Clop created custom web shell for Windchill data theft attacks
7 Articles
7 Articles
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
I put it in context: Clop’s cyberattack is not an isolated incident. The cyberextortion group has exploited a zero-day at PTC Windchill to steal data from dozens of multinationals and press with threatening emails since mid-July. CVE-2026-12569 vulnerability: dates, patch and silence of the PTC company revealed the vulnerability CVE-2026-12569 on June 17 and published the patch the next day with initial compromise indicators. The failure, a remo…
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












