ThreatCluster

Quarry PhaaS Ecosystem Targets U.S. Taxpayers with IRS Phishing Campaigns

First seen 16 Jun 2026, 07:22 UTC GbhackersCybersecuritynews 76% similarity 64

Article Content

Browse articles
ThreatCluster

A cybercrime operation named The Quarry has been identified as the source of numerous phishing campaigns targeting American taxpayers. These campaigns impersonate the IRS and SSA, exploiting a Phishing-as-a-Service (PhaaS) toolkit developed by an individual known as RockyBelling. Research from SOCRadar indicates that nearly 200 affiliates are utilizing this modular toolkit, which features advanced cloaking and real-time victim telemetry. The campaigns have been active from April 2025 to April 2026, affecting a significant number of U.S. victims. Legitimate remote management tools are being abused in these attacks, complicating detection efforts. The operation's organized nature suggests a high level of sophistication and coordination among the affiliates. Current status indicates ongoing phishing attempts as the toolkit remains in use.

Key Points: • The Quarry operation targets U.S. taxpayers with sophisticated IRS and SSA phishing schemes. • Nearly 200 affiliates are linked to a modular PhaaS toolkit developed by RockyBelling. • Legitimate remote management tools are being exploited to enhance the effectiveness of these phishing campaigns.

ThreatCluster AI How this analysis works

Timeline

2025-04-01
Phishing campaigns identified
Research began revealing a series of phishing campaigns impersonating IRS and SSA, traced back to The Quarry operation.
Gbhackers
2025-04-30
SOCRadar research published
SOCRadar's findings linked almost 200 affiliates to The Quarry's PhaaS toolkit, highlighting its modular capabilities.
Gbhackers
2026-06-16
Current phishing activity reported
As of today, ongoing phishing attempts are being reported, leveraging the Quarry toolkit and legitimate RMM tools.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story