastructure spans 80+ phishing domains and 40+ ScreenConnect panels (primary ASN 23470 / ReliableSite, distinctive JARM fingerprints, Let's Encrypt issuance timing).

MITRE ATT&CK techniques used in TL-2026-0805

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution; T1559 Inter-Process Communication

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

discovery

T1217 Browser Information Discovery

command-and-control

T1219 Remote Access Tools

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

  • ConnectWise — ScreenConnect (ConnectWise Control)
    Vulnerable versions: abused as legitimate RMM; no version-specific vulnerability
  • U.S. Internal Revenue Service — IRS brand (impersonated)
    Vulnerable versions: brand abuse / impersonation
  • U.S. Social Security Administration — SSA brand and portal (impersonated)
    Vulnerable versions: brand abuse / impersonation
  • Microsoft — Windows (target OS; UAC abused)
    Vulnerable versions: Windows endpoints

Remediation for The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

Immediate actions

  • Block the known Quarry phishing domains and ScreenConnect panel domains at perimeter and DNS layers
  • Alert on unexpected ConnectWise ScreenConnect (ConnectWise Control) installations and outbound connections from managed endpoints
  • Alert on outbound HTTPS POST to api.telegram.org from corporate/managed endpoints not authorized to use Telegram
  • Hunt for MSI execution with /quiet ALLUSERS=2 launched from %TEMP% directories
  • Hunt for .vbs files invoking ShellExecute with the runas verb and MSXML2.ServerXMLHTTP.6.0 / ADODB.Stream COM objects

Workarounds

  • Restrict execution of .vbs/.js/.hta via Attack Surface Reduction rules and script-host hardening
  • Network-segment endpoints and restrict outbound traffic to known RMM and messaging endpoints

Longer-term hardening

  • Deploy an application-control/allowlisting policy that blocks unauthorized RMM tools (ScreenConnect, AnyDesk, etc.) per CISA AA23-025A
  • Deploy EDR with behavioral detection for living-off-the-land RMM abuse and script-based droppers
  • Implement DNS filtering and newly-registered-domain blocking for government-impersonation lures
  • Mandate phishing-resistant MFA and conduct IRS/SSA tax-season phishing awareness training

Timeline of The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

  • Start of the victim-telemetry collection window: monitored affiliate Telegram bots begin capturing victim information (IP, User-Agent, filename, timestamp) from April 2025 onward.
  • The Quarry PhaaS/MaaS operation observed active at the earliest, per SOCRadar's assessment that it 'has been running since at least April 2025,' supplying phishing toolkits to affiliate operators.
  • New phishing domains registered in April 2026, expanding the operation's infrastructure footprint.
  • UAC bypass demonstration video released in the 'Rocky War Room' Telegram channel as part of product marketing for the new VBS dropper.
  • In April 2026, the actor 'Rock' announced an alternative delivery path in the Telegram channel: a Visual Basic Script dropper with UAC bypass, using ShellExecute runas for elevation and silent MSI install via /quiet ALLUSERS=2.
  • End of the victim-telemetry collection window (April 2025 through April 2026); monitoring of affiliate Telegram bots recorded 500+ distinct victim IPs across 14 countries, with 94.7% of victims in the United States.
  • Continued domain registration through May 2026; in total 80+ phishing domains and 40+ self-hosted ScreenConnect panels identified across the campaign.
  • SOCRadar published 'The Quarry' analysis documenting RockyBelling, ~200 affiliates, IOCs, TTPs, and victimology (500+ victim IPs across 14 countries, 94.7% US).

Sources cited for The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

Threats related to The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to

Detection coverage for TL-2026-0805

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0805 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats