Skip to main content
Emerging ThreatsMalware & Ransomware

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

Brightly-lit industrial control system terminal on a factory floor.

"We have received continued reports of heightened threat activity," PTC warned its customers, a concise line that encapsulates a rapidly evolving intrusion pattern exploiting internet-exposed PTC Windchill and FlexPLM deployments.

CVE-2026-12569: a critical Windchill RCE being weaponized

Security analysts say attackers are exploiting CVE-2026-12569, described in public advisories as a critical PTC Windchill flaw with a CVSS score of 9.3. The vulnerability was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog late last month. Ransom-ISAC, eCrime.ch and DEFUSED released a coordinated advisory linking active exploitation of the Windchill defect to follow-on activity that results in remote code execution (RCE) and web-shell deployment.

FlexPLM WSDL information disclosure chained to enable unauthenticated RCE

According to the coordinated advisory, attackers "chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/." The FlexPLM WSDL endpoint issue carries a CVSS v3.1 score of 7.5; researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said, "In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation."

Observed tradecraft: JSP web shells, data staging, double extortion

ReliaQuest reported on X that it observed exploitation of CVE-2026-12569 leading to "unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration." The coordinated reporting says attackers have been found to perform file system enumeration, stage engineering and design data, and ultimately carry out double extortion data theft—stealing high-value files and then threatening public release or sale.

Targets, IoCs, and extortion messaging

Ransom-ISAC and PTC both shared four IP addresses as indicators of compromise; the advisory notes these IoCs match those published by PTC. The four IPs are listed as 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35. Reported targets of the campaign include organizations in manufacturing, automotive, aerospace, and retail sectors. Extortion emails tied to the incidents appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, accompanied by directions for contacting the Cl0p ransomware crew.

Cl0p affiliates and the group's prior playbook

The activity has been attributed to affiliates linked to the Cl0p ransomware operation—also referenced in reporting as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—though Ransom-ISAC and others stop short of attributing every intrusion to a single actor. The advisory notes that "the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories." The group has previously exploited widely used enterprise products, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, MOVEit Transfer, and a vulnerability in Oracle E-Business Suite, as part of prior data-theft and extortion operations.

What this means for technologists, procurement leaders, and regulators

  • Technologists and security teams: Expect unauthenticated RCE and web-shell deployment against internet-exposed Windchill and FlexPLM instances; validate exposure, apply vendor guidance, and watch for the four IoCs shared by Ransom-ISAC and PTC.
  • Procurement and enterprise owners in manufacturing, automotive, aerospace, and retail: The campaign specifically stages engineering/design data, underscoring the risk to product IP—organizations should assess internet exposure of PTC products and review access controls for high-value repositories.
  • Policymakers and regulators: With CVE-2026-12569 added to CISA's KEV catalog and coordinated advisories in circulation, regulators will see this as an active exploited vulnerability scenario requiring prioritized mitigation and cross-sector notification.

The pattern is familiar: a pre-authentication disclosure fed into a server-side flaw, rapid web-shell deployment, and focused exfiltration of design and engineering artifacts followed by extortion. Whether defenders can interrupt the chain will depend on timely patching, swift detection of the hex-named JSP web shells under /Windchill/login/, and containment of compromised accounts used to send extortion notices. For now the advisory trail—PTC's warning, the Ransom-ISAC/eCrime.ch/DEFUSED coordination, and ReliaQuest's X post—provides a narrow but actionable picture of a focused campaign exploiting CVE-2026-12569 and a FlexPLM WSDL flaw to harvest sensitive enterprise engineering data.

Original reporting: https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html