The Truth Behind the Wedsolution. It Legal Notice: Real Lawsuit or Phishing Scam?
Opening the container bundled with a wedsolution.it message triggers an infection routine rather than displaying a legal summons. Reverse engineering of the payloads captured across the 2024, 2026 campaign reveals a recurring distribution of info-stealers and remote access Trojans (RATs).
| Observed Payload | Primary Mechanism | Operational Impact |
|---|---|---|
| Remcos RAT Variant | Obfuscated VBScript masquerading as a legal document icon | Grants attackers complete remote control, keystroke logging, and screen capture. |
| Agent Tesla / RedLine | Multi-stage PowerShell dropper triggered via LNK shortcut | Extracts stored browser passwords, FTP credentials, and cryptocurrency wallets. |
| GuLoader Shellcode | Encrypted binary payload hosted on public cloud storage | Bypasses endpoint detection to load secondary ransomware or corporate espionage tools. |
The execution chain typically relies on user deception. The extracted folder contains what appears to be a PDF or Word document, complete with an altered icon. In reality, the file features a double extension, such as `Court_Summons_Case_9821.pdf.exe` or `Legal_Infringement_Notice.vbs`. Once clicked, the script initiates a background PowerShell sequence that communicates with a remote command-and-control (C2) server, injects the malware into legitimate Windows processes, and establishes persistence on the host machine.