#threatreport #MediumCompleteness
Dark Web Profile: Rock | 14-06-2026
Source:
socradar.io/blog/dark-web-prโฆ
Key details below โ
๐งโ๐ปActors/Campaigns:
The_quarry
Rockybelling
๐Threats:
Screenconnect_tool, Adspect_tool, Tiflux_tool, Centrastage_tool, Fleetdeck_tool, Uac_bypass_technique, Cloaking_technique, Credential_harvesting_technique, Evilginx_tool, Violet_rat, Spear-phishing_technique,
๐ฏVictims: United states, Saas and development, Healthcare and medtech, Media and entertainment, Fintech and finance, E commerce and retail, Education, Real estate, Travel
๐ญIndustry: Entertainment, Education, Healthcare, Retail, Financial, E-commerce, Government
๐Geo: Egypt, Germany, Brazil, Canada, Japan
๐TTPs:
โ๏ธTactics: 12
๐ ๏ธTechnics: 17
๐งจIOCs:
- File: 4
๐ฝSoftware: Telegram, Dropbox, Gmail, Chrome
๐ขAlgorithms: rsa-4096, base64, aes
๐Programming Languages: visual_basic, powershell, javascript, php
#threatreport:
Rock is an individual cybercriminal developing and selling a comprehensive phishing and remote access toolkit under the Malware-as-a-Service (MaaS) and Phishing-as-a-Service (PhaaS) model, referred to as The Quarry. This operation has been active since at least April 2025, with indications of early distributions predating this. Characterized by tax-themed phishing lures imitating U.S. government agencies, the operation primarily deploys legitimate Remote Monitoring and Management (RMM) tools, notably ScreenConnect, for its payloads. The majority of recorded victims (over 90%) are based in the U.S., with the framework utilized to target platforms including SSA, IRS, Adobe, Dropbox, and DocuSign across numerous domains.
Rock, who operates under aliases such as RockyBelling and Rockky, maintains a presence on Telegram, where he promotes his services and tools. His business model involves selling access to the toolkit to various affiliates, who then execute their own phishing campaigns adapted to their targets. The adaptability of his service allows for significant variations in campaigns, complicating attribution, as multiple operators can use the same kit but present different themes.
Rock's toolkit includes several components for the entire attack lifecycle. The Remote Access tools typically utilize self-hosted RMM, while also incorporating Visual Basic Script (VBS) droppers that enhance delivery capabilities and evade detection. This VBS dropper variant has recently been advanced for better efficacy. Additionally, phishing kits are modular, featuring customizable lure pages and integrated cloaking mechanisms to filter out non-target traffic by using Adspect technology. Tools like the Rocky Gmail Sender and Rock VPS Mailer serve in mass-mailing operations, equipped with anti-detection features and subject randomization.
In terms of operational execution, affiliates engage in the scraping of email addresses and distribution of phishing emails, often masking malicious activity with legitimate hardware and software references. Victims encounter a series of misleading narratives that coax them into downloading software purportedly for tax purposes, resulting in the installation of RMM payloads. These payloads harvest sensitive data and can facilitate lateral movement within targeted organizations.
Victim profiles show a broad geographical spread, though primarily concentrated in the U.S., often targeting employees within SaaS, healthcare, and financial sectors. The operation showcases a proactive stance, conducting reconnaissance to identify exposed credentials across various public resources.
Rock's services exemplify how individual developers can significantly impact cyber crime by providing modular, easily deployable malicious software paired with ongoing support, highlighting an evolving threat landscape wherein organizations must remain vigilant against sophisticated phishing operations. The continued activity and emergence of new domains connected to Rockโs operations underscore the necessity for proactive cybersecurity measures and monitoring to mitigate risks associated with these developing threats.