Executive Summary
Affiliates of the Cl0p ransomware group are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in internet-exposed PTC Windchill and FlexPLM environments. This campaign leverages a chain of vulnerabilities, enabling attackers to deploy persistent web shells, exfiltrate sensitive engineering and product lifecycle data, and extort organizations through double extortion tactics. The primary targets are organizations in the manufacturing, automotive, aerospace, and retail sectors, where the compromise of intellectual property and operational data can have severe business and reputational consequences. Immediate action is required to patch affected systems, restrict internet exposure, and monitor for indicators of compromise.
Threat Actor Profile
The Cl0p ransomware group, also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, is a financially motivated cybercriminal syndicate known for its rapid exploitation of newly disclosed vulnerabilities in enterprise software. Cl0p specializes in double extortion operations, combining data encryption with the exfiltration and threatened public release of sensitive information to maximize leverage over victims. The group has a history of targeting high-value enterprise applications, particularly those exposed to the internet, and is adept at weaponizing unauthenticated RCE flaws to gain initial access. Their operations are characterized by sophisticated reconnaissance, lateral movement, and the use of custom web shells for persistent access.
Technical Analysis of Malware/TTPs
The attack chain begins with exploitation of a critical vulnerability in the PTC Windchill login servlet, tracked as CVE-2026-12569 (CVSS 9.3), which allows unauthenticated remote code execution. Attackers first perform reconnaissance by querying the FlexPLM WSDL endpoint, exploiting an information disclosure flaw (CVSS 7.5) to enumerate the target environment and tailor subsequent payloads. Using the gathered intelligence, the adversary exploits the Windchill login servlet to execute arbitrary code without authentication.
Upon successful exploitation, the attackers deploy hex-named JSP web shells under the /Windchill/login/ directory. These web shells provide persistent, covert access to the compromised server, enabling the execution of arbitrary commands, file system enumeration, and data staging. The attackers then enumerate directories containing engineering and product design files, staging them for exfiltration. Data is exfiltrated over encrypted channels to attacker-controlled infrastructure, often using outbound connections to known malicious IP addresses.
The final phase involves the deployment of ransomware payloads to encrypt critical data, followed by extortion emails sent from compromised internal accounts. These emails threaten the public release of exfiltrated data unless ransom demands are met, leveraging the double extortion model. The technical sophistication of the campaign is evident in the use of custom web shells, targeted reconnaissance, and the chaining of multiple vulnerabilities to bypass authentication and escalate privileges.
Key technical indicators include the presence of hex-named JSP web shells (e.g., /Windchill/login/7c0a0a34c9d8d53b.jsp), malicious request headers such as X-windchill-req: ?x8Fmgow, and the creation of files like flst.txt in temporary or working directories, which indicate file listing activity by the attacker. Outbound connections to a set of malicious IP addresses, including 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35, are also strong indicators of compromise.
Exploitation in the Wild
Since late June 2026, there has been a marked increase in exploitation attempts targeting internet-exposed PTC Windchill and FlexPLM instances. Security researchers and threat intelligence platforms, including Ransom-ISAC, Field Effect, and Kudelski Security, have reported widespread scanning and exploitation activity, with successful compromises leading to the deployment of web shells and subsequent data exfiltration.
Victims have reported receiving extortion emails from compromised internal accounts, with attackers threatening to leak sensitive engineering and product data unless ransom demands are met. The exfiltrated data is often highly sensitive, including proprietary designs, intellectual property, and operational documentation. The campaign has primarily impacted organizations in the manufacturing, automotive, aerospace, and retail sectors, but the global footprint of PTC Windchill and FlexPLM means that organizations across multiple geographies are at risk.
The tactics, techniques, and procedures (TTPs) observed in these attacks align closely with previous Cl0p operations, including the rapid weaponization of unauthenticated RCE vulnerabilities, the use of custom web shells for persistence, and the execution of double extortion schemes. The campaign demonstrates a high level of operational maturity, with attackers leveraging both technical exploits and social engineering to maximize impact.
Victimology and Targeting
The primary targets of this campaign are organizations that rely on PTC Windchill and FlexPLM for product lifecycle management and engineering data storage. This includes companies in the manufacturing, automotive, aerospace, and retail sectors, where the compromise of design and operational data can have significant financial and reputational repercussions.
Victim organizations are typically those with internet-exposed Windchill or FlexPLM instances, often due to misconfigured firewalls or legacy deployments that have not been properly segmented from public networks. The attackers demonstrate a clear preference for high-value targets with large repositories of proprietary data, and the use of double extortion tactics indicates a focus on maximizing financial gain while inflicting reputational damage.
Geographically, the campaign appears to be global in scope, with incidents reported in North America, Europe, and Asia. The widespread adoption of PTC products in multinational enterprises increases the risk profile for organizations across all regions.
Mitigation and Countermeasures
Immediate mitigation steps are critical to prevent exploitation and limit the impact of ongoing attacks. Organizations should apply the latest security updates from PTC for Windchill and FlexPLM without delay. Patch details and downloads are available through the official PTC advisory and support portal.
Internet exposure of Windchill and FlexPLM instances should be eliminated wherever possible. Systems should be placed behind VPNs or other secure access mechanisms, and direct access from the public internet should be strictly prohibited. Network segmentation and firewall rules should be reviewed to ensure that only authorized users can access these critical systems.
Continuous monitoring for indicators of compromise is essential. Security teams should monitor for the presence of hex-named JSP web shells in the /Windchill/login/ directory, unusual access to FlexPLM WSDL endpoints, and outbound connections to known malicious IP addresses. SIEM and EDR solutions should be configured to flag POST requests to /Windchill/login/[0-9a-f]{16}\.jsp, block requests containing the X-windchill-req header, and alert on the creation of unauthorized .jsp files.
If compromise is suspected, organizations should initiate incident response procedures immediately. This includes forensic analysis of affected systems, credential resets, and communication with relevant stakeholders. File integrity monitoring should be implemented to detect unauthorized changes to critical directories, and regular backups should be maintained to facilitate recovery in the event of ransomware deployment.
Organizations are also encouraged to review and update their incident response and disaster recovery plans, ensuring that they are prepared to respond to ransomware and data extortion incidents. Employee awareness training on phishing and social engineering tactics can help reduce the risk of credential compromise during post-exploitation phases.
References
- PTC Advisory: Windchill & FlexPLM RCE Vulnerability
- PTC eSupport Article – CS473270
- NVD Entry: CVE-2026-12569
- The Hacker News: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
- Reddit: Cl0p ransomware affiliates are actively exploiting unauthenticated RCE
- Field Effect: Actively exploited PTC Windchill flaw allows unauthenticated RCE
- Kudelskki Security: Critical RCE Vulnerability in Windchill and FlexPLM
- SentinelOne: CVE-2026-4681
- CISA KEV Catalog
- DEFUSED Security Advisory
- eCrime.ch Threat Intelligence
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure the resilience of critical business operations. For more information about how Rescana can help your organization strengthen its cybersecurity posture, we are happy to answer questions at info@rescana.com.



