RockyBelling is the operator and developer behind The Quarry, a phishing-as-a-service and malware-as-a-service ecosystem active since at least April 2025. The actor is also known as Rockky, Rock, and Mike, and has used Telegram as a central platform for sales, coordination, victim notifications, and exfiltration. The Quarry has been marketed to a large affiliate base and provides modular phishing kits, cloaking infrastructure, bulk email tooling, self-hosted remote access panels, and post-exploitation scripts. The Quarry has primarily targeted victims in the United States, with observed activity spanning 14 countries. Its lures have heavily impersonated the IRS and the Social Security Administration, as well as widely trusted brands including Microsoft, Adobe, DocuSign, Dropbox, and Messenger. The ecosystem has relied extensively on layered filtering and cloaking, including Adspect-based traffic filtering, Windows-user-agent checks, randomized delivery paths, and anti-analysis measures designed to hide phishing content from researchers, scanners, and sandboxes. A defining operational characteristic of The Quarry is delivery of legitimate remote monitoring and management software, especially ConnectWise ScreenConnect, to obtain remote access while reducing conventional malware detection. The service has also offered self-hosted ScreenConnect deployments and associated maintenance. In April 2026, the ecosystem added a VBS-based dropper with UAC-bypass functionality that silently installed remote access software and delivered decoy documents. Post-exploitation tooling associated with the ecosystem has included scripts for browser-history theft and document discovery, with exfiltration routed through Telegram. RockyBelling has claimed authorship of most tools in the catalog, and code analysis has supported that assessment. The ecosystem has also been linked to bulk email tooling such as Rocky Gmail Sender and to broader phishing enablement services sold as complete campaign packages. Separate reporting connected codemado’s MaDoO Blaster bulk-mailing tool to The Quarry as a promoted third-party offering, indicating RockyBelling’s role as an ecosystem operator and marketplace curator in addition to direct tool development. The Quarry appears to support financially motivated cybercrime, including phishing, credential theft, remote access enablement, and downstream monetization of stolen access. Reporting has assessed that the ecosystem may facilitate initial access brokerage and possible resale of compromised access to ransomware operators, but high-confidence evidence directly tying RockyBelling to ransomware deployment itself is not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named cybercriminal connected through The Quarry ecosystem; promotes MaDoO Blaster and is materially linked to codemado as an ecosystem operator rather than the main subject of the report.
Runs The Quarry phishing-as-a-service ecosystem and promoted codemado's MaDoO Blaster to customers.
The developer and operator behind The Quarry ecosystem who builds, maintains, updates, and sells the modular PhaaS/MaaS toolkit, provisions ScreenConnect panels, distributes phishing kits and droppers, and supports a large affiliate base through Telegram.
Threat actor at the center of The Quarry cybercrime ecosystem, acting as developer and infrastructure provider for phishing kits and related tooling. Connected here through promotion/support of codemado's MaDoO Blaster.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.