Cybercriminals Deploy 'The Quarry' Phishing Service in Widespread IRS-Themed Attacks on U.S. Targets

A newly identified Phishing-as-a-Service (PhaaS) ecosystem known as 'The Quarry' is enabling cybercriminals to launch sophisticated, large-scale phishing campaigns targeting U.S. businesses and individuals with lures themed around the Internal Revenue Service. Security researchers recently uncovered the highly modular platform, which was reportedly assembled by a single developer operating under the alias 'RockyBelling.' The service provides affiliates worldwide with the tools and infrastructure needed to conduct targeted attacks aimed at stealing credentials and committing financial fraud.

The emergence of The Quarry is part of a broader and troubling trend in cybercrime: the industrialization of phishing. PhaaS platforms effectively lower the barrier to entry, allowing threat actors with limited technical expertise to execute complex attacks that were once the domain of highly skilled hacking groups. According to a March 2026 warning from Microsoft, a separate but similar campaign using the Energy365 phishing kit was estimated to be sending hundreds of thousands of malicious emails daily, highlighting the immense scale these service-based operations can achieve.

In our experience, these attacks represent a direct and escalating threat to the financial stability of small and mid-sized businesses. This is no longer about generic spam; these are calculated campaigns designed to exploit the trust inherent in financial communications, especially those involving tax authorities like the IRS or trusted advisors like CPAs. We have seen firsthand how a single compromised email account can spiral into devastating losses, from fraudulent wire transfers to corporate identity theft used to file bogus tax returns. The attackers are clever, using convincing branding and social engineering to bypass even vigilant employees. Business owners must understand that this is not just an IT problem but a core operational vulnerability.

This is precisely where our financial risk management services become critical. A strong defense requires more than just antivirus software; it requires integrating robust financial controls with operational security protocols. We work with clients to establish and enforce procedures for verifying payment requests, authenticating communications, and securing sensitive financial data against these specific types of threats. The goal is to build a resilient framework that can withstand a targeted attack and mitigate potential damage. For businesses concerned about their exposure to these advanced financial scams, C&S Finance Group LLC at csfinancegroup.com offers guidance on strengthening internal controls.

The tactics employed by affiliates using PhaaS platforms are varied and designed to evade traditional security measures. One common method, observed in a campaign that affected approximately 100 U.S. organizations, involved using QR codes and fake W2 forms as lures. These attacks directed employees to phishing pages that perfectly mimicked Microsoft 365 sign-in portals. The goal was to siphon not only user credentials but also two-factor authentication (2FA) codes, effectively bypassing a key layer of security. Another tactic involves using Certified Public Accountant (CPA) impersonations to lend legitimacy to the malicious emails, tricking finance department employees into clicking on malicious links.

This service-based model has created a distributed and specialized cybercrime economy. According to analysis from the security firm Flashpoint, the PhaaS pipeline involves distinct actors at each stage. Some specialize in developing and maintaining the phishing kits and infrastructure. Others, known as affiliates, rent these services to conduct the actual attacks. A third group focuses on monetizing the stolen data, which can range from selling credential logs on dark web forums to using the compromised accounts for complex financial fraud, including tax schemes and money laundering.

The United States is a primary focus for these criminal enterprises. Research from Trellix on a different PhaaS platform, Morphing Meerkat, found that since tracking began in November 2024, nearly half of all global detections of its malicious URLs were located in the U.S. This indicates a concentrated effort by PhaaS affiliates to target American organizations, likely due to the high value of the financial data they can obtain. The scale is significant, with some services, like the one offering the Storm-1167 phishing kit, estimated to have several hundred active affiliates, according to research from Sekoia.io.

While law enforcement and cybersecurity firms are increasing their efforts to dismantle these networks, the decentralized and resilient nature of the PhaaS model makes it a persistent threat. Businesses should anticipate that these attacks will continue to grow in sophistication, with platform operators constantly updating their tools and evasion techniques. Moving forward, maintaining a strong security posture will require continuous employee education on emerging threats and the implementation of multi-layered security controls that can detect and block these advanced phishing attempts.