Rock, tracked by SOCRadar as The Quarry, is a one-person MaaS/PhaaS operation that sells a full phishing and remote access toolkit to affiliates running tax-themed campaigns against U.S. victims. The ecosystem uses legitimate RMM software, Adspect cloaking, and Telegram-based reporting to support campaigns impersonating the IRS, SSA, Adobe, Dropbox, DocuSign, and Messenger. #TheQuarry #Rock #ScreenConnect #Adspect #Telegram #IRS #SSA #Adobe #Dropbox #DocuSign #Messenger
Keypoints
- Rock is the developer behind The Quarry, a MaaS/PhaaS ecosystem active since at least April 2025.
- The operation is centered on tax-themed lures impersonating U.S. agencies and brands, with over 90% of recorded victims in the U.S.
- Rock sells tools, infrastructure, and support to affiliates, with observed pricing for scrapers, mass-mailers, and self-hosted ScreenConnect setups.
- ScreenConnect is the primary remote access payload, while Tiflux, Datto, and FleetDeck also appear in some campaigns.
- The phishing kit includes cloaking with Adspect, modular PHP infrastructure, VBS droppers, and Telegram-based victim logging and C2.
- Post-exploitation activity can include browser history theft, W-2 document searching, credential harvesting, and selling access onward.
- SOCRadar notes the ecosystem remains active, with new domains and Telegram activity continuing into April and May 2026.
MITRE Techniques
- [T1596.005 ] Scan Databases â Automated scrapers collect corporate domains by sector and locate hardcoded credentials in accessible resources such as JavaScript files (âAutomated scrapers collect corporate domains by sector and locate hardcoded credentials in accessible resources such as JavaScript filesâ).
- [T1583.001 ] Domains â Registers custom domains using tax-related naming conventions as the primary phishing infrastructure (âRegisters custom domains using tax-related naming conventions as the primary phishing infrastructureâ).
- [T1583.006 ] Web Services â Leverages public GitHub and GitLab repositories to host MSI payloads and decoy PDFs, abusing platform reputation (âLeverages public GitHub and GitLab repositories to host MSI payloads and decoy PDFs, abusing platform reputationâ).
- [T1587.001 ] Malware â Develops a modular PHP phishing kit with cloaking, VBS droppers with UAC bypass, PS1 post-exploitation scripts, and bulk email tooling (âDevelops a modular PHP phishing kit with cloaking, VBS droppers with UAC bypass, PS1 post-exploitation scripts, and bulk email toolingâ).
- [T1583.004 ] Server â Deploys self-hosted ScreenConnect instances provisioned per affiliate as remote access infrastructure (âDeploys self-hosted ScreenConnect instances provisioned per affiliate as remote access infrastructureâ).
- [T1566.001 ] Spearphishing Attachment â Distributes the VBS dropper directly as an email attachment using tax-themed lures (âDistributes the VBS dropper directly as an email attachment using tax-themed luresâ).
- [T1566.002 ] Spearphishing Link â Distributes links to malicious domains via bulk email, redirecting victims to fake SSA, IRS, Adobe, Dropbox, or DocuSign portals (âDistributes links to malicious domains via bulk email, redirecting victims to fake SSA, IRS, Adobe, Dropbox, or DocuSign portalsâ).
- [T1204 ] User Execution â Victims execute the RMM installer, prompted by the tax-themed context and the âSecurity Connectorâ popup (âVictims execute the RMM installer, prompted by the tax-themed context and the âSecurity Connectorâ popupâ).
- [T1059.005 ] Visual Basic â Uses VBS scripts as an alternative delivery vector with three obfuscation variants (âUses VBS scripts as an alternative delivery vector with three obfuscation variantsâ).
- [T1059.001 ] PowerShell â The most advanced VBS variant runs a PowerShell script implementing AES decryption before launching the payload (âThe most advanced VBS variant runs a PowerShell script implementing AES decryption before launching the payloadâ).
