Beware of the Ransomware Attack Using Repeated UAC Alert!
Sodinokibi ransomware is being distributed using repeated UAC (User Account Control) alert. Once the end-user clicks the ‘Yes(Y)’ button, the malware is downloaded and takes control of the PC. Thereby, extra caution is needed not to click the ‘Yes(Y)’ button when the repeated alert appears.

The new Sodinokibi ransomware, also known as BlueCrab ransomware, has been identified as being distributed using the Drive-By-Download method via the Fallout EK and Adobe Flash Player Vulnerability (CVE-2018-15982). BlueCrab ransomware is automatically downloaded on the PC when a user with the vulnerable version of Flash Player visits a malicious website.
When the BlueCrab ransomware is downloaded on the PC, the UAC alert appears. If the user clicks the ‘No(N)’ button, the same alert will continue to appear.
When the puzzled user finally clicks on the ‘Yes(Y)’ button, the ransomware acquires the PC’s 'administrative rights' and searches running processes and services to terminate certain processes and services. This allows the ransomware to deactivate security programs, such as anti-virus programs, while encrypting running document files or important DB files.
Ransomware needs administrative rights to access folders to encrypt files or delete VSC (Volume Shadow Copies). Previous BlueCrab ransomware attempted to gain administrative rights by using the program vulnerabilities. However, it has been confirmed that the code for exploiting the vulnerability has been removed from the recent ransomware. Instead, the ransomware gains administrative right by pressuring the user with repeated UAC alert to obtain permission.
After gaining administrative rights and terminating the process and service, BlueCrab ransomware encrypts the files on the PC and changes the PC background.
Keep Calm and Reboot!
Most end-user have difficulty dealing with repeated UAC alert because they lose full control over their PC.
When this occurs, beware not to click the button within the alert. Instead, press the [Ctrl + Alt + Delete] keys to open the Task Manager and terminate the process. If that does not work, try rebooting the PC by pressing the power button. After that, it is highly recommended that the end-user performs a thorough malware scan via anti-virus program, such as the well-established AhnLab V3.
AhnLab’s V3 product detects BlueCrab ransomware with following aliases while also blocking related websites and vulnerabilities.
<V3 Product Aliases>
- Trojan/Win32.BlueCrab
- Trojan/Win32.MalPE
- Packed/Win32.SuspiciousPacker
- Malware/MDP.Exploit.M2185
▶Learn more about V3, AhnLab’s anti-virus product.
The distribution of BlueCrab malware using the vulnerability of Adobe Flash Player is increasing. Thereby, it is recommended that the Adobe Flash player is updated to the latest version.
To prevent malware infections, including BlueCrab ransomware, apply the latest security updates for software and operating systems, including Flash Player, and Internet browsers (IE, Chrome, Firefox, etc.) to keep the PC’s anti-virus up-to-date. The end-user should also refrain from visiting websites or downloading programs that have not yet been verified for safety.