Clop Ransomware Exploits Critical PTC Windchill and FlexPLM Flaw in Widespread Data Theft Campaign

Clop Ransomware Exploits Critical PTC Windchill and FlexPLM Flaw in Widespread Data Theft Campaign

The Clop ransomware gang (also tracked as Cl0p) is actively exploiting a critical vulnerability in PTC Windchill and FlexPLM product lifecycle management systems, deploying JSP webshells to steal sensitive product data from organizations across aerospace, defense, automotive, and manufacturing sectors, security researchers warned this week.

Security analyst monitoring network traffic and system logs on multi-monitor setup

ReliaQuest, the cybersecurity firm that first reported the campaign, said threat actors are targeting Internet-exposed instances of the enterprise PLM platforms using CVE-2026-12569 — a critical improper input validation vulnerability carrying a CVSS score of 9.3 out of 10.

"ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability affecting PTC Windchill and FlexPLM," the company said in its analysis. "Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration."

The attacker behind the campaign remains unconfirmed, but ReliaQuest noted the observed tradecraft shares characteristics with previous Clop campaigns targeting enterprise applications and high-value data repositories. The Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) confirmed the Windchill and FlexPLM attacks on Thursday, sharing additional details about how the extortion emails are structured and distributed.

"Clop's extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization, and include Clop's latest contact information," said Allan Parsons, head of threat intelligence at Ransom-ISAC. "This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses."

How the Attack Works

Clop operators are exploiting the deserialization flaw to plant JSP webshells on vulnerable PLM servers, giving them persistent remote access to systems that manage the entire lifecycle of physical products — from initial design through manufacturing and supply chain management.

PTC Windchill and PTC FlexPLM are enterprise platforms in a category known as Product Lifecycle Management. These systems track, design, and manage products from the original idea through final manufacturing. They store highly sensitive intellectual property including CAD drawings, bill of materials, supplier contracts, and product specifications.

The two systems are widely deployed across engineering, manufacturing, quality, and supply chain teams at high-profile companies in aerospace, defense, automotive, heavy machinery, retail, and medtech sectors. PTC says its products serve more than 30,000 customers globally, with over 1,500 brand and retail customers using FlexPLM.

For manufacturing companies, a PLM breach is arguably more damaging than a typical corporate data theft. The stolen data includes blueprints for unreleased products, manufacturing processes, supply chain details, and trade secrets that competitors or foreign adversaries would pay handsomely to obtain. In defense and aerospace, the national security implications of stolen CAD files and engineering specifications are even more serious.

Anonymous figure standing in server room holding a Guy Fawkes mask

The attack approach follows Clop's established playbook: breach an enterprise application, exfiltrate sensitive data, and then extort the victim by threatening to publish stolen files on the gang's dark web leak site.

After exfiltrating data, Clop publishes stolen documents on its dark web leak site, making them available via Torrent download if victims refuse to pay the ransom demand. The gang typically gives victims several weeks to negotiate before leaking the first tranche of stolen data, increasing pressure over time with additional releases.

Patch Timeline and Government Response

PTC began releasing security patches for CVE-2026-12569 on June 17. While the company did not initially confirm in-the-wild exploitation, it released remediation guidance in a private advisory and urged customers to review their environments for indicators of compromise (IOCs).

The situation escalated quickly after PTC warned customers of heightened threat activity on June 26. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to secure their PTC Windchill and FlexPLM instances within three days.

German authorities responded with notable urgency. According to German news outlet Heise, the Federal Office for Information Security (BSI) emailed and called PTC customers in the middle of the night, warning them to patch their systems as quickly as possible. This echoes the same urgency German authorities showed in March, when reports surfaced that a similar critical Windchill and FlexPLM flaw tracked as CVE-2026-4681 may have been exploited or was likely to be exploited soon.

The US Department of State now offers a $10 million reward for information linking this cybercrime gang's attacks to a foreign government, reflecting the severity of Clop's ongoing campaigns and the broader geopolitical stakes of enterprise software compromise.

Clop's Long History of Enterprise Breaches

Clop has a well-documented history of targeting enterprise file-sharing platforms and PLM systems. Previous campaigns have hit Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer — the latter affecting more than 2,770 organizations worldwide in one of the largest data theft extortion operations on record.

Most recently, the gang exploited an Oracle EBS zero-day flaw to steal sensitive files from numerous organizations since early August 2025, including Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, Estee Lauder, Korean Air, and American Airlines subsidiary Envoy Air.

"What makes Clop especially dangerous is their willingness to invest in finding and weaponizing zero-day vulnerabilities in enterprise software," said John Hultquist, chief analyst at Mandiant. "They do not just phish their way in — they study the software stack and find the cracks that everyone else misses."

The Oracle EBS campaign alone exposed the gang's sophistication: they had maintained persistent access to multiple victim networks for months before triggering the mass data exfiltration event, carefully selecting high-value documents while avoiding detection by endpoint security tools.

This pattern of long-term preparation followed by a coordinated strike is hallmarks of Clop's operations, and the Windchill and FlexPLM campaign appears to follow the same playbook. ReliaQuest noted that PTC began patching the vulnerability on June 17, but the gang exploited instances that had not yet been updated within the first week of the patches becoming available.

Mitigation Steps for PLM Operators

ReliaQuest advised PTC customers to immediately patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Organizations that suspect compromise should isolate affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

"If your organization runs PTC Windchill or FlexPLM on the public internet, treat it as compromised until proven otherwise," the ReliaQuest team warned in their advisory.

Additional mitigation steps include monitoring for the specific JSP webshells deployed by Clop in this campaign, reviewing network traffic logs for unusual data transfers from PLM servers, and implementing network segmentation to prevent lateral movement from PLM systems to other critical infrastructure.

Security teams should also audit their PLM deployments for any instances that may have been added outside of standard IT governance — shadow PLM deployments that bypass security controls are particularly vulnerable because they often lack the monitoring and access restrictions that protect core systems.

The broader lesson for enterprise security teams is clear: any Internet-exposed application that handles valuable intellectual property is a potential target. PLM systems, which contain the crown-jewel product data for manufacturers, are increasingly in the crosshairs of ransomware gangs who understand the value of what sits inside these servers.

Cybersecurity teams should review their exposure to CVE-2026-12569 urgently and ensure all PTC systems are patched and segmented away from the open Internet. For more coverage of enterprise threats and security developments, see our Cloud & Edge Computing section.

Source: BleepingComputer

← Back to Home