Quarry PhaaS Ecosystem Targets U.S. Taxpayers with IRS Phishing Campaigns
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A cybercrime operation named The Quarry has been identified as the source of numerous phishing campaigns targeting American taxpayers. These campaigns impersonate the IRS and SSA, exploiting a Phishing-as-a-Service (PhaaS) toolkit developed by an individual known as RockyBelling. Research from SOCRadar indicates that nearly 200 affiliates are utilizing this modular toolkit, which features advanced cloaking and real-time victim telemetry. The campaigns have been active from April 2025 to April 2026, affecting a significant number of U.S. victims. Legitimate remote management tools are being abused in these attacks, complicating detection efforts. The operation's organized nature suggests a high level of sophistication and coordination among the affiliates. Current status indicates ongoing phishing attempts as the toolkit remains in use.
Key Points: • The Quarry operation targets U.S. taxpayers with sophisticated IRS and SSA phishing schemes. • Nearly 200 affiliates are linked to a modular PhaaS toolkit developed by RockyBelling. • Legitimate remote management tools are being exploited to enhance the effectiveness of these phishing campaigns.