The Clop ransomware group is exploiting installations of PTC Windchill and FlexPLM. The attackers chain a pre-authentication information leak to a flaw in the Windchill login servlet, leading to remote code execution and data theft via double extortion.
This has been revealed by research conducted by Ransom-ISAC. A coordinated threat advisory led by Ransom-ISAC, in collaboration with eCrime.ch and DEFUSED, describes an ongoing campaign by a Clop affiliate. Companies that have PTC Windchill and FlexPLM exposed to the internet are being targeted. This Product Lifecycle Management software often contains sensitive engineering and design data.
The attackers combine two vulnerabilities. First, they exploit a pre-authentication information leak in the FlexPLM WSDL endpoint (CVSS 7.5). They then link this to a flaw in the Windchill login servlet that allows unauthenticated remote code execution (CVSS 9.8). They then deploy JSP webshells with hexadecimal names under /Windchill/login/.
Following the intrusion, the attackers perform filesystem enumeration via flst.txt and prepare data for exfiltration. Confirmed affected sectors include manufacturing, automotive, aerospace, and retail. The advisory shares four new C2 indicators, in addition to previously distributed IOCs.
Zero-day since early June
The researchers suspect that Clop affiliates began exploiting CVE-2026-12569 as a zero-day in early June 2026. This critical RCE vulnerability, with a CVSS score of 9.8, arises from the deserialization of untrusted data and affects Windchill and FlexPLM prior to release 11.0 M030. The vulnerability was disclosed on June 17. CISA added the vulnerability to its Known Exploited Vulnerabilities list on June 25. PTC has since released patched builds.
It is noteworthy, however, that public sources have not yet explicitly linked the exploitation of this vulnerability to Clop. Security researchers have primarily confirmed the deployment of JSP webshells, while CISA has provisionally left the column regarding ransomware use marked as “unknown.”
Email extortion
Since July 20, Ransom-ISAC has observed an extortion campaign believed to be attributed to Clop. The group sends emails with the subject line “Windchill PDMLink module serious data leak” to hundreds of users within affected organizations. These emails originate from randomly compromised accounts and contain Clop’s most recent contact information.
According to the advisory, this approach is consistent with what was seen last year in the Oracle EBS campaign, only with new email addresses. In that campaign, which exploited an actively abused zero-day vulnerability in Oracle E-Business Suite, Google estimates that more than 100 organizations were likely affected. Clop has long been known as a pioneer in exploiting zero-days in enterprise software such as MOVEit, Cleo, and SysAid.
As of July 22, Clop had not yet posted any victims of this campaign on its dark web leak site, nor had it publicly claimed responsibility for the attack.