- [T1548.002 ] Bypass User Account Control â The VBS dropper triggers UAC; the April 2026 variant implemented a bypass with no visible dialog (âThe VBS dropper triggers UAC; the April 2026 variant implemented a bypass with no visible dialogâ).
- [T1036.005 ] Match Legitimate Name or Location â RMM installers use filenames simulating tax documents such as ScreenConnect.ClientSetup.exe and StatementID-5ecc7a9.exe (âRMM installers use filenames simulating tax documents (ScreenConnect.ClientSetup.exe, StatementID-5ecc7a9.exe)â).
- [T1027 ] Obfuscated Files or Information â VBS variants use Base64 concatenation, hexadecimal encoding, and AES decryption in a secondary PowerShell stage (âVBS variants use Base64 concatenation, hexadecimal encoding, and AES decryption in a secondary PowerShell stageâ).
- [T1070.004 ] File Deletion â The VBS dropper deletes the MSI installer after installation, removing the primary forensic artifact (âThe VBS dropper deletes the MSI installer after installation, removing the primary forensic artifactâ).
- [T1656 ] Impersonation â Impersonates SSA, IRS, Adobe, Dropbox, DocuSign, and ConnectWise with customized CSS, official logos, and security messaging (âImpersonates SSA, IRS, Adobe, Dropbox, DocuSign, and ConnectWise with customized CSS, official logos, and security messagingâ).
- [T1539 ] Steal Web Session Cookie â A credential harvesting panel likely derived from Evilginx targets credentials and session cookies (âA credential harvesting panel likely derived from Evilginx targets credentials and session cookiesâ).
- [T1552.001 ] Credentials in Files â Scrapers identify hardcoded credentials in public resources, including JavaScript files with cloud access keys (âScrapers identify hardcoded credentials in public resources, including JavaScript files with cloud access keysâ).
- [T1083 ] File and Directory Discovery â The W-2 Document Finder recursively searches the user profile for files containing âw2â (âThe W-2 Document Finder recursively searches the user profile for files containing âw2âłâ).
- [T1185 ] Browser Session Hijacking â The Browser History Stealer force-closes the browser to read locked SQLite databases and export six months of history (âThe Browser History Stealer force-closes the browser to read locked SQLite databases and export six months of historyâ).
- [T1071.001 ] Web Protocols â All exfiltration runs through HTTPS POST requests to the public Telegram API (âAll exfiltration runs through HTTPS POST requests to the public Telegram APIâ).
- [T1568.002 ] Domain Generation Algorithms â The kit generates random 300-character URL fragments during PHP redirects to complicate tracking (âThe kit generates random 300-character URL fragments during PHP redirects to complicate trackingâ).
- [T1219 ] Remote Access Software â The installed RMM connects to the affiliateâs self-hosted ScreenConnect panel over RSA-4096, disguised as legitimate remote support (âThe installed RMM connects to the affiliateâs self-hosted ScreenConnect panel over RSA-4096, disguised as legitimate remote supportâ).
- [T1657 ] Financial Theft â Targeting the U.S. tax season alongside W-2 and credential theft points to tax fraud and access to victim financial infrastructure (âTargeting the U.S. tax season alongside W-2 and credential theft points to tax fraud and access to victim financial infrastructureâ).
Indicators of Compromise
- [Domains] phishing and delivery infrastructure â dozens of domains, newly created domains in April and May 2026
- [File names] RMM and lure-related filenames â ScreenConnect.ClientSetup.exe, StatementID-5ecc7a9.exe
- [File paths / directories] payload staging locations â /sources/, /downloads/, index.php, de.php
- [URLs / services] exfiltration and communication â public Telegram API, GitHub, GitLab
- [Software / agent names] installed remote access tools â ScreenConnect, Tiflux, Datto, FleetDeck
- [Campaign themes / brands] impersonated brands and portals â IRS, SSA, Adobe, Dropbox, DocuSign, Messenger, ConnectWise