Dark Web Profile: Rock

Rock, tracked by SOCRadar as The Quarry, is a one-person MaaS/PhaaS operation that sells a full phishing and remote access toolkit to affiliates running tax-themed campaigns against U.S. victims. The ecosystem uses legitimate RMM software, Adspect cloaking, and Telegram-based reporting to support campaigns impersonating the IRS, SSA, Adobe, Dropbox, DocuSign, and Messenger. #TheQuarry #Rock #ScreenConnect #Adspect #Telegram #IRS #SSA #Adobe #Dropbox #DocuSign #Messenger

Keypoints

  • Rock is the developer behind The Quarry, a MaaS/PhaaS ecosystem active since at least April 2025.
  • The operation is centered on tax-themed lures impersonating U.S. agencies and brands, with over 90% of recorded victims in the U.S.
  • Rock sells tools, infrastructure, and support to affiliates, with observed pricing for scrapers, mass-mailers, and self-hosted ScreenConnect setups.
  • ScreenConnect is the primary remote access payload, while Tiflux, Datto, and FleetDeck also appear in some campaigns.
  • The phishing kit includes cloaking with Adspect, modular PHP infrastructure, VBS droppers, and Telegram-based victim logging and C2.
  • Post-exploitation activity can include browser history theft, W-2 document searching, credential harvesting, and selling access onward.
  • SOCRadar notes the ecosystem remains active, with new domains and Telegram activity continuing into April and May 2026.

MITRE Techniques

  • [T1596.005 ] Scan Databases – Automated scrapers collect corporate domains by sector and locate hardcoded credentials in accessible resources such as JavaScript files (‘Automated scrapers collect corporate domains by sector and locate hardcoded credentials in accessible resources such as JavaScript files’).
  • [T1583.001 ] Domains – Registers custom domains using tax-related naming conventions as the primary phishing infrastructure (‘Registers custom domains using tax-related naming conventions as the primary phishing infrastructure’).
  • [T1583.006 ] Web Services – Leverages public GitHub and GitLab repositories to host MSI payloads and decoy PDFs, abusing platform reputation (‘Leverages public GitHub and GitLab repositories to host MSI payloads and decoy PDFs, abusing platform reputation’).
  • [T1587.001 ] Malware – Develops a modular PHP phishing kit with cloaking, VBS droppers with UAC bypass, PS1 post-exploitation scripts, and bulk email tooling (‘Develops a modular PHP phishing kit with cloaking, VBS droppers with UAC bypass, PS1 post-exploitation scripts, and bulk email tooling’).
  • [T1583.004 ] Server – Deploys self-hosted ScreenConnect instances provisioned per affiliate as remote access infrastructure (‘Deploys self-hosted ScreenConnect instances provisioned per affiliate as remote access infrastructure’).
  • [T1566.001 ] Spearphishing Attachment – Distributes the VBS dropper directly as an email attachment using tax-themed lures (‘Distributes the VBS dropper directly as an email attachment using tax-themed lures’).
  • [T1566.002 ] Spearphishing Link – Distributes links to malicious domains via bulk email, redirecting victims to fake SSA, IRS, Adobe, Dropbox, or DocuSign portals (‘Distributes links to malicious domains via bulk email, redirecting victims to fake SSA, IRS, Adobe, Dropbox, or DocuSign portals’).
  • [T1204 ] User Execution – Victims execute the RMM installer, prompted by the tax-themed context and the “Security Connector” popup (‘Victims execute the RMM installer, prompted by the tax-themed context and the “Security Connector” popup’).
  • [T1059.005 ] Visual Basic – Uses VBS scripts as an alternative delivery vector with three obfuscation variants (‘Uses VBS scripts as an alternative delivery vector with three obfuscation variants’).
  • [T1059.001 ] PowerShell – The most advanced VBS variant runs a PowerShell script implementing AES decryption before launching the payload (‘The most advanced VBS variant runs a PowerShell script implementing AES decryption before launching the payload’).
  • [T1548.002 ] Bypass User Account Control – The VBS dropper triggers UAC; the April 2026 variant implemented a bypass with no visible dialog (‘The VBS dropper triggers UAC; the April 2026 variant implemented a bypass with no visible dialog’).
  • [T1036.005 ] Match Legitimate Name or Location – RMM installers use filenames simulating tax documents such as ScreenConnect.ClientSetup.exe and StatementID-5ecc7a9.exe (‘RMM installers use filenames simulating tax documents (ScreenConnect.ClientSetup.exe, StatementID-5ecc7a9.exe)’).
  • [T1027 ] Obfuscated Files or Information – VBS variants use Base64 concatenation, hexadecimal encoding, and AES decryption in a secondary PowerShell stage (‘VBS variants use Base64 concatenation, hexadecimal encoding, and AES decryption in a secondary PowerShell stage’).
  • [T1070.004 ] File Deletion – The VBS dropper deletes the MSI installer after installation, removing the primary forensic artifact (‘The VBS dropper deletes the MSI installer after installation, removing the primary forensic artifact’).
  • [T1656 ] Impersonation – Impersonates SSA, IRS, Adobe, Dropbox, DocuSign, and ConnectWise with customized CSS, official logos, and security messaging (‘Impersonates SSA, IRS, Adobe, Dropbox, DocuSign, and ConnectWise with customized CSS, official logos, and security messaging’).
  • [T1539 ] Steal Web Session Cookie – A credential harvesting panel likely derived from Evilginx targets credentials and session cookies (‘A credential harvesting panel likely derived from Evilginx targets credentials and session cookies’).
  • [T1552.001 ] Credentials in Files – Scrapers identify hardcoded credentials in public resources, including JavaScript files with cloud access keys (‘Scrapers identify hardcoded credentials in public resources, including JavaScript files with cloud access keys’).
  • [T1083 ] File and Directory Discovery – The W-2 Document Finder recursively searches the user profile for files containing “w2” (‘The W-2 Document Finder recursively searches the user profile for files containing “w2″‘).
  • [T1185 ] Browser Session Hijacking – The Browser History Stealer force-closes the browser to read locked SQLite databases and export six months of history (‘The Browser History Stealer force-closes the browser to read locked SQLite databases and export six months of history’).
  • [T1071.001 ] Web Protocols – All exfiltration runs through HTTPS POST requests to the public Telegram API (‘All exfiltration runs through HTTPS POST requests to the public Telegram API’).
  • [T1568.002 ] Domain Generation Algorithms – The kit generates random 300-character URL fragments during PHP redirects to complicate tracking (‘The kit generates random 300-character URL fragments during PHP redirects to complicate tracking’).
  • [T1219 ] Remote Access Software – The installed RMM connects to the affiliate’s self-hosted ScreenConnect panel over RSA-4096, disguised as legitimate remote support (‘The installed RMM connects to the affiliate’s self-hosted ScreenConnect panel over RSA-4096, disguised as legitimate remote support’).
  • [T1657 ] Financial Theft – Targeting the U.S. tax season alongside W-2 and credential theft points to tax fraud and access to victim financial infrastructure (‘Targeting the U.S. tax season alongside W-2 and credential theft points to tax fraud and access to victim financial infrastructure’).

Indicators of Compromise

  • [Domains] phishing and delivery infrastructure – dozens of domains, newly created domains in April and May 2026
  • [File names] RMM and lure-related filenames – ScreenConnect.ClientSetup.exe, StatementID-5ecc7a9.exe
  • [File paths / directories] payload staging locations – /sources/, /downloads/, index.php, de.php
  • [URLs / services] exfiltration and communication – public Telegram API, GitHub, GitLab
  • [Software / agent names] installed remote access tools – ScreenConnect, Tiflux, Datto, FleetDeck
  • [Campaign themes / brands] impersonated brands and portals – IRS, SSA, Adobe, Dropbox, DocuSign, Messenger, ConnectWise


Read more: https://socradar.io/blog/dark-web-profile-rock/