The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access — Threadlinqs Intelligence
As of 2026-06-15, The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM Access is a high-severity phishing threat attributed to RockyBelling, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-0805 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: RockyBelling · FINANCIAL
The Quarry is an active Phishing-as-a-Service and Malware-as-a-Service operation, run by an actor known as RockyBelling, that has supplied phishing toolkits to roughly 200 affiliate operators since
The Quarry is a turnkey Phishing-as-a-Service (PhaaS) and Malware-as-a-Service (MaaS) operation documented by SOCRadar in June 2026 and active since at least April 2025. The operation is operated by a developer/seller using the alias RockyBelling (also Rock, Rockky, Mike), who markets the kit through a Telegram channel named "Rocky War Room" (~194 subscribers at analysis) and hosts ScreenConnect MSI installers, post-exploitation scripts, and bot tokens in a GitLab account. Arabic-language comments found in kit files suggest a possible regional connection, though origin is unconfirmed.
The Quarry sells tiered services: an entry-level "Rocky Gmail Sender" mass-mailer for ~$500, a self-hosted ScreenConnect panel setup for ~$2,000 with ~$100/month maintenance, and a full campaign setup with guidance for ~$3,000. Approximately 200 affiliate operators have enrolled. Each affiliate is provisioned a self-hosted ScreenConnect instance with a per-affiliate RSA-4096 certificate and a pre-compiled MSI installer for that panel.
The attack chain runs through six phases. Distribution uses the Rocky Gmail Sender with subject-line randomization, HTML templates, and sector/domain email scraping. Phase 1 performs initial filtering: index.php detects User-Agent and redirects non-Windows visitors to errorPage.php while appending random ~300-character URL fragments to defeat session correlation. Phase 2 applies Adspect traffic cloaking with WebGL vendor/renderer analysis, timezone validation, browser-object checks, nested-frame detection, TouchEvent analysis, and Array.prototype.includes fingerprinting; bots are 301-redirected to webmail.windstream.net while real victims proceed. Adspect stream_id reuse clusters campaigns by operator. Phase 3 serves high-fidelity lure pages, most prominently a fake SSA portal (SSA seal, "Estimated Benefits," "Earnings Record," "Security Verification" sections, 5-step interaction flow), with secondary Adobe, Dropbox, DocuSign, and Messenger panels on the same backend.
Phase 4 delivers payloads via a web kit (de.php selects a random variant from /sources/, stages it in a unique 12-character /downloads/ subdirectory, and delivers it through a hidden iframe) across three kit versions (X, Y, Z). Version Z adds a keepalive.php heartbeat (every 5s), a 3-second post-download redirect to webmail.windstream.net, and a safe_cleanup() directory-expiration routine. A VBS dropper introduced April 2026 uses ShellExecute with the runas verb for UAC elevation, downloads an RMM MSI from GitHub/GitLab raw-content URLs alongside a decoy PDF (commonly social-security-statement-upd.pdf), and installs the MSI silently via /quiet ALLUSERS=2 using MSXML2.ServerXMLHTTP.6.0 and ADODB.Stream COM objects, staging in TEMP and self-deleting afterward; obfuscation evolved from Base64 concatenation to hex encoding to an AES-decrypted PS1 second stage.
Phase 5 exfiltrates real-time victim telemetry (IP, User-Agent, filename, UTC timestamp, source file, direct link) to affiliate Telegram bots via HTTPS POST to api.telegram.org, requiring no panel access. Phase 6 post-exploitation tooling includes a PowerShell browser-history stealer (closes Chrome/Edge, exports 6 months of history to CSV via a runtime-downloaded SQLite binary), a W-2 document finder (recursive scan of C:\Users\{username}\ for filenames containing "w2"), the promoted VioletRAT (cookie recovery, credential dumping, background control), and AWS credential harvesting from publicly exposed JavaScript. The operation behaves as a likely Initial Access Broker pipeline, with access potentially resold to ransomware operators. SOCRadar observed 500+ distinct victim IPs across 14 countries, with 94.7% of victims in the United States, spanning SaaS/Dev, Healthcare, Media, and Fintech sectors. Infrastructure spans 80+ phishing domains and 40+ ScreenConnect panels (primary ASN 23470 / ReliableSite, distinctive JARM fingerprints, Let's Encrypt issuance timing).
Target sectors: SaaS, software development, healthcare, media and entertainment, fintech, finance, e-commerce, retail, real estate, education, travel and logistics, non-profit
Target regions: North America, United States, South America, Europe, Asia, Africa
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1587, T1588, T1585, T1589, T1566, T1566, T1204, T1204