The Quarry is a phishing-as-a-service and malware-enabled cybercrime ecosystem active since at least April 2025. It is associated with a developer tracked under the aliases RockyBelling, Rock, Rockky, and Mike, and appears to support a large affiliate base numbering close to 200 operators. The operation is primarily financially motivated and has focused heavily on U.S.-based victims, especially through tax- and government-themed phishing that impersonates the Internal Revenue Service, the Social Security Administration, and document-sharing brands such as DocuSign, Adobe, Microsoft, and Dropbox. The Quarry provides affiliates with a turnkey toolkit that includes phishing pages, cloaking infrastructure, bulk email tooling, remote access panel deployment, and post-exploitation scripts. A defining characteristic of the ecosystem is its use of legitimate remote monitoring and management software, especially ConnectWise ScreenConnect, as the primary payload for persistent remote access. This allows operators to gain interactive control of victim systems while reducing reliance on conventional malware. In addition to web-based lures, the ecosystem has also used script-based droppers to silently install remote access software while presenting decoy documents to the victim. Operationally, The Quarry uses layered filtering and traffic cloaking to evade researchers, automated scanners, and non-target visitors. Campaign infrastructure has been observed restricting delivery based on platform characteristics and using cloaking services to hide phishing content unless a visitor matches the intended victim profile. The phishing workflow commonly begins with bulk email delivery, followed by credential harvesting or social engineering that leads victims to download a purported security or document-access component. After compromise, operators deploy scripts to collect browser history, search for tax and payroll documents such as W-2 records, and steal credentials, cookies, and other sensitive data. Tooling associated with the ecosystem has also included promotion of credential- and cookie-theft malware. Observed victimology indicates a strong concentration in the United States, with campaigns aligned to tax season and identity-related themes, though activity has also affected victims in multiple other countries. The ecosystem’s objectives extend beyond simple credential theft and appear to include financial fraud, tax-related identity theft, theft of corporate and cloud access, and possible initial access brokerage. Reporting has assessed that stolen access may be resold or otherwise enable downstream ransomware activity. The Quarry has also been linked to adjacent phishing operators through supplier or customer relationships rather than confirmed centralized command-and-control membership. In particular, the actor known as codemado has been tied to the ecosystem through promotion of a bulk-mailing tool in Quarry-associated channels, indicating commercial integration with the broader service network. Overall, The Quarry represents a mature criminal service platform combining phishing, remote access enablement, cloaking, affiliate support, and post-compromise data theft at scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-service network materially connected to codemado as a supplier/client relationship rather than a command structure.
A phishing-as-a-service ecosystem mentioned as broader context and possibly a supplier relationship through promotion of MaDoO Blaster, but not directly tied to the three operators beyond that.
Phishing-as-a-Service operation selling a toolkit to nearly 200 operators for tax-themed and government-impersonation phishing campaigns, delivering remote access via ScreenConnect and supporting post-exploitation data theft.
A phishing-as-a-service / malware-as-a-service ecosystem behind hundreds of phishing campaigns impersonating the IRS, SSA, DocuSign, Adobe, Microsoft, and Dropbox. It provides phishing kits, Adspect-based cloaking, bulk email tooling, Telegram-based victim logging, ScreenConnect-based remote access delivery, VBS droppers with UAC bypass, and post-exploitation scripts to nearly 200 affiliates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